Attackers are exploiting two critical flaws in Citrix NetScaler ADC and NetScaler Gateway. Companies use the devices to give staff remote access to internal networks. Citrix confirmed the attacks in a security bulletin on Sunday and released fixes. Both flaws were exploited before a patch existed.
“Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed,” Citrix said.
CVE-2026-88771 lets an attacker run commands without logging in. It affects all NetScaler ADC and Gateway deployments, including the default setup. CVE-2026-88772 is a memory overflow that can lead to remote code execution or a crash. It needs a setting called DTLS, which is on by default on VPN servers. Both score 9.5 out of 10 for severity.
The bulletin covers eight flaws in total. Fixed versions are 14.1-73.37 and 13.1-64.23, plus matching FIPS builds. Citrix is upgrading the cloud services it manages itself.
Government warnings
The US Cybersecurity and Infrastructure Security Agency (CISA) added both flaws to its list of known exploited vulnerabilities on Sunday. It gave federal civilian agencies until 30 September to fix them.
“CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally,” the agency said in an alert.
CISA urged organisations to check for signs of compromise before patching, because updates can erase forensic evidence. The first flaw gives attackers full control of the gateway and direct access to the network behind it. That is according to the Dutch National Cyber Security Centre (NCSC-NL) in its advisory.
Warnings before the patch
Before Citrix went public, administrators said on Reddit that IT suppliers had told them to shut their NetScaler devices down. A pre-notification from NCSC-NL was also circulating, Lawrence Abrams reported for BleepingComputer. It said Citrix found the flaws while investigating incidents at customers and notified the EU under the Cyber Resilience Act. NCSC-NL declined to confirm the notice to BleepingComputer.
The attacks have run all month, security researcher Kevin Beaumont wrote, describing the attackers as “probably nation state aligned”. Citrix has not said who is behind them.
Earlier this month, Cisco warned that attackers were exploiting a maximum-severity flaw in its Identity Services Engine. Microsoft’s September updates fixed two zero-days.
Get the TNW newsletter
Get the most important tech news in your inbox each week.