Skip to content
Unlisted Report logoUnlisted ReportSubscribe
Vulnerabilities

CISA warns of exploited Citrix NetScaler zero-days

Two critical NetScaler ADC and Gateway flaws allowing remote code execution are being exploited worldwide, CISA says. Check for compromise before patching.

By · Published · Updated · 4 min read

Lock image for the Citrix NetScaler zero-day alert

CISA has issued an alert after Citrix disclosed eight new vulnerabilities in NetScaler ADC and NetScaler Gateway, two of which are already being exploited, according to CISA.

The flaws

  • CVE-2026-88771 and CVE-2026-88772 are critical zero-days that can each allow remote code execution. Both are in CISA's Known Exploited Vulnerabilities catalog.
  • Six more flaws, CVE-2026-88773 to CVE-2026-88778, were disclosed at the same time.

CISA says it has partner reports confirming exploitation globally.

Why NetScaler bugs are so dangerous

NetScaler appliances sit at the edge of corporate networks and handle remote access for staff. Taking one over gives attackers a trusted position inside the network and access to user sessions. Past NetScaler flaws, such as "Citrix Bleed", were used by ransomware gangs and state hackers against thousands of organizations.

What to do now

  1. Check for compromise first. Citrix has published indicators of compromise in NetScaler Console.
  2. Preserve evidence. CISA warns updates may wipe forensic data, so capture logs and images if you suspect a breach.
  3. Patch to the fixed versions in Citrix's security bulletin.
  4. End active sessions and rotate credentials after patching.

Sources

Read next