Citrix NetScaler zero-days under attack, CISA warns

Published

Attackers are exploiting two critical zero-day flaws in Citrix NetScaler ADC and NetScaler Gateway, the remote-access appliances many organizations expose to the internet. The US Cybersecurity and Infrastructure Security Agency (CISA) added both bugs, CVE-2026-88771 and CVE-2026-88772, to its Known Exploited Vulnerabilities (KEV) catalog on September 27, 2026, and issued a separate alert saying it has reports and partner threat intelligence confirming the flaws are being exploited globally.

The two zero-days are part of a batch of eight vulnerabilities Citrix disclosed in a single security bulletin covering CVE-2026-88771 through CVE-2026-88778. According to CISA, each of the two exploited flaws can independently enable remote code execution, meaning an attacker does not need to chain them together to run code on an appliance.

Two of eight flaws are already in use

The CVE records for the batch, published to the National Vulnerability Database on September 27, give the following severity scores (CVSS v4, higher is worse):

CISA says malicious actors are exploiting "at least some" of the eight. Only the first two carry a KEV listing, and neither CISA nor Citrix has published details of who is behind the attacks or which organizations have been hit. The Citrix bulletin carries the technical detail for each flaw.

NetScaler has been a repeated target this year. IntelFusions has covered a SAML heap overflow that let attackers hijack NetScaler VPN gateways in August, and an access broker that exploited an earlier Citrix bug to plant DragonForce ransomware in July.

Hunt first, then patch to 14.1-73.37 or 13.1-64.23

According to the CVE records, the flaws are fixed in the following releases, and every earlier build of these branches is affected:

CISA's advice has an unusual order of operations. Because the bugs were exploited as zero-days, the agency encourages administrators to check for signs of compromise before patching where possible. Citrix has made indicators of compromise available through NetScaler Console and has published steps to take if an appliance is suspected to be compromised. If an organization suspects a breach, CISA says it should preserve forensic evidence first, since applying the update may destroy the forensic visibility investigators need.

CISA also acknowledges that updating NetScaler appliances can be complex and may require downtime, which is precisely why it issued a standalone alert rather than relying on the KEV listing alone. US federal civilian agencies are bound by the KEV catalog to remediate; everyone else is urged to treat it as a priority list.

The lesson from earlier NetScaler waves is that patching closes the door but does not evict anyone already inside. An appliance that was reachable from the internet before the fix should be treated as a place to look, not just a box to update.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions