Citrix discloses two critical NetScaler zero-days after days of exploitation reports
Citrix disclosed CVE-2026-88771 and CVE-2026-88772, both scoring 9.5 on the CVSS scale, affecting default configurations of its NetScaler ADC and Gateway products. Citrix confirmed exploits against unmitigated deployments and urged customers to patch immediately, though public warnings of attacks had circulated online since September 25, days before the formal disclosure.
GoKawiil's interpretation of the reporting above, not reported fact.
The gap between initial exploitation reports and Citrix's disclosure left customers without official guidance while attacks were reportedly already underway, according to watchTowr founder Benjamin Harris, who said evidence suggests attacks began at least a week earlier. Restricted early warnings, such as the deleted NCSC-NL notice shared under TLP:AMBER+STRICT, may have limited how quickly affected organizations could act, raising questions about disclosure timing for widely used network infrastructure.
- Two critical NetScaler flaws (CVSS 9.5) enable remote code execution and, in one case, DDoS attacks.
- Exploitation reports surfaced publicly on Reddit and via researchers days before Citrix's official disclosure.
- Citrix is urging all customers running default NetScaler ADC/Gateway configurations to patch immediately.
Source: darkreading.com — Rob Wright, 2026-09-29
Published there as: “Dual NetScaler Zero-Days Trigger Chaos for Citrix Customers”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.