Two Citrix RCE Zero Days Exploited in the Wild

On September 26, Coalition alerted at-risk policyholders to two Citrix NetScaler zero-day vulnerabilities following unconfirmed reports of active exploitation from reliable sources.
At the time of our Zero-Day Alert, Citrix had not publicly acknowledged the vulnerabilities. We observed increased scanning for NetScaler assets on Coalition honeypots, which may indicate threat actors are preparing for or running attacks. As a result, we recommended that policyholders disconnect devices from the internet if possible, restrict access if not possible to disconnect, and patch once it became available.
On September 27, Citrix officially published a security bulletin confirming the vulnerabilities and released patches for the impacted NetScaler appliances. We have since followed up with affected policyholders to provide additional remediation guidance.
What’s happening?
Citrix confirmed that exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments were observed in the wild.
CVE-2026-88771 is a critical remote code execution (RCE) vulnerability that can allow an unauthenticated attacker to execute arbitrary commands.
CVE-2026-88772 is a memory overflow vulnerability that can lead to remote code execution or a denial-of-service condition.
The patch also addressed six other flaws. NetScaler is a popular target for cyber criminals because it provides remote access to internal applications and desktops and is often exposed directly to the internet. NetScaler is widely used by enterprises across all industries, further supporting how lucrative these zero days can be for attackers.
Given the severe consequences of successful exploitation, immediate action is necessary. Before Citrix publicly acknowledged the vulnerabilities, IT suppliers, security researchers, and the Dutch National Cyber Security Center had already begun its own outreach to potentially impacted organizations. Security teams then flocked to Reddit, awaiting additional information or confirmation from Citrix.
Not a “Secure by Design” response
In 2025, Citrix signed CISA’s Secure by Design pledge, committing to seven measurable product-security goals alongside hundreds of other vendors. The premise is simple: when a vulnerability emerges, vendors should disclose it quickly, share what they know about active exploitation, and give customers actionable guidance — even before a patch is ready.
On these two zero days, Citrix’s public communications lagged the initial reports by at least 36 hours, based on our timeline.
In today’s threat environment, 36 hours is an eternity. During that window, customers had neither clear guidance nor a confirmed scope of impact. They didn’t have acknowledgement of new vulnerabilities at all and Citrix customers were left to fend for themselves.
The disconnect between a public commitment and what customers experience in practice matters more today than ever. AI is compressing the window between discovery and mass exploitation, so response timelines that once seemed merely slow are becoming materially riskier. The end user still bears much of the responsibility for securing the technology they buy, despite being the party least equipped to do so.
On these two zero days, Citrix’s public communications lagged the initial reports by at least 36 hours, based on our timeline.
When a zero day lands and guidance is slow, customers are left treading water with both hands tied, unsure how deep the water is or how long they’ll be treading.
This is why Active Insurance exists. Wherever gaps in vendor response appear, someone needs to sit on the policyholder’s side of the table: monitoring threats, translating them into plain language, and helping customers respond quickly. Security cannot stop at the vendor’s product team; it must extend to the customers who rely on that product when the stakes are highest.
How should businesses address this?
The following supported versions of Citrix NetScaler ADC and Citrix NetScaler Gateway are affected by the vulnerabilities:
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 BEFORE 14.1-73.37
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 BEFORE 13.1-64.23
Citrix NetScaler ADC FIPS BEFORE 14.1-73.37 FIPS
Citrix NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.279
Organizations running any of the above versions of NetScaler ADC and NetScaler Gateway should install the relevant updated versions as soon as possible, as vulnerabilities are being actively exploited. Those that cannot immediately patch should limit exposure to the internet until they can patch.
More detailed guidance for remediation can be found in Citrix’s security bulletin, including details on all eight vulnerabilities and steps to determine if an appliance meets the CVE preconditions. Citrix has also made generic Indicators of Compromise available through NetScaler Console to help customers determine if their NetScaler deployments have been affected.
Who’s at risk?
Enterprises rely on Citrix NetScaler worldwide to manage traffic and authentication. Given the nature of both zero days (each with a 9.5 severity score), cybersecurity agencies in the UK, US, and the Netherlands all released advisories confirming the vulnerabilities.
Citrix Bleed One and Citrix Bleed Two, prior NetScaler zero days, led to high-profile breaches impacting critical infrastructure, healthcare entities, and major companies.
How Coalition is responding
Following our initial outreach on September 26, we have followed up with policyholders to ensure that they are aware a patch is available, both through email and in some cases, ongoing direct phone calls.
For assistance with mitigation, contact Coalition’s Security Support Center at securitysupport@coalitioninc.com.
SPOT & STOP CYBER THREATS
Coalition Control
Take control of your cyber risk >






