Citrix has officially confirmed that two critical remote code execution (RCE) vulnerabilities, designated as CVE-2026-88771 and CVE-2026-88772, affecting its NetScaler appliances are actively being exploited in the wild. The company has released urgent security updates to address these flaws, which were the subject of private warnings to organizations over the preceding weekend from cybersecurity researchers, IT providers, and national cybersecurity agencies. The widespread deployment of NetScaler appliances as internet-facing edge devices, crucial for secure remote access and application delivery, makes these vulnerabilities a significant threat to corporate network perimeters.
The initial indications of a developing incident emerged through informal channels, primarily on platforms like Reddit, where Citrix administrators began reporting an unusual surge in private communications from IT suppliers and security teams. These communications, often lacking specific details, universally advised immediate shutdown of NetScaler appliances. One administrator shared on Reddit, "We got a call from our IT supplier’s security team, they couldn’t give any details but they advised to shut our Netscalers down immediately." This pattern of discreet outreach extended to law enforcement, Computer Emergency Response Teams (CERTs), and national cybersecurity agencies, all reportedly contacting organizations to alert them to the issue.
The gravity of the situation was further underscored by public statements from cybersecurity firms. WatchTowr, a prominent cybersecurity firm, issued a warning stating they were "rapidly reacting to rumors" of multiple unpatched Citrix NetScaler RCE vulnerabilities being exploited in the wild, having verified the information through "authoritative sources." Their cautious but firm alert highlighted the credibility of the intelligence, even in the absence of detailed public disclosures.
Official Confirmation and Technical Details of the Vulnerabilities
Citrix has now formally acknowledged the severity of the situation by publishing security bulletin CTX697096. This bulletin provides official confirmation of the vulnerabilities and details the security updates released for affected NetScaler ADC (Application Delivery Controller) and NetScaler Gateway appliances.
CVE-2026-88771: This vulnerability is classified as a remote code execution flaw stemming from improper input validation. It allows an unauthenticated attacker to execute arbitrary commands on the affected appliance, posing a severe risk. Citrix has assigned this vulnerability a critical severity score of 9.5 out of 10. Crucially, Citrix states that this flaw affects all NetScaler ADC and NetScaler Gateway deployments, irrespective of their configuration, and does not require any specific features to be enabled for exploitation. This broad impact means a vast number of organizations are potentially exposed.
CVE-2026-88772: This vulnerability is characterized as a memory overflow issue that can also lead to remote code execution or, alternatively, a denial-of-service (DoS) condition. It also carries a high severity score of 9.5. Exploitation of CVE-2026-88772 is possible when DTLS (Datagram Transport Layer Security) is enabled on a NetScaler ADC or NetScaler Gateway. Citrix specifically notes that DTLS is enabled by default on VPN virtual servers, a common configuration for remote access deployments.
In their official security bulletin, Citrix explicitly stated, "Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed." This direct confirmation validates the earlier warnings and confirms that these vulnerabilities are not theoretical but are actively being weaponized against organizations.
The affected versions of NetScaler ADC and NetScaler Gateway include:
- NetScaler ADC and NetScaler Gateway 13.1 before 13.1-49.18
- NetScaler ADC and NetScaler Gateway 13.0 before 13.0-91.12
- NetScaler ADC and NetScaler Gateway 12.1 before 12.1-66.17
- NetScaler ADC and NetScaler Gateway 12.0 before 12.0-58.17
- NetScaler ADC and NetScaler Gateway 11.1 before 11.1-65.22
- NetScaler ADC and NetScaler Gateway 11.0 before 11.0-70.17
- NetScaler ADC and NetScaler Gateway 10.5 before 10.5-71.18
Additionally, Secure Private Access Hybrid deployments that utilize NetScaler instances are also affected and require upgrading to the recommended builds. Citrix clarified that the security bulletin applies to customer-managed NetScaler ADC and NetScaler Gateway appliances. Cloud Software Group is undertaking the necessary upgrades for Citrix-managed cloud services and Citrix-managed Adaptive Authentication.
Pre-Disclosure Warnings and International Concern
The proactive, albeit private, warnings issued over the weekend were not a spontaneous reaction. Evidence suggests that national cybersecurity agencies were already alerted and disseminating information. Reports indicate that the Dutch National Cyber Security Centre (NCSC-NL) had sent a pre-notification to organizations within the Netherlands prior to Citrix’s public disclosure. Copies of this notification, shared online, revealed that the agency had received intelligence from a European partner CERT concerning two critical NetScaler zero-day vulnerabilities.

According to these pre-disclosure notices, one of the vulnerabilities allowed attackers to inject shellcode directly into memory, while the technical specifics of the second were still under investigation at that time. At that stage, no CVE identifiers had been assigned, and Citrix had not yet released an official advisory. The NCSC-NL notification indicated that Citrix had discovered these vulnerabilities while investigating incidents within customer environments and had identified active exploitation. Furthermore, it stated that Citrix had submitted a notification under the European Union’s Cyber Resilience Act following the discovery of these attacks.
The NCSC-NL noted that exploitation had been observed at multiple Citrix customers globally, though the extent of the attacks was not fully known. The agency also cautioned that exploitation attempts could intensify once Citrix released patches and more technical details became available. Recognizing that NetScaler upgrades can necessitate planned downtime, the NCSC-NL’s early warning aimed to provide organizations with sufficient lead time to prepare, implement interim safeguards, and swiftly deploy patches upon their release.
When contacted by BleepingComputer for confirmation regarding the legitimacy of the circulating advisory, the Dutch NCSC declined to provide specific details, citing their policy of not disclosing further information to entities outside their direct constituency. They stated, "As part of our role as the National CSIRT and sectoral CSIRT for designated organizations, the NCSC-NL monitors relevant developments and cyber threats affecting the Netherlands 24/7. We provide information and advice to organizations so that they can take appropriate measures. As you’re not part of our constituency, we cannot disclose any further information at this time." This response, while maintaining operational discretion, indirectly validated the existence of the proactive communication.
Chronology of the Incident
The unfolding of this critical security event can be pieced together through the various reports and confirmations:
- Early Weekend (Date not specified but preceding Monday’s wider disclosure): Cybersecurity researchers, IT providers, and national cybersecurity agencies begin privately contacting organizations. These warnings advise immediate shutdown of NetScaler appliances due to suspected zero-day vulnerabilities.
- Over the Weekend: Discussions emerge on platforms like Reddit, with Citrix administrators sharing their experiences of receiving urgent, albeit vague, shutdown advisories from their IT suppliers and security teams.
- Over the Weekend: WatchTowr publicly issues a cautious alert about unpatched Citrix NetScaler RCE vulnerabilities being exploited, citing credible information.
- Over the Weekend: The Dutch National Cyber Security Centre (NCSC-NL) reportedly sends pre-notifications to Dutch organizations about two critical NetScaler zero-days, detailing potential exploitation methods and confirming active exploitation.
- Monday (Date of original article publication): Citrix officially confirms the active exploitation of CVE-2026-88771 and CVE-2026-88772, releasing security updates and bulletin CTX697096.
- Post-Confirmation: Cybersecurity news outlets, including BleepingComputer, publish detailed reports on the confirmed vulnerabilities, the official response, and the broader implications.
Broader Impact and Implications
The exploitation of these NetScaler vulnerabilities carries significant implications for organizations worldwide. NetScaler appliances are frequently deployed at the network edge, acting as a primary gateway for remote employees and external partners to access internal corporate resources. A compromise of such a device can provide attackers with an immediate and deep foothold into an organization’s network perimeter, bypassing traditional endpoint security measures. This "beachhead" can then be leveraged to move laterally within the network, access sensitive data, or deploy further malicious payloads.
The fact that these are zero-day vulnerabilities means that for a period, no official patches were available, leaving organizations vulnerable. The widespread nature of NetScaler deployments means that a significant number of organizations, across various sectors including finance, healthcare, and government, are at risk. The severity scores of 9.5 for both CVEs indicate a critical threat level, demanding immediate attention.
The additional six vulnerabilities fixed in the same security bulletin further highlight the importance of applying the latest patches. While the focus has understandably been on the actively exploited zero-days, the presence of other critical flaws underscores a need for regular and comprehensive patching of NetScaler infrastructure.
Mitigation and Remediation Recommendations
Citrix’s release of security bulletin CTX697096 and the accompanying patches marks a critical turning point. The company strongly advises administrators to upgrade affected NetScaler ADC and NetScaler Gateway appliances to the patched versions as a matter of utmost urgency.
For organizations unable to apply the updates immediately due to operational constraints, Citrix recommends reducing internet exposure of the affected appliances wherever operationally feasible. This could involve temporarily disabling remote access features, restricting access to known trusted IP addresses, or implementing additional security layers in front of the NetScaler appliances until patching can be completed.
The incident serves as a stark reminder of the persistent threat landscape and the critical importance of:
- Proactive Vulnerability Management: Staying informed about emerging threats and vulnerabilities from trusted sources.
- Rapid Patch Deployment: Establishing robust processes for testing and deploying security updates promptly.
- Network Segmentation: Implementing network segmentation to limit the blast radius of any potential breach.
- Incident Response Planning: Having a well-defined and practiced incident response plan to effectively manage security incidents.
- Threat Intelligence: Leveraging threat intelligence feeds to stay ahead of attacker tactics, techniques, and procedures.
The coordinated warnings and swift confirmation by Citrix underscore the collaborative efforts required to combat sophisticated cyber threats. Organizations that have deployed NetScaler appliances must treat this advisory with the highest priority to protect their networks and sensitive data from exploitation. The race is now on to patch these critical systems before attackers can further leverage these vulnerabilities.







