Urgent Warning: Citrix NetScaler Zero-Days Being Actively Exploited
Cybersecurity agencies in the United States, United Kingdom and the Netherlands issued urgent warnings this weekend about zero-day vulnerabilities affecting Citrix NetScaler application delivery controllers and Gateway devices. These devices act as the front door for users connecting into an organisation's network, making them a high-value target. Citrix has confirmed eight new vulnerabilities in total, two of which (CVE-2026-88771 and CVE-2026-88772) are already being actively exploited by attackers and carry near-maximum severity scores of 9.5 out of 10.
The US Cybersecurity and Infrastructure Security Agency (CISA) has ordered all federal agencies to patch the two exploited flaws immediately and to conduct forensic checks on any systems running the affected products, warning that threat actors are exploiting these vulnerabilities globally. Patches have now been released for all eight vulnerabilities. Researchers at watchTowr found that one of the flaws was being exploited before a fix even existed, and some reports suggest exploitation may date back several days before the public advisories.
The situation caused confusion over the weekend after several private security firms urged organisations to take their NetScaler appliances offline without initially providing evidence, ahead of the official confirmations. Citrix NetScaler products are widely used by large organisations worldwide to manage network traffic and user authentication, making them an attractive and high-impact target for attackers.