Two Exploited NetScaler Zero-Days: Check Default Deployments

Two Exploited NetScaler Zero-Days: Check Default Deployments

By QUASA Editorial Team
Publication Date: 2026-10-04 07:00:00

On September 27, 2026, Citrix’s NetScaler security bulletin disclosed eight vulnerabilities in customer-managed NetScaler ADC and NetScaler Gateway, including the actively exploited CVE-2026-88771 and CVE-2026-88772; it states, “Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed.” The first flaw affects every deployment running an affected build, including a default configuration. The second requires DTLS, which is enabled by default on VPN virtual servers.

Administrators therefore need to check the installed build on every customer-managed instance before using configuration to narrow exposure to the DTLS flaw. The CERT-EU advisory recommends updating affected software and assessing possible compromise on internet-facing appliances that ran affected builds. An update addresses the software flaws; the assessment asks whether someone gained access before it was installed.

Inventory every customer-managed instance first

CVE-2026-88771…