Skip to main content
Emerging Threats

Citrix Rushes Patches for Exploited NetScaler Zero-Days

Empty server room with rows of equipment racks and monitoring screens.

CVE-2026-88771 — a command-injection flaw rated 9.5 on the CVSS scale — was among the vulnerabilities Citrix patched Sunday after researchers warned of active exploitation.

CVE-2026-88771 and CVE-2026-88772: the defects Citrix addressed

Nearly two days after the first unconfirmed rumors circulated, Citrix published a security advisory Sunday disclosing two zero-days, CVE-2026-88771 and CVE-2026-88772, and released patches for those defects plus six additional issues. Both critical defects carry a CVSS score of 9.5 and permit remote code execution. Citrix said in a prepared statement: "We recently identified critical vulnerabilities in Citrix NetScaler ADC and Citrix NetScaler Gateway that led us to immediately develop and release a new version of the software that addresses the issues."

Why CVE-2026-88771 drew particular alarm

Researchers highlighted CVE-2026-88771 as especially dangerous because it is a command-injection vulnerability that affects NetScaler appliances in a default configuration, giving attackers a large pool of potential targets. A proof-of-concept exploit for CVE-2026-88771 is publicly available, increasing the likelihood of opportunistic exploitation.

Evidence of active exploitation and scope of exposure

The earliest known exploitation attempt recorded in the reporting occurred Sept. 24, when GreyNoise observed an unsuccessful attempt against a Citrix NetScaler Gateway it controls for malicious-activity scanning. Researchers warned exploitation likely began before that scan. Palo Alto Networks reported identifying more than 50,000 publicly exposed Citrix NetScaler instances potentially vulnerable to the two zero-days as of Sunday. Citrix has not disclosed how many customers have been compromised; researchers are still assessing the fallout.

The weekend information vacuum and industry reaction

For most of the prior weekend, the record shows an information gap: multiple CERTs, advisory firms, insurance providers, researchers and security professionals circulated warnings through unofficial channels while Citrix remained publicly silent. That silence drew public criticism. "The information vacuum was most striking. Customers were receiving warnings through unofficial channels while Citrix remained publicly silent," Ben Harris, founder and CEO at watchTowr, told CyberScoop. He added that Citrix "could have warned customers that active exploitation was occurring and provided immediate defensive guidance without disclosing technical details that would help attackers," and warned that "when active exploitation is underway, hours matter."

Citrix did not directly answer questions about the lengthy communication delay, though the company posted the prepared statement quoted above. The vendor said it is making generic indicators of compromise available to customers in their user consoles and referred customers to previously issued guidance for those who suspect compromise.

Responses by CISA, insurers, and named security leaders

The Cybersecurity and Infrastructure Security Agency issued an alert Sunday after Citrix's public confirmation and added CVE-2026-88771 and CVE-2026-88772 to its known exploited vulnerabilities catalog. The vendor had appeared on that catalog five times this year and a total of 26 times since late 2021, according to the reporting.

Insurance carrier Coalition notified potentially vulnerable customers during the period of limited official data; Joe Toomey, vice president of underwriting at Coalition, wrote on LinkedIn that Citrix was "unconscionably irresponsible" for remaining silent for more than 36 hours after reports of in-the-wild exploitation began circulating. Security leaders also took to public posts: Charles Carmakal, chief technology officer at Mandiant Consulting, and Wendi Whitmore, chief security intelligence officer at Palo Alto Networks, issued direct warnings on LinkedIn about the urgent threat.

How NetScaler customers, insurers, and defenders are likely to react

  • NetScaler customers: Those with externally exposed appliances will be focused on patch deployment and forensic review. Citrix's release of generic indicators in user consoles and its prior guidance for suspected compromise provide action points, but the vendor has not disclosed compromise counts.
  • Insurers and underwriters: Carriers that notified customers during the information gap — such as Coalition — signaled they will continue proactive outreach when vendors lag on public confirmation, even without CISA or vendor confirmation.
  • Security operations and threat hunters: With a proof-of-concept exploit public and tens of thousands of potentially exposed devices, defenders and threat hunters will prioritize scanning, containment, and analysis of suspicious activity tied to the published indicators of compromise.

Attribution for the attacks remains under investigation. The reporting notes NetScaler products are a "common, recurring target" for both financially motivated cybercriminals and state-sponsored espionage groups, which contextualizes why rapid, clear communication matters to a broad set of organisations. The core, unresolved question left by this episode is procedural: can vendors deliver faster, actionable notification once evidence of in-the-wild exploitation appears, or will customers continue to rely on informal channels and third-party warnings?

Source: CyberScoop — Citrix patches actively exploited NetScaler zero-days after a weekend of unofficial warnings