NetScaler Admins Told to Patch Critical Zero-Days in ADC and Gateway Now
Citrix said the flaws include two critical 9.5-rated bugs and one 9.3-rated issue that can allow remote code execution and request smuggling.
- On Sunday, the United States Cybersecurity and Infrastructure Security Agency issued an alert confirming threat actors are actively exploiting critical vulnerabilities in Citrix NetScaler globally.
- Citrix published a bulletin on Sunday warning of eight CVEs, with CVE-2026-88771 and CVE-2026-88772 rated critical at 9.5 CVSS scores.
- Risk management efforts must address the 9.3-rated CVE-2026-88773, allowing HTTP request smuggling, and an 8.8-rated bug related to TCP Initial Sequence Number prediction.
- A Reddit thread alleges at least one Citrix channel partner knew of these flaws on Saturday, a day before the disclosure prompted CISA to issue its warning.
- Thankfully, Citrix has released refreshes containing necessary fixes, as NetScaler remains a frequent target on the annual most-exploited bugs list published by Five Eyes.
19 Articles
19 Articles
NetScaler admins told to patch critical zero-days in ADC and Gateway now
Citrix NetScaler ADC and NetScaler Gateway users should take their systems offline and patch them immediately, they were told over the weekend, as news emerged of two critical unauthenticated remote code execution zero-day vulnerabilities in the products under active attack. “Monday will be too late,” watchtower CEO Benjamin Harris wrote in a LinkedIn post on Sunday. Citrix subsequently confirmed the two remotely exploitable vulnerabilities were…
Citrix confirms two exploited NetScaler zero-days
Citrix has confirmed active exploitation of two critical NetScaler RCE flaws, CVE-2026-88771 and CVE-2026-88772, both rated 9.5, and released fixes in CTX697096. Affected products include NetScaler ADC and Gateway, with DTLS-dependent exposure noted...
Citrix has confirmed that two critical vulnerabilities in its NetScaler products are already under active attack all over the world. The company has published a newsletter on eight CVE, and the issue of vulnerabilities Citrix NetScaler has immediately alarmed the IT security agencies of half the planet. Key points Citrix has released a newsletter out of eight [...]
CERT.se warns of CVE-2026-88771 and CVE-2026-88772, two critical vulnerabilities in Citrix Netscaler ADC and Citrix Netscaler Gateway. The vulnerabilities in question have been given a CVSS rating of 9.5, which means that exploiting the vulnerabilities could lead to unauthenticated remote code execution on vulnerable instances. To be on the safe side, users are therefore advised to install the latest updates for Citrix Netscaler as soon as possi…
Coverage Details
Bias Distribution
- 75% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium











