Particle.news
Download on the App Store

Citrix Confirms Two NetScaler Zero-Day Flaws Were Exploited

The bugs let attackers run code on edge VPN and gateway appliances, prompting urgent patches or isolation to prevent and investigate active breaches.

Overview

  • Citrix disclosed on Sunday that two critical NetScaler zero-days, now tracked as CVE-2026-88771 and CVE-2026-88772, were exploited in the wild and the company released fixes for affected 14.1 and 13.1 builds.
  • CVE-2026-88771 is an unauthenticated input-validation flaw that allows remote code execution and CVE-2026-88772 is a DTLS-related memory overflow that can cause remote code execution or denial of service.
  • Citrix published updated builds (including 14.1-73.37 and 13.1-64.23) and added a generic IoC scan in NetScaler Console starting with 14.1-73.36, but the vendor warns those detections require telemetry and may miss attacker techniques.
  • Before the public advisory, administrators, CERTs and IT suppliers privately urged organizations to isolate or take NetScaler appliances offline, and earlier August fixes do not address these new zero-days.
  • Because NetScaler devices sit at the network edge and attackers can keep access after a breach, Citrix and national CSIRTs advise preserving evidence, running forensic reviews, rotating credentials and seeking expert help rather than relying on patching alone.