Unpatched NetScaler Zero-Days Exploited, watchTowr Says – Cyber Kendra

Unpatched NetScaler Zero-Days Exploited, watchTowr Says – Cyber Kendra

By Vivek
Publication Date: 2026-09-26 17:43:00

Two unpatched remote code execution vulnerabilities in Citrix NetScaler have been exploited in the wild as zero-days, security firm watchTowr said on Saturday, as organisations take appliances offline ahead of patches Citrix is expected to release early next week.

Update: Citrix has released patches for the two exploited zero-days, now tracked as CVE-2026-88771 and CVE-2026-88772. Read our full coverage of the Citrix NetScaler patches.

In a follow-up post on X, watchTowr said the exploitation was discovered during forensic investigations, and that Citrix’s communications and patches are expected early next week. The two flaws match the number that administrators had been warned about earlier in the day. The company asked that further questions go to Citrix, noting that it is not the vendor’s product security team.

Earlier in the day, watchTowr said in a post on X that it was reacting to reports that several unpatched NetScaler RCE vulnerabilities are…