Citrix NetScaler zero-days exploited, RCE confirmed
Citrix has confirmed that two critical NetScaler remote code execution vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks and that it has released security u
What Happened
Citrix has confirmed that two critical remote code execution vulnerabilities in its NetScaler product line, tracked as CVE-2026-88771 and CVE-2026-88772, are being actively exploited in the wild. The vendor released security updates addressing both issues after initial exploitation reports surfaced. NetScaler appliances function as application delivery controllers and remote access gateways for thousands of enterprises worldwide, making them a high-value target for initial access brokers and state-sponsored actors alike.
This disclosure follows a pattern of repeated NetScaler compromises over the past several years, including the CitrixBleed vulnerability that saw widespread exploitation by ransomware affiliates.
Why It Matters
NetScaler sits at the network edge, often exposed directly to the internet to serve remote workers and route application traffic. A successful RCE on this appliance hands attackers a foothold inside the perimeter with minimal friction, no phishing required, no credentials needed. From there, threat actors routinely pivot to internal Active Directory environments, deploy ransomware, or establish persistent backdoors that survive patching.
Organizations running NetScaler as their VPN or remote access solution face compounded risk: the same device that guards entry becomes the entry point. For regulated industries handling sensitive data, exploitation could trigger breach reports and mandatory disclosure obligations depending on what attackers accessed or exfiltrated while resident on the appliance.
Technical Details
Both vulnerabilities allow unauthenticated or low-privilege attackers to execute arbitrary code on vulnerable NetScaler instances. One of the two carries the unauthenticated remote code execution designation, meaning no valid credentials are required to trigger it, a significant escalation in severity compared to vulnerabilities that demand prior access.
Exploitation observed in the wild involves crafted requests sent directly to the appliance’s management or gateway interface. Security researchers have published proof-of-concept details for both CVE-2026-88772 and CVE-2026-88771, lowering the barrier for less sophisticated attackers to attempt exploitation. Citrix has not publicly attributed the attacks to a specific threat group.
Affected versions span multiple NetScaler ADC and NetScaler Gateway firmware branches. Administrators should verify their exact build against Citrix’s advisory and apply the corresponding hotfix immediately.
Immediate Risk
Any internet-facing NetScaler appliance that has not been patched is at critical risk. Exploitation requires only network reachability, a condition most deployments satisfy. The window between proof-of-concept publication and mass scanning is historically measured in hours, not days.
Indicators of compromise include unexpected processes on the appliance, anomalous outbound connections, modified configuration files, and new local accounts. Because NetScaler appliances run a hardened FreeBSD-based OS, unusual shell activity is a strong signal of compromise.
Security Insight
Edge appliance vulnerabilities follow a predictable economic cycle: vendor patches, researchers publish PoCs, and commodity attackers monetize the gap within days. But the more instructive parallel is CitrixBleed in 2023, where patching alone was insufficient. Organizations that had already been compromised discovered that applying the fix simply locked in attacker persistence rather than evicting it. The lesson for this disclosure is that remediation must include forensic validation, not just firmware updates. A patched appliance that was compromised before the patch remains compromised. Teams should assume exploitation occurred if their NetScaler was internet-facing prior to patching and hunt for persistence accordingly.
Further Reading
Never miss a security update
Get real-time security alerts delivered to your preferred platform.
Related News
Threat actors associated with the Anubis ransomware operation have been observed exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to obtain initial access. 'Although tactics differ between
Hackers are exploiting a critical severity vulnerability, tracked as CVE-2026-3055, in Citrix NetScaler ADC and NetScaler Gateway appliances to obtain sensitive data. [...]
Cybersecurity roundup for 2026-06-29 to 2026-07-05. 1 CVE advisories, 1 breach reports, 3 threat news stories.
Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally. The ShinyHunters-linked activity involv