Particle.news

Citrix Patches Two NetScaler Zero‑Days Exploited in the Wild

National cyber agencies ordered rapid remediation because compromised NetScaler edge appliances can give attackers broad access to enterprise networks.

Overview

  • Citrix confirmed active exploitation of two critical NetScaler flaws, tracked as CVE-2026-88771 and CVE-2026-88772, that allow unauthenticated remote code execution on unmitigated appliances.
  • The flaws were found during incident response and forensic work and Citrix released security updates over the weekend to address the issues and several other NetScaler defects.
  • CISA added the two CVEs to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch by September 30, with other national CERTs issuing urgent guidance and pre-notifications.
  • Citrix published generic Indicators of Compromise available via NetScaler Console but warned the IoCs may miss attacker activity and advised customers to preserve forensic evidence before applying updates.
  • Operators must weigh immediate actions such as isolating or taking appliances offline because many NetScaler instances remain internet-exposed, earlier August fixes do not fix these zero-days, and the 13.1 branch recently reached End of Maintenance.