SOCLYDE logo
Current languageEN
Cybersecurity newsVulnerabilityCitrixRemote access

Citrix netscaler: two exploited rce zero-days

Citrix and cybersecurity agencies warn about two critical flaws exploited in NetScaler ADC and Gateway.

By Soclyde Team

An administrator checks a network gateway in a technical room

In summary

  • CVE-2026-88771 and CVE-2026-88772 affect Citrix NetScaler ADC and Gateway and are being exploited in the wild.
  • Internet-facing appliances should be identified, updated and reviewed after remediation.
  • Rotate secrets if the investigation finds evidence that the gateway was compromised.

Explore next

Soclyde resources

Article contents

On 27 September 2026, Citrix published a bulletin covering eight NetScaler ADC and NetScaler Gateway vulnerabilities. Two of them, CVE-2026-88771 and CVE-2026-88772, are critical and are being exploited in the wild. They affect an access boundary that is often internet-facing: the gateway publishing applications or remote access.

What the advisories confirm

CVE-2026-88771 enables unauthenticated remote code execution under the conditions described by Citrix. CVE-2026-88772 is another critical flaw that can lead to code execution or denial of service. CISA added both to its KEV catalog, while CERT-EU recommends patching and checking for compromise.

Severity scores are not enough to assess this situation: active exploitation and the gateway’s role make an accurate appliance inventory more urgent than waiting for a normal maintenance cycle.

The scope to review

List NetScaler ADC and Gateway appliances, versions, builds and network exposure. Include standby, test and provider-managed environments. Record virtual servers, authentication profiles, VPN access and published applications.

Do not assume an instance is out of scope because it is not used as a VPN: the Citrix matrix and the real configuration determine applicability. Review filtering rules and administrative paths as well.

Patch, then look for evidence

Apply the fixed builds listed by Citrix, with a verified backup and rollback plan. After updating, review access logs, account creation, configuration changes and unexpected processes. A patch does not prove that earlier exploitation did not occur.

If the appliance was directly reachable from the Internet, preserve useful evidence before rotation or cleanup. Have your security team or managed service provider assess the indicators.

Accounts and secrets to review

Inventory administrator accounts, certificates, API keys and service secrets used by published applications. Prepare a coordinated rotation if the investigation shows that configuration was read or changed. Review fallback accounts too: they can remain active after a migration.

The workflow should separate software remediation, compromise assessment and access re-establishment. Completing only one does not replace the other two.

How Soclyde fits

Soclyde does not patch NetScaler and cannot determine whether an appliance was compromised. It can help keep administrator and service access in a local-first encrypted vault, using distinct credentials for each purpose.

That organization supports rotation after the investigation without turning the vault into a detection tool or a substitute for Citrix remediation.

Key takeaway

Two NetScaler zero-days are being exploited and require urgent operational treatment. Inventory gateways, apply Citrix builds, search for evidence and review secrets. To prepare a rotation, see the secure password generator or contact Soclyde.

Frequently asked questions

Which Citrix products are affected?

The bulletin covers customer-managed NetScaler ADC and NetScaler Gateway deployments. Check the Citrix advisory for the exact versions and builds instead of relying on the product name alone.

Should a NetScaler be taken offline before patching?

Citrix and government agencies recommend urgent remediation for exposed appliances. Plan a maintenance window and follow the vendor procedure; whether a temporary shutdown is required depends on your architecture and service owner.

What if the appliance was exposed?

Preserve logs, look for unusual connections and configuration changes, and have the appliance assessed. If access is confirmed or plausible, rotate administrative and service secrets after preserving evidence.

References

Sources and references

Need advice?

Design your password strategy with Soclyde

Schedule a dedicated walkthrough with the team to see how local-first security adapts to your stack.

Talk with us

Keep reading