Site icon VMVirtualMachine.com

Citrix Patches Two Exploited NetScaler RCE Zero-Days – Cyber Kendra

Citrix Patches Two Exploited NetScaler RCE Zero-Days – Cyber Kendra

By Vivek
Publication Date: 2026-09-27 16:49:00

Citrix on Sunday released patches for two critical NetScaler ADC and NetScaler Gateway vulnerabilities that attackers exploited as zero-days, one of which allows unauthenticated command execution on appliances running the default configuration.

The flaws, tracked as CVE-2026-88771 and CVE-2026-88772, each carry a CVSS v4 score of 9.5. They are among eight vulnerabilities addressed in security bulletin CTX697096.

“Exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments has been observed,” Citrix said. The company did not say who was behind the attacks, how many organisations were hit, or when exploitation began.

The Dutch National Cyber Security Centre (NCSC-NL) issued an advisory on Sunday evening with a high priority rating, urging organisations to apply the updates urgently. The agency said Secure Private Access Hybrid deployments that use NetScaler instances are also vulnerable. The flaws affect customer-managed appliances,…

Exit mobile version