# Citrix NetScaler zero-days exploited in the wild

Published: 2026-09-27 · Severity: severe · Sectors: technology, infrastructure
Canonical: https://vorant.io/reports/302bc704-33ee-5e9f-9191-0639e117e652/citrix-netscaler-zero-days-exploited-in-the-wild

> CISA warns two actively exploited zero-day RCE flaws among eight new Citrix NetScaler ADC/Gateway CVEs are being used by attackers globally.

CISA has issued an alert amplifying Citrix's disclosure of eight new vulnerabilities affecting NetScaler ADC and NetScaler Gateway appliances. Of these, CVE-2026-88771 and CVE-2026-88772 have been added to CISA's Known Exploited Vulnerabilities (KEV) catalog; both are rated critical and can independently enable remote code execution. CISA states it has received reports and partner threat intelligence confirming active, global exploitation of at least these two flaws as zero-days prior to patch availability.

Because patching NetScaler appliances can require downtime and complex change management, CISA is urging administrators to prioritize checking for indicators of compromise before applying updates, since patching can destroy forensic evidence needed to determine if a device was already compromised. Citrix has published IOCs via NetScaler Console and a security bulletin covering all eight CVEs, along with guidance for handling suspected compromise.

Defenders running NetScaler ADC or Gateway should treat this as an urgent action item: review Citrix's security bulletin for affected versions and fixed builds, check appliances for compromise indicators using Citrix's provided guidance and NetScaler Console, preserve forensic evidence (logs, memory, configuration) if compromise is suspected, and then apply the security updates. Given the internet-facing nature of these appliances and their history as high-value targets for both APT and ransomware-affiliated actors, rapid triage and patching should be treated as a priority.

## Mentioned in this report

- Vulnerabilities: CVE-2026-88771 (KEV), CVE-2026-88772 (KEV), CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, CVE-2026-88778

Source reporting: https://www.cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/302bc704-33ee-5e9f-9191-0639e117e652/citrix-netscaler-zero-days-exploited-in-the-wild.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
