Security News

Citrix Fixes Critical Zero-Days Already Being Exploited: Patch Now

Infosecurity Magazine · 28 Sept 2026
Key Takeaway If your business runs Citrix NetScaler ADC or Gateway on-premises, apply the latest security updates immediately given confirmed active exploitation.

Citrix has issued updates addressing eight newly disclosed vulnerabilities in its NetScaler ADC and NetScaler Gateway products, with CVSS severity scores ranging from 7 to 9.5. Two of these, CVE-2026-88771 and CVE-2026-88772, are critical zero-day flaws that Citrix has confirmed are being actively exploited on unpatched systems. A third critical issue, CVE-2026-88773, is an HTTP request smuggling vulnerability affecting devices with HTTP configuration enabled, scoring 9.3 on the CVSS scale.

Given the severity, several national cybersecurity agencies have moved quickly. Australia's Cyber Security Centre issued a critical alert on September 28 urging organisations to patch immediately, while the Dutch National Cyber Security Centre reportedly issued similar warnings. In the United States, the Cybersecurity and Infrastructure Security Agency ordered federal agencies to apply the fixes by September 30. It is not yet known who is behind the current exploitation attempts, though Citrix zero-days have previously been targeted by state-linked threat actors such as Salt Typhoon.

Citrix has clarified that this bulletin applies only to customer-managed NetScaler ADC and Gateway deployments, as its cloud-managed services are updated automatically by Cloud Software Group.

Summarised by CISO AI from Infosecurity Magazine. We link back to every original so you can read it yourself.