Citrix Patches Critical Zero Days Under Active Exploitation

▼ Summary
– Citrix has released updates for eight new vulnerabilities in NetScaler ADC and NetScaler Gateway, including two critical zero-day flaws under active exploitation.
– The most urgent issues are CVE-2026-88771, an unauthenticated remote code execution flaw, and CVE-2026-88772, a memory overflow vulnerability affecting DTLS configurations.
– Global cybersecurity agencies such as the Australian ACSC, Dutch NCSC-NL, and US CISA have issued alerts and mandates urging immediate patching of these systems.
– Reports indicate that exploitation attempts are ongoing, with historical context linking similar Citrix zero-days to China-based threat actor Salt Typhoon.
– The remaining five vulnerabilities include HTTP request smuggling and various memory overflow or prediction flaws, all requiring prompt attention from customer-managed deployments.
Citrix has released emergency security updates for eight new vulnerabilities affecting its NetScaler ADC and NetScaler Gateway platforms, addressing two critical zero-day exploits that are currently being actively weaponized by threat actors. The vendor’s September 27 bulletin detailed flaws with CVSS scores ranging from 7 to 9.5, emphasizing the urgent need for administrative action to secure these widely deployed network appliances.
The most severe of the newly disclosed issues involves CVE-2026-88771, a remote code execution (RCE) vulnerability stemming from improper input validation. This flaw allows unauthenticated attackers to execute arbitrary commands on systems running default configurations. Simultaneously, CVE-2026-88772 presents a memory overflow risk that can lead to RCE or denial of service conditions. This second zero-day impacts any deployment where DTLS configuration is enabled, which remains the standard setting for VPN virtual servers.
“Exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments has been observed,” Citrix said in a blog post. “Citrix strongly urges affected customers to install the relevant updated versions as soon as possible.”
Beyond the active zero-days, the update addresses CVE-2026-88773, a critical HTTP request smuggling vulnerability with a CVSS score of 9.3. This issue arises when HTTP configuration is enabled on NetScaler ADC or NetScaler Gateway instances. Prior to the official disclosure, reports had already circulated regarding the exploitation of these zero-day bugs, prompting immediate responses from global cybersecurity bodies.
Global Response and Historical Context
Government agencies worldwide have moved quickly to mitigate the risk. The Australian Signals Directorate’s Australian Cyber Security Centre (ACSC) issued a critical alert on September 28, urging organizations to apply patches immediately. Similarly, the Dutch National Cyber Security Center (NCSC-NL) reportedly sent alerts to local entities, while the US Cybersecurity and Infrastructure Security Agency (CISA) mandated that federal agencies patch their systems by Wednesday, September 30.
While attribution for the current campaign remains unclear, historical context suggests state-sponsored activity. In 2025, a cyber intrusion linked to the China-based group Salt Typhoon targeted a Citrix zero-day, highlighting the persistent interest in these high-value targets.
Additional Vulnerabilities and Scope
The remaining five vulnerabilities included in the bulletin cover various severity levels, primarily focusing on memory management and policy bypasses:
- CVE-2026-88774: A feature policy bypass due to improper HTTP URL-based expression usage (CVSS 7).Citrix clarified that this bulletin specifically applies to customer-managed Citrix NetScaler ADC and Citrix NetScaler Gateway environments. For cloud-based services, the vendor noted that the Cloud Software Group handles updates separately. “Cloud Software Group upgrades the Citrix-managed cloud services and Citrix-managed Adaptive Authentication with the necessary software updates,” the company confirmed, ensuring that managed customers do not need to take manual action for those specific offerings.


