Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway

Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway
CISA is amplifying Citrix’s disclosure of eight new vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway, including two critical zero-day flaws that can independently enable remote code execution. CISA says these issues are being actively exploited worldwide and urges organizations to review Citrix guidance, check for indicators of compromise before patching, and preserve forensic evidence if compromise is suspected. #Citrix #NetScalerADC #NetScalerGateway #CVE-2026-88771 #CVE-2026-88772 #CVE-2026-88773 #CVE-2026-88774 #CVE-2026-88775 #CVE-2026-88776 #CVE-2026-88777 #CVE-2026-88778

Keypoints

  • CISA amplified Citrix’s disclosure of eight new vulnerabilities in Citrix NetScaler ADC and Citrix NetScaler Gateway.
  • CVE-2026-88771 and CVE-2026-88772 were added to the CISA Known Exploited Vulnerabilities (KEV) Catalog.
  • Both KEV-listed flaws are described as critical zero-day vulnerabilities that can independently lead to remote code execution.
  • CISA says it has reports and partner threat intelligence confirming active exploitation by threat actors worldwide.
  • Organizations are urged to review Citrix advisories, assess exposure, and incorporate the vulnerabilities into risk-management efforts.
  • CISA recommends checking for indicators of compromise before patching when possible because updates may reduce forensic visibility.
  • Citrix has published IoCs and additional guidance through NetScaler Console and a security bulletin for CVE-2026-88771 through CVE-2026-88778.

MITRE Techniques

  • [T1190 ] Exploit Public-Facing Application – Threat actors are exploiting vulnerable Citrix NetScaler appliances exposed to the internet (‘threat actors are actively exploiting these vulnerabilities globally’).
  • [T1210 ] Exploitation of Remote Services – The flaws can be used remotely to gain code execution on affected systems (‘can independently enable remote code execution’).
  • [T1059 ] Command and Scripting Interpreter – Remote code execution implies the attacker may run commands on the compromised appliance (‘enable remote code execution’).

Indicators of Compromise

  • [CVE IDs ] Vulnerability identifiers referenced in Citrix and CISA guidance – CVE-2026-88771, CVE-2026-88772, and 6 more CVEs
  • [Product names ] Affected platforms mentioned in the alert – Citrix NetScaler ADC, Citrix NetScaler Gateway
  • [Guidance/document reference ] Citrix advisory and bulletin for compromise assessment – Security Bulletin for CVE-2026-88771 through CVE-2026-88778, NetScaler Console


Read more: https://www.cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway