Two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway that allow remote code execution have been exploited in the wild, Citrix confirmed on September 27. It released fixes for both, along with six other flaws. One of the two affects every deployment on an affected version, including those in the default configuration.
The bulletin came a day after security firm watchTowr
Swati KhandelwalSep 27, 2026Vulnerability / Network Security
Two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway that allow remote code execution have been exploited in the wild, Citrix confirmed on September 27. It released fixes for both, along with six other flaws. One of the two affects every deployment on an affected version, including those in the default configuration.
The bulletin came a day after security firm watchTowr said two unpatched NetScaler RCE flaws had been exploited, and after some administrators said they had taken appliances offline. Citrix did not say whether its two flaws are the ones watchTowr described, but they match that account.
NetScaler ADC and NetScaler Gateway sit at the edge of enterprise networks, where they handle VPN and remote access, load balancing, and user authentication.
Citrix said in its bulletin that the two exploited flaws are:
"Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed," the company said. It did not say how widely the flaws have been exploited, by whom, or since when.
The bulletin is Citrix's first public notice of the flaws, so both were attacked before a fix was public. It lists no workaround for either and no indicators of compromise.
Appliances on 14.1-73.32 and 13.1-63.21, the builds that fixed the exploited authentication bypass CVE-2026-19490 in August, fall inside the affected range and need the new update.
The fixes are in the following versions, which Citrix urged affected customers to install as soon as possible:
The bulletin covers customer-managed appliances, including NetScaler instances used in Secure Private Access Hybrid deployments. Citrix upgrades its own cloud services and Citrix-managed Adaptive Authentication.
The 13.1 fix arrives after that branch reached End of Maintenance on September 15 under Citrix's release schedule.
The six other flaws, which the bulletin does not list as exploited, are:
watchTowr's first post on X on September 26 said it was reacting to rumors of several unpatched NetScaler RCE vulnerabilities in the wild. "While details are scarce, the information is credible," it wrote. A follow-up post at 22:19 UTC said the two flaws were discovered during forensic investigations and that Citrix communications and patches were expected early in the week of September 28.
On September 26, an administrator posting on r/Citrix wrote that their IT supplier's security team had phoned to advise shutting their NetScalers down immediately, without giving details. Others in the thread said their organizations had done the same. Where the suppliers' warning came from has not been established.
Because the flaws were exploited before a fix was public, installing the update will not show whether an attacker got in first.
In 2025, after a NetScaler flaw was exploited as a zero-day against Dutch organizations, the Netherlands' National Cyber Security Centre said that updating alone did not remove the risk, because an attacker could keep access gained before the patch, and told administrators to run its check scripts.
Citrix's existing guidance for a suspected NetScaler compromise says to:
The Dutch agency's 2025 check scripts, which cover a live appliance, core dumps, and full NetScaler images, are a further option, with limits.
The README for the live-appliance script says it looks for files that indicate compromise, is not specific to one vulnerability, and comes with no guarantee of effectiveness. The code was last updated in September 2025.
The Hacker News has asked Cloud Software Group, the company that owns Citrix and NetScaler, and watchTowr for comment, and will update the story if it hears back.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally | 0 | 7.63 | 28-09-2026 |
| 2 | Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT | 0 | 7.9 | 30-09-2026 |
| 3 | Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution | 0 | 8.39 | 30-09-2026 |
| 4 | Citrix Netscaler: Kritische Sicherheitslücken erlauben Codeeinschleusung | 0 | 9.03 | 27-09-2026 |
| 5 | Два нулевых дня в Citrix NetScaler эксплуатируют неделями, администраторы отключают шлюзы | 0 | 9.11 | 29-09-2026 |
| 6 | Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager | 0 | 9.95 | 30-09-2026 |
| 7 | Две zero-day без пароля открыли хакерам корпоративные VPN | 0 | 15.56 | 28-09-2026 |
| 8 | SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild | 0 | 6.8 | 26-09-2026 |
| 9 | WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV | 0 | 9.71 | 25-09-2026 |
| 10 | Zimbra zero-day exploit exposes mail servers to attack, Microsoft warns | 0 | 16.62 | 30-09-2026 |