Over the past weekend, Citrix issued urgent updates to address two critical zero-day vulnerabilities found in its NetScaler products. These vulnerabilities have reportedly been actively exploited, prompting a swift response from the company.
Overview of the Vulnerabilities
Citrix’s advisory detailed eight security issues impacting NetScaler ADC and NetScaler Gateway. Among these, remote code execution, HTTP request smuggling, denial of service (DoS), and security bypass vulnerabilities were highlighted. The two zero-day flaws, tracked as CVE-2026-88771 and CVE-2026-88772, were confirmed to have been exploited in the field.
With a high CVSS score of 9.5, CVE-2026-88771 poses a significant threat as it allows remote code execution without needing authentication. This vulnerability impacts all default configurations of NetScaler ADC and Gateway. Meanwhile, CVE-2026-88772, characterized as a memory overflow issue, can be leveraged for remote code execution or DoS attacks, particularly affecting appliances with DTLS enabled by default on VPN virtual servers.
Community and Government Response
Over the weekend, administrators managing NetScaler products reported receiving directives from IT suppliers, CERT teams, and MDR providers to immediately deactivate their systems. This advice often came with little explanation, causing confusion among users. These alerts were traced back to a confidential pre-notification from the Dutch National Cyber Security Centre (NCSC-NL), which had been shared under strict TLP:AMBER conditions.
The NCSC-NL’s communication, shared on Reddit, mentioned that the zero-day vulnerabilities were identified through collaboration with a European partner CERT, affecting numerous Citrix clients globally. While some administrators took proactive measures to shut down their systems, others reported not having received any official notification.
Official Recommendations and Future Outlook
The Cybersecurity and Infrastructure Security Agency (CISA) acted quickly, incorporating CVE-2026-88771 and CVE-2026-88772 into its Known Exploited Vulnerabilities (KEV) catalog. CISA issued a cautionary alert to emphasize that these vulnerabilities are being actively targeted worldwide. The agency urged users and administrators to thoroughly review Citrix’s advisories and check for any signs of compromise before applying patches.
Currently, CISA’s KEV catalog includes over a dozen vulnerabilities related to Citrix NetScaler, among them the newly listed CVE-2026-19490 and CVE-2026-8452. The urgency of addressing these vulnerabilities underscores the critical nature of maintaining updated security measures in today’s digital landscape.
In conclusion, Citrix’s rapid response to these vulnerabilities highlights the ongoing challenges in cybersecurity. Users and administrators are advised to stay informed and act swiftly to protect their systems against potential threats.
