Now Available: Active Cyber Insurance for Enterprises
Cyber Incident? Get Help

Two Citrix RCE Zero Days Exploited in the Wild

Citrix 2 Zero Days Exploited in the Wild

On September 26, Coalition alerted at-risk policyholders to two Citrix NetScaler zero-day vulnerabilities following unconfirmed reports of active exploitation from reliable sources. 

At the time of our Zero-Day Alert, Citrix had not publicly acknowledged the vulnerabilities. We observed increased scanning for NetScaler assets on Coalition honeypots, which may indicate threat actors are preparing for or running attacks. As a result, we recommended that policyholders disconnect devices from the internet if possible, restrict access if not possible to disconnect, and patch once it became available. 

On September 27, Citrix officially published a security bulletin confirming the vulnerabilities and released patches for the impacted NetScaler appliances. We have since followed up with affected policyholders to provide additional remediation guidance.

What’s happening?

Citrix confirmed that exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments were observed in the wild.

  • CVE-2026-88771 is a critical remote code execution (RCE) vulnerability that can allow an unauthenticated attacker to execute arbitrary commands.

  • CVE-2026-88772 is a memory overflow vulnerability that can lead to remote code execution or a denial-of-service condition. 

The patch also addressed six other flaws. NetScaler is a popular target for cyber criminals because it provides remote access to internal applications and desktops and is often exposed directly to the internet. NetScaler is widely used by enterprises across all industries, further supporting how lucrative these zero days can be for attackers.

Given the severe consequences of successful exploitation, immediate action is necessary. Before Citrix publicly acknowledged the vulnerabilities, IT suppliers, security researchers, and the Dutch National Cyber Security Center had already begun its own outreach to potentially impacted organizations. Security teams then flocked to Reddit, awaiting additional information or confirmation from Citrix.

Not a “Secure by Design” response

In 2025, Citrix signed CISA’s Secure by Design pledge, committing to seven measurable product-security goals alongside hundreds of other vendors. The premise is simple: when a vulnerability emerges, vendors should disclose it quickly, share what they know about active exploitation, and give customers actionable guidance — even before a patch is ready.

On these two zero days, Citrix’s public communications lagged the initial reports by at least 36 hours, based on our timeline. 

In today’s threat environment, 36 hours is an eternity. During that window, customers had neither clear guidance nor a confirmed scope of impact. They didn’t have acknowledgement of new vulnerabilities at all and Citrix customers were left to fend for themselves.

The disconnect between a public commitment and what customers experience in practice matters more today than ever. AI is compressing the window between discovery and mass exploitation, so response timelines that once seemed merely slow are becoming materially riskier. The end user still bears much of the responsibility for securing the technology they buy, despite being the party least equipped to do so. 

On these two zero days, Citrix’s public communications lagged the initial reports by at least 36 hours, based on our timeline. 

When a zero day lands and guidance is slow, customers are left treading water with both hands tied, unsure how deep the water is or how long they’ll be treading.

This is why Active Insurance exists. Wherever gaps in vendor response appear, someone needs to sit on the policyholder’s side of the table: monitoring threats, translating them into plain language, and helping customers respond quickly. Security cannot stop at the vendor’s product team; it must extend to the customers who rely on that product when the stakes are highest.

How should businesses address this?

The following supported versions of Citrix NetScaler ADC and Citrix NetScaler Gateway are affected by the vulnerabilities:

  • Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 BEFORE 14.1-73.37

  • Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 BEFORE 13.1-64.23

  • Citrix NetScaler ADC FIPS BEFORE 14.1-73.37 FIPS

  • Citrix NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.279

Organizations running any of the above versions of NetScaler ADC and NetScaler Gateway should install the relevant updated versions as soon as possible, as vulnerabilities are being actively exploited. Those that cannot immediately patch should limit exposure to the internet until they can patch. 

More detailed guidance for remediation can be found in Citrix’s security bulletin, including details on all eight vulnerabilities and steps to determine if an appliance meets the CVE preconditions. Citrix has also made generic Indicators of Compromise available through NetScaler Console to help customers determine if their NetScaler deployments have been affected.

Who’s at risk?

Enterprises rely on Citrix NetScaler worldwide to manage traffic and authentication. Given the nature of both zero days (each with a 9.5 severity score), cybersecurity agencies in the UK, US, and the Netherlands all released advisories confirming the vulnerabilities. 

Citrix Bleed One and Citrix Bleed Two, prior NetScaler zero days, led to high-profile breaches impacting critical infrastructure, healthcare entities, and major companies. 

How Coalition is responding

Following our initial outreach on September 26, we have followed up with policyholders to ensure that they are aware a patch is available, both through email and in some cases, ongoing direct phone calls. 

For assistance with mitigation, contact Coalition’s Security Support Center at securitysupport@coalitioninc.com.


SPOT & STOP CYBER THREATS 

Coalition Control

Take control of your cyber risk >


This blog post is designed to provide general information on the topic presented and is not intended to construe or render legal or other professional services of any kind. If legal or other professional advice is required, the services of a professional should be sought. The views and opinions expressed as part of this blog post do not necessarily state or reflect those of Coalition. Neither Coalition nor any of its employees make any warranty of any kind, express or implied, or assume any legal liability or responsibility for the accuracy, completeness, or usefulness of any information, product, or process disclosed. Any action you take upon the information contained herein is strictly at your own risk. Coalition and its affiliates will not be liable for any losses and damages in connection with your use or reliance upon the information. The blog post may include links to other third-party websites. These links are provided as a convenience only. Coalition does not endorse, have control over, nor assumes responsibility or liability for the content, privacy policy, or practices of any such third-party websites.
Copyright © 2026. All rights reserved. Coalition and the Coalition logo are trademarks of Coalition, Inc.

Related blog posts

See all articles
Security

Blog

Outcomes Over Alert Queues: Rebuilding MDR Around Speed

Coalition was recognized in “The Managed Detection And Response Services Landscape, Q3 2026” report by Forrester Research Inc.
Tim MalcomVetterSeptember 17, 2026
Security

Blog

How Third Wave Innovations Shifted from Reactive Triage to Automated Verdicts with Wirespeed

By transitioning to Wirespeed, Third Wave Innovations has scaled its core business with unprecedented precision.
Gregory AndersenSeptember 15, 2026
Security

Blog

Inbox In-Fighting: A Window Into BEC Subculture

Coalition Incident Response has observed threat actors using the names of inbox rules to communicate. What did we learn from hidden chats?
Chris HendricksSeptember 03, 2026