Security17 publishers2 min readPublished Updated
Citrix patches two NetScaler zero-days that attackers used before any fix existed
Citrix shipped fixes on September 27 for NetScaler flaws CVE-2026-88771 and CVE-2026-88772, both rated 9.5 and exploited on unpatched appliances. Exploitation began before the fix, at a date Citrix has not given, so affected appliances need an intrusion check as well as an upgrade.
The Watch · Security desk

What happened
- Each of the two flaws is rated critical, and either one on its own can give an attacker remote code execution on NetScaler ADC or Gateway.
- The pair are two of eight vulnerabilities Citrix disclosed in NetScaler ADC and Gateway, numbered CVE-2026-88771 through CVE-2026-88778.
- Citrix has published indicators of compromise through NetScaler Console, along with a security bulletin covering all eight CVEs.
- CISA says updating NetScaler appliances can be complex and may require downtime, and gives that as its reason for issuing the alert.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- decision A patch does not settle whether an appliance was entered. Owners have to decide, box by box, whether to capture evidence first, because the update may remove what an investigator needs.
- exposure Any NetScaler reachable while these were zero-days may already have been exploited. A fully updated appliance can still hold an attacker who got in before the fix.
- constraint The maintenance window has to fit the compromise check and evidence capture as well as the update itself and whatever outage it brings.
CISA's alert sets an order of work. Where possible, owners should look for signs of compromise before they patch [6]. Both flaws were exploited as zero-days, before any fix existed, so an appliance that was reachable in that period may already have been entered [3]. "Should your organization suspect compromise, it is important to preserve forensic evidence prior to applying updates, as updates may result in loss of forensic visibility," CISA wrote [8].
An appliance that matches Citrix's indicators moves to incident response. For that case Citrix published a separate document, "Steps to Take if NetScaler ADC is Suspected to be Compromised," which CISA links from the alert [9].
The public record is short. CISA posted the alert on 27 September 2026 [11]. It based its warning on "reports and partner threat intelligence" confirming exploitation that it describes as global [4]. The alert does not name the attackers, give a victim count, list fixed builds, set a federal remediation deadline, or say whether exploitation needs credentials.
The eight CVEs do not carry the same risk. Only CVE-2026-88771 and CVE-2026-88772 went into the KEV catalog [2]. That leaves six disclosed flaws with no exploitation listing in this alert [12]. CISA's own wording is looser: it says malicious actors are exploiting "at least some of these vulnerabilities" [10]. For now the two KEV entries are the confirmed attack path. The other six are covered by the same Citrix bulletin [7].
What to watch
- Whether CISA adds any of the other six CVEs, CVE-2026-88773 through CVE-2026-88778, to the KEV catalog.
- Attribution or victim counts from Citrix, CISA, or incident responders for the exploitation CISA calls global.
- Revisions to the indicators of compromise Citrix ships through NetScaler Console as more exploitation data surfaces.