Skip to content

Security1 publisher2 min readPublished

watchTowr tells NetScaler owners to pull gateways offline over zero-day CVE-2026-88771

watchTowr says attackers exploited CVE-2026-88771, a pre-auth command injection in default-config Citrix NetScaler, before any fix existed. Upgrading to 14.1-73.37 or 13.1-64.23 closes the hole, though a gateway exposed in that window may already have been used.

The Watch · Security desk

Illustration accompanying watchTowr tells NetScaler owners to pull gateways offline over zero-day CVE-2026-88771

What happened

  • Citrix fixed the flaw in bulletin CTX697096, which covers eight vulnerabilities across NetScaler ADC and NetScaler Gateway.
  • watchTowr lists a second NetScaler remote code execution zero-day, CVE-2026-88772, alongside it.
  • On Saturday, watchTowr says, it firmed up circulating rumors with national and international authorities, then alerted its clients and the public.
  • watchTowr located the bug by comparing vulnerable build 14.1-73.30 with a patched release, and its post walks through the injection.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Response scope covers every gateway that sat reachable on an affected build before the upgrade, including boxes already patched, since exploitation needed no login and predates the fix.
  • decision Pulling a gateway offline, as watchTowr advises, cuts remote access for everyone who logs in through it; keeping it up means upgrading and checking for intrusion on a live front door.
  • capability watchTowr's public walkthrough of the patched code gives attackers who missed the zero-day window a shorter path to gateways still on old builds.
  • precedent If watchTowr's account holds, Citrix's own channel is a late signal for exploited NetScaler bugs, so teams that watch only vendor notices start response after attackers do.

The injection needs no credentials [1]. It works against the default configuration [2]. On an affected build, the only thing an attacker needs is a network path to the appliance [1]. According to watchTowr, NetScaler Gateway is the remote-access front door for thousands of organisations [12].

Citrix's part of the public record is the bulletin and its fixed builds. Those also cover 14.1-73.37 FIPS and, for 13.1-FIPS and 13.1-NDcPP, 13.1-37.279 [6]. The exploitation claim comes from watchTowr [3]. It does not name the national and international authorities it says it checked with [7], and its post does not identify an attacker [17]. The post also thanked "the lorries for which the patches and various pieces of information fell off" [15]. watchTowr wrote that "the entire world apparently knew about Citrix NetScaler CVEs before Citrix had woken up or bothered to acknowledge them" [9].

watchTowr gave two reasons for its offline advice: exploitation in the wild, and the critical nature of many organisations that run NetScalers. It said this was "going to be bad" [8]. watchTowr sells an exposure management platform and says clients who configured it have already had their exposure mitigated [14].

The post is titled "Oh Look, The Foot Gun Went Off Again" [16]. The pattern it describes is in how customers find out. watchTowr wrote that an actively exploited remote code execution bug in a default configuration reached the world through many channels, none of which included Citrix [10]. It also wrote that "communicating with your customers who pay for a solution to secure their environment feels like the bare minimum, not optional" [11].

What to watch

  • Citrix confirming or disputing in-the-wild exploitation of CVE-2026-88771 and CVE-2026-88772 in its own words.
  • Indicators of compromise or forensic guidance for NetScaler appliances that were exposed before the fixed builds.
  • A named group tied to the exploitation, showing whether this is one operator or a sustained NetScaler campaign.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories