News / Cybersecurity
Citrix Confirms Active Exploitation of Two Critical Zero-Day Flaws in NetScaler Published on 27 September 2026 by Christ-loisele (3 min read)
Two unpatched zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) target Citrix NetScaler appliances. The vendor released urgent fixes after confirming ongoing attacks, while agencies like the CISA and researchers warn about their severity.
Two zero-day flaws actively exploited before patch release
Citrix officially confirmed on September 27, 2026, that two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) were already being exploited in attacks before patches were released. According to BleepingComputer , these flaws enable remote code execution (RCE) on NetScaler ADC and NetScaler Gateway appliances, widely deployed as remote access and application delivery devices.
The first flaw (CVE-2026-88771) stems from a failed input validation and affects all versions of NetScaler ADC and Gateway. The second (CVE-2026-88772) exploits a memory overflow requiring DTLS protocol activation, potentially leading to code execution or denial of service. Both have been observed in action on unpatched deployments, as highlighted by Citrix in a statement.
Exploits for flaws CVE-2026-88771 and CVE-2026-88772 have been observed on unprotected NetScaler deployments, confirming active exploitation even before Citrix released patches.
Illustration: Lawing Tech
Global alert and urgent recommendations
The CISA (Cybersecurity and Infrastructure Security Agency) has added these two vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, signaling global active exploitation. The U.S. agency has amplified Citrix’s alert and advises organizations to check for signs of compromise before applying updates, while preserving forensic evidence to avoid erasing clues.
Affected versions include NetScaler ADC and Gateway 14.1 before 14.1-73.37 and 13.1 before 13.1-64.23, as well as FIPS versions before 14.1-73.37 FIPS and 13.1-37.279. Citrix also published a security bulletin detailing eight vulnerabilities, including these two zero-days, without providing specific workarounds or compromise indicators.
What this means here
In Benin and across West Africa, where NetScaler appliances are often used to secure remote access to government infrastructure or corporate systems, these flaws could be exploited to compromise sensitive data or disrupt critical services. Administrations and businesses using outdated versions of NetScaler ADC or Gateway should urgently assess their exposure and apply Citrix’s recommended fixes, while monitoring compromise indicators.
The complexity of updates, which may require service downtime, could delay corrective actions. In this case, organizations might consider temporarily isolating vulnerable appliances until patches are implemented, as suggested by an anonymous Citrix administrator to BleepingComputer .
Context and expert reactions
The vulnerabilities were discovered by Citrix during investigations into incidents at customer sites, and private alerts were sent to organizations before their public disclosure, according to The Hacker News . The cybersecurity firm watchTowr has confirmed the credibility of rumors circulating about the active exploitation of these flaws, despite the lack of technical details.
This situation echoes the attacks targeting NetScaler vulnerabilities in 2025 within Dutch organizations, underscoring the need for African stakeholders to strengthen their monitoring of critical vulnerabilities and adopt rapid response protocols to security alerts.
Sources