Signal

Citrix confirms two critical NetScaler zero-day RCE vulnerabilities are being exploited in attacks, says it has released security updates to fix the flaws

First reported by Bleepingcomputer ·

The signal ●●●● Compiled by AI from Bleepingcomputer, Techmeme, iTnews, CISA, Cyber Daily and 5 more
Why you might care

If you manage NetScaler devices, you must immediately apply security updates to prevent exploitation of two critical remote code execution vulnerabilities.

What happened

Citrix has confirmed that two critical zero-day vulnerabilities in its NetScaler Application Delivery Controller (ADC) and Gateway devices are actively being exploited by threat actors. The vulnerabilities, CVE-2026-88771 and CVE-2026-88772, both rated 9.5 out of 10, allow for remote code execution (RCE). CVE-2026-88771 requires no preconditions, while CVE-2026-88772 is a memory overflow bug affecting devices with datagram transport layer security (DTLS) enabled, which is on by default for NetScaler Gateways. Citrix has released urgent security updates to address these flaws, as well as six other disclosed zero-day vulnerabilities. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the two critical flaws to its Known Exploited Vulnerabilities catalog, mandating immediate action for U.S. government entities. Australian authorities have also recommended organizations operating vulnerable Citrix products install the updates and review their device logging for suspicious activity.

What it means

The active exploitation of these NetScaler zero-days signifies a persistent threat landscape where critical infrastructure components remain attractive targets for sophisticated attackers. The fact that these vulnerabilities are being exploited in the wild, rather than being discovered and patched proactively, highlights the ongoing cat-and-mouse game between security vendors and threat actors. Organizations relying on NetScaler for application delivery and secure remote access are at immediate risk, necessitating rapid patching to mitigate potential breaches and ensure service continuity.

This situation underscores the importance of robust vulnerability management programs and the critical role of supply chain security, as flaws in widely used infrastructure software can have far-reaching consequences. The inclusion on CISA's KEV list and advisories from other cybersecurity agencies indicate a high level of concern and the potential for widespread impact, urging administrators to not only patch but also to audit their systems for signs of compromise and review their security configurations.

AI-written summary. May contain errors.

Amazon Security