
UPDATE
Citrix on Sept. 27 disclosed two critical NetScaler zero-day vulnerabilities after reports of exploitation had caused alarm among customers for several days.
CVE-2026-88771 is a remote code execution (RCE) flaw with a 9.5 CVSS score that stems from improper input validation, while CVE-2026-88772 is a memory overflow vulnerability, also with a 9.5 CVSS score, that can lead to RCE and distributed denial-of-service (DDoS) attacks. Both zero-days affect default configurations of Citrix's NetScaler Application Delivery Control (ADC) and Getaway products.
"Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed," Citrix said in its advisory, which strongly urged customers to update their software.
However, public reports of possible exploitation first surfaced online on Sept. 25 in a Reddit thread, and there's additional evidence that attacks began "at least a week ago," according to Benjamin Harris, founder and CEO of watchTowr.
Communication Breakdowns for NetScaler Attacks
On Sept. 25, several Citrix users noted on Reddit that IT providers and security teams were urging them to disable their NetScaler appliances. Additionally, one Reddit user posted a private pre-notification from the Dutch National Cyber Security Centre (NCSC-NL) warning of possible NetScaler zero-day attacks, but it was later deleted. According to an FAQ from Tenable on the exploitation activity, the alert was distributed under Traffic Light Protocol (TLP):AMBER+STRICT restrictions, which limit the public sharing of such information.
On Sept. 26, watchTowr warned of potential zero-day attacks on NetScaler customers in social media posts. "We are currently rapidly reacting to rumors that multiple unpatched Citrix NetScaler RCE vulnerabilities are circulating in the wild," the company said in a post on X. "While details are scarce, the information is credible."
Later that day, Harris posted on LinkedIn that the rumors were true. "While details are scarce, we have now confirmed the rumors with authoritative sources," he wrote. "Please, take this seriously and pull NetScaler appliances offline immediately."
However, Citrix didn't disclose the zero-days until the following day, along with several other NetScaler flaws, and released patches. But Harris notes that, according to authoritative sources like national CERTs, exploitation had begun at least a week ago. Similarly, GreyNoise said in a blog post yesterday that it first detected exploitation on Sept. 24.
Confusion as Citrix Remained Quiet on Zero-Day Rumors
Harris takes issue with Citrix's silence on the reported attacks, emphasizing that in today's cyber-threat landscape with rapidly shrinking exploitation windows, "hours do matter," to say nothing of several days.
"It's not unusual for zero-days to be exploited; we see that time and time again," he tells Dark Reading. "But I think what's typically done in those situations is that you make users aware that there is a risk that is currently kind of unmanageable, and of course I think that's what's frustrating people today."
Harris also said that the patch watchTowr's team analyzed for a technical analysis of CVE-2026-88771 published yesterday was dated Sept. 24, which indicates Citrix had knowledge of the exploitation activity last week, though the timing is unclear.
In a report published Tuesday, Google's Threat Intelligence Group (GTIG) said the campaign has been "ongoing since at least early September," and that GTIG and Mandiant first detected exploitation of CVE-2026-88772 in late September.
Dark Reading contacted Citrix for comment on when the company became aware of the exploitation activity, as well as the scope of the attacks. The software maker did not respond to those questions and provided the following statement:
"We recently identified critical vulnerabilities in Citrix NetScaler ADC and Citrix NetScaler Gateway that led us to immediately develop and release a new version of the software that addresses the issues. We always advise customers to promptly adopt the latest version of our software, and we are underscoring that guidance here to ensure our customers immediately benefit from the updates in this latest release."
Harris criticized Citrix for remaining quiet on the zero-day rumors, which he says seems "almost purposeful," and says the company should have acted sooner to provide customers with clarity about the situation. Instead, NetScaler administrators found themselves in a pickle, relying on rumored attacks and debating whether to disable their appliances across their networks.
"One the rumors begin, don't let people just panic," he says.
Risks to NetScaler Customers
Harris says the two zero-day vulnerabilities are particularly dangerous for enterprises because they impact default configurations for NetScaler products and they are both trivial to exploit.
"If it's on the Internet, it is vulnerable," he says, adding that the stars aligned in a way that could not be much worse for customers.
First, he notes, NetScaler is used by many large organizations and enterprises, including many in the critical infrastructure space, which gives attackers high-value targets. "You've also got clearly a capable attacker, and you've got an attacker that basically has a skeleton key to every organization running a Citrix NetScaler, and they're actually using it," he says.
Palo Alto Networks, meanwhile, reported that its scans revealed more than 50,000 exposed NetScaler instances on the Internet. While disabling all NetScaler appliances across an organization may seem drastic, Harris says that in this case, it may be justifiable. If organizations cannot update to fixed versions of NetScaler ADC and Gateway, they should consider disabling the products.
This story was updated at 3:45 p.m. ET on Sept. 29 to reflect new information in a Google Threat Intelligence Group report.