Citrix Confirms Active Attacks on Netscaler Zero-Day Flaws, Urgent Patching Advised
Citrix has confirmed that its Netscaler Application Delivery Controller (ADC) and Gateway devices are under active attack, following weekend alerts from administrators. The vendor has released urgent updates for a total of eight zero-day vulnerabilities, two of which are already being exploited in the wild.
The most severe flaw, CVE-2026-88771, is rated 9.5 out of 10 and allows attackers to remotely run arbitrary commands with no preconditions needed. A second flaw of the same severity, CVE-2026-88772, affects devices with datagram transport layer security (DTLS) enabled, which is on by default on Netscaler Gateways, and can lead to remote code execution or denial of service. Six further vulnerabilities rated between 7.0 and 9.3 were also disclosed. Both Citrix and EU cyber defence agencies have confirmed exploitation of the two most critical bugs, and the US Cybersecurity and Infrastructure Security Agency has added them to its Known Exploited Vulnerabilities catalogue.
The full scale of exploitation is not yet known, with details still emerging on public forums such as Reddit. The Australian Signals Directorate has urged organisations running vulnerable Citrix products to review the vendor's advisories, install the security update as a priority, and check device logs for suspicious activity consistent with exploitation of these flaws.