Two critical zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances are reportedly being exploited in the wild, raising serious concerns for organisations that rely on the products for remote access and application delivery. Security firm watchTowr disclosed the activity on September 26, stating that attackers had used the flaws to achieve remote code execution before Citrix released patches or detailed technical guidance. The company warned that the vulnerabilities could allow attackers to compromise exposed appliances and potentially gain access to connected networks.
According to watchTowr, the flaws were discovered during forensic investigations into suspected intrusions. Both vulnerabilities reportedly enable remote code execution, meaning an unauthenticated attacker could potentially execute malicious commands on a vulnerable NetScaler device. Because these appliances frequently sit at the edge of corporate networks and handle VPN or application access, a successful compromise could provide attackers with an important entry point for credential theft, lateral movement, data exfiltration or ransomware deployment.
At the time of the initial disclosure, Citrix had not confirmed the vulnerabilities, published affected-version information or released a security update. The absence of official indicators of compromise or a reliable workaround left administrators with limited options. Some organisations reportedly chose to take NetScaler appliances offline to reduce the risk, although doing so can disrupt remote workers, business applications and customer-facing services. Researchers expected Citrix to issue communications and patches during the week beginning September 28.
The situation later developed when Citrix confirmed that two critical NetScaler flaws had been exploited and released fixes alongside patches for six additional vulnerabilities. The issues were identified as CVE-2026-88771 and CVE-2026-88772, both carrying a CVSS score of 9.5. The first is an improper input-validation vulnerability that could allow an unauthenticated attacker to run arbitrary commands, while the second involves improper memory-buffer restrictions and could lead to remote code execution or denial-of-service attacks.
Security teams should treat these vulnerabilities as an emergency priority. Administrators should identify all internet-facing NetScaler ADC and Gateway systems, apply Citrix’s latest fixes immediately and review logs for unusual authentication, configuration or administrative activity. Organisations should also rotate potentially exposed credentials, inspect connected systems for signs of post-compromise activity and restrict management access wherever possible. CISA’s addition of both flaws to its Known Exploited Vulnerabilities catalogue further underlines the urgency of patching and incident investigation.
