Critical

Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway

All CISA Advisories
Actively Exploited

Overview

The Cybersecurity and Infrastructure Security Agency (CISA) has reported eight critical vulnerabilities in Citrix NetScaler ADC and Citrix NetScaler Gateway products, specifically CVE-2026-88771 through CVE-2026-88778. Among these, CVE-2026-88771 and CVE-2026-88772 are particularly concerning as they are zero-day vulnerabilities, meaning they are actively being exploited by attackers. CISA has confirmed that these vulnerabilities allow for remote code execution, which poses a significant risk to organizations using these systems. Citrix has published advisories and indicators of compromise to help users assess their exposure and take necessary actions. Organizations are urged to check for signs of compromise before applying patches, as doing so may erase critical forensic evidence.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: Citrix NetScaler ADC, Citrix NetScaler Gateway, CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, CVE-2026-88778
  • Action Required: Organizations should review Citrix's advisories for CVE-2026-88771 through CVE-2026-88778.
  • Timeline: Newly disclosed

Original Article Summary

CISA is amplifying Citrix’s disclosure of eight new vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway products: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778. CISA has added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) Catalog. Both are critical, zero-day vulnerabilities that can independently enable remote code execution. CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally. Because updating Citrix NetScaler appliances can be complex and may require downtime, CISA is issuing this Alert to help organizations assess exposure, prioritize mitigation, and account for these vulnerabilities into their risk-management activities. Given the potential consequences of successful exploitation and the fact that malicious actors are exploiting at least some of these vulnerabilities, CISA urges users and administrators to review Citrix’s advisories. If possible, users are encouraged to check for indication of compromise prior to patching. Citrix has made indicators of compromise available through NetScaler Console and published additional guidance in their recent publication, Security Bulletin for CVE-2026-88771 through CVE-2026-88778, to support organizations in assessing potential compromise. Should your organization suspect compromise, it is important to preserve forensic evidence prior to applying updates, as updates may result in loss of forensic visibility. Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778 - Security Updates - Citrix Community Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778 Steps to Take if NetScaler ADC is Suspected to be Compromised Disclaimer The information in this report is being provided “as is” for informational purposes only. CISA does not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this document. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by CISA.

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Newly disclosed

Remediation

Organizations should review Citrix's advisories for CVE-2026-88771 through CVE-2026-88778. Users are encouraged to check for indicators of compromise in the NetScaler Console prior to patching. If a compromise is suspected, preserve forensic evidence before applying updates to avoid losing visibility.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to CVE, Zero-day, Critical.

Related Coverage

⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats

The Hacker News

This week saw a notable rise in cyber threats, including a $387 million cryptocurrency hack that has raised alarms in the crypto community. Attackers registered a previously harmless domain that appeared in about 1,700 repositories and began using it to distribute malicious content. This incident illustrates how old assumptions about security can be exploited by cybercriminals. Additionally, weak service accounts, outdated vulnerabilities, and exposed systems continue to provide attackers with easy access points. Companies and users alike need to remain vigilant and update their security measures to protect against these ongoing threats.

Sep 28, 2026

Webinar: How to Govern AI Agents, Reduce Excessive Access, and Control Shadow AI

The Hacker News

AI agents are increasingly being deployed in business environments without adequate security oversight, posing significant risks. These agents are capable of accessing applications, managing data, and interacting with APIs, often without the same safeguards that protect human users. A report from Okta found that just 47% of Chief Information Security Officers (CISOs) are confident in their ability to identify all AI agents in their systems. This lack of visibility can lead to unauthorized access and data breaches, making it crucial for organizations to establish stronger governance frameworks for AI usage. As AI continues to evolve and integrate into various business functions, companies must prioritize security measures to mitigate these risks.

Sep 28, 2026

Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent

The Hacker News

Researchers have identified a new botnet named Carbonato that is specifically targeting exposed Docker daemons. This malware deploys an AI framework called Hermes Agent, which is open-source. Once installed, Carbonato modifies the framework's persona file to execute tasks sent through Telegram. This is concerning because it allows attackers to remotely control compromised systems, potentially leading to unauthorized access and exploitation of Docker environments. Organizations using Docker should ensure their daemons are properly secured to prevent unauthorized access and deployment of such malware.

Sep 28, 2026

JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources

The Hacker News

In June 2026, the hacking group JADEPUFFER, tracked by Microsoft as Storm-3168, executed a significant attack on Azure environments using compromised service principals. Over approximately 18 hours, the attackers managed to delete various Azure resources, showcasing an advanced level of sophistication in their methods. This incident raises alarms for organizations relying on Azure, as it highlights vulnerabilities in how service principals can be exploited. Companies must reassess their security measures to protect against such intrusions, especially those tied to critical cloud infrastructure. The incident serves as a reminder of the ongoing risks associated with cloud services and the importance of robust access controls.

Sep 28, 2026

CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally

The Hacker News

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has flagged two serious vulnerabilities in Citrix NetScaler ADC and Gateway systems that are currently being exploited by attackers. The first vulnerability, identified as CVE-2026-88771, has a CVSS score of 9.5, indicating its severity. This flaw allows unauthenticated attackers to potentially gain unauthorized access. Organizations using these Citrix products should be particularly vigilant, as the vulnerabilities can lead to significant security breaches. CISA's inclusion of these flaws in its Known Exploited Vulnerabilities catalog emphasizes the urgency for affected users to take immediate action to protect their systems.

Sep 28, 2026

CISA orders feds to patch exploited Citrix flaws by Wednesday

BleepingComputer

The Cybersecurity and Infrastructure Security Agency (CISA) has instructed U.S. federal agencies to address two serious vulnerabilities in Citrix NetScaler products. These flaws could allow attackers to exploit the systems, leading to unauthorized access and potential data breaches. CISA's directive comes after evidence surfaced that these vulnerabilities are actively being targeted in the wild. Agencies are urged to implement patches by the upcoming Wednesday to secure their systems. This incident emphasizes the ongoing risks associated with critical infrastructure and the need for timely updates to protect sensitive government data.

Sep 28, 2026