Citrix NetScaler Zero-Day Flaws Exploited: Patch Now
Attackers Need No Password
The latest attacks on Citrix NetScaler require no password at all. Citrix has disclosed two critical zero-day flaws in NetScaler ADC and NetScaler Gateway. Attackers can strike corporate VPNs and other edge services directly from the internet.
Both flaws score 9.5 on CVSS 4.0. Moreover, criminals exploited them before any fix existed. Only weeks earlier, attackers had already targeted NetScaler through an authentication bypass bug.
The Two Critical Vulnerabilities
CVE-2026-88771: Improper Input Validation
The first flaw stems from improper validation of input. A remote attacker needs no account. Likewise, the target needs no special feature or unusual configuration.
A successful attack runs arbitrary commands on the NetScaler appliance. Citrix has rushed out fixes for similar unauthenticated attacks in past years.
CVE-2026-88772: Memory Overflow
The second zero-day causes a memory overflow. It can lead to remote code execution or a denial of service.
Exploitation requires DTLS to be enabled. However, virtual VPN servers on NetScaler enable this protocol by default. Therefore, a typical enterprise gateway already meets the attack condition.
Affected NetScaler Versions
The flaws threaten NetScaler ADC and NetScaler Gateway in these branches:
- Version 14.1, before build 14.1-73.37
- Version 13.1, before build 13.1-64.23
- 14.1-FIPS, fixed in 14.1-73.37 FIPS
- 13.1-FIPS and 13.1-NDcPP, which need at least 13.1-37.279
Hybrid Secure Private Access deployments with their own NetScaler instances are also affected. Earlier, a similar memory overflow in the same products already posed a remote code execution risk.
How to Respond
No workaround exists for these two zero-days. Consequently, Citrix urges administrators to upgrade to the fixed builds.
For internet-facing systems, an update alone may not suffice. Administrators should first preserve logs and other forensic data. Next, they should check the device for signs of compromise. Finally, they should rotate any passwords, secrets, and certificates the attackers may have reached.
Timeline of the Disclosure
The first public warnings appeared on September 26. During real-world breach investigations, watchTowr learned of two unknown remote code execution bugs. It warned its clients before any CVE identifiers existed.
On September 27, Citrix released patches. In the same window, CISA added both flaws to its Known Exploited Vulnerabilities catalog. After the official advisory, watchTowr published the technical details of the two zero-days.
Six More Bugs Fixed
Citrix also closed six other issues in NetScaler ADC and Gateway. They include HTTP request smuggling, several memory handling errors, and configuration-dependent flaws. The full list of fixes and exploit conditions appears in the Citrix security bulletin.
The company advises owners of internet-facing VPNs, Gateways, and AAA servers to install the new builds first.
A Pattern of Edge Device Attacks
NetScaler has faced this situation before. In summer 2025, the CitrixBleed 2 flaw let attackers read device memory and steal active session tokens. Notably, defenders saw malicious activity before public exploit tools spread widely.
In June 2025, another critical bug could knock a gateway offline with one crafted request. That flaw also touched Gateway and VPN configurations. Thus, edge devices again became direct targets.
Past compromises show even heavier consequences. In 2023, attackers who breached NetScaler deployed web shells on the devices. They then dug into the infrastructure. In effect, the protective gateway became a permanent door into the corporate network.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.