Citrix released emergency patches on September 27, 2026, for two actively exploited NetScaler zero-days that can allow remote code execution on customer-managed ADC and Gateway appliances. The company identified the flaws as CVE-2026-88771 and CVE-2026-88772. CISA said it had received reports and partner intelligence confirming exploitation globally and added both flaws to its Known Exploited Vulnerabilities catalog.

The two issues are part of a Citrix bulletin covering eight vulnerabilities in NetScaler ADC and NetScaler Gateway. Citrix said exploitation was observed on unmitigated deployments. CERT-EU described both exploited flaws as critical, unauthenticated remote code execution risks and advised organizations with internet-facing appliances to assess them for compromise.

CVE-2026-88771 is an improper input validation flaw that Citrix says can let an unauthenticated attacker run arbitrary commands. It has a CVSS v4.0 score of 9.5 and affects all deployments of the supported product lines, including default configurations; no optional feature must be enabled. Citrix has not tied the flaw in its bulletin to a particular attack group or disclosed an attack count.

CVE-2026-88772 is a memory overflow that can lead to remote code execution or denial of service and also carries a 9.5 CVSS v4.0 score. It applies where DTLS is enabled. Citrix says DTLS is enabled by default on a VPN virtual server unless an administrator explicitly disables it. The vendor provides configuration checks in its bulletin so operators can identify appliances that meet this precondition.

Citrix lists fixed builds 14.1-73.37 and 13.1-64.23 for standard NetScaler ADC and Gateway installations, with separate fixed builds for FIPS and NDcPP editions. Secure Private Access Hybrid deployments using NetScaler instances also require updates. Citrix says its managed cloud services and managed Adaptive Authentication are being updated by the company. The Canadian Centre for Cyber Security issued a separate alert about the two exploited flaws.

CISA urged organizations to review Citrix guidance and, where possible, check for compromise before patching. It cautioned that updates can reduce forensic visibility and advised preserving evidence if compromise is suspected. Citrix has made indicators of compromise available through NetScaler Console. CERT-EU recommended immediate updates and a compromise assessment for exposed appliances; administrators should use the vendor bulletin to confirm their version and configuration.