๐ด Active exploitation. Citrix released emergency patches for two critical zero-day vulnerabilities in NetScaler ADC and NetScaler Gateway after both were exploited before patches were available. CISA added both to the Known Exploited Vulnerabilities catalog with an FCEB remediation deadline of September 30, 2026. (BleepingComputer; CISA KEV)
What was disclosed
Citrix confirmed on September 27, 2026 that two vulnerabilities in NetScaler ADC and NetScaler Gateway were exploited before patches became available. CVE-2026-88771 is an improper input validation flaw enabling unauthenticated remote code execution. CVE-2026-88772 is a buffer boundary enforcement failure also enabling unauthenticated RCE. Both affect appliances configured as ADC and Gateway in default configurations. Patches shipped alongside fixes for six additional lower-severity flaws. No threat actor attribution has been confirmed. Exploitation enables full pre-authentication RCE on internet-facing appliances.
What organizations need to do right now
Apply the Citrix patches released September 27 immediately. The FCEB deadline is September 30 (Wednesday); federal agency security teams have two days. For organizations that cannot patch within 24 hours: take internet-facing NetScaler appliances offline or behind a restrictive IP allowlist until patching is complete. Review NetScaler logs for anomalous HTTP request patterns, unexpected POST bodies to ADC management interfaces, and newly created or modified user accounts. Check for web shell presence in the NetScaler file system. These indicators are consistent with post-exploitation activity observed in prior Citrix zero-day campaigns.
Why edge appliances keep ending up here
NetScaler ADC and Gateway occupy a strategically valuable position: they are internet-facing, handle authentication and access control for internal resources, and are deployed by exactly the organizations attackers most want to reach, including financial institutions, healthcare systems, and government agencies. Volt Typhoon targeted Citrix Bleed (CVE-2023-4966) in its 2023-2024 critical infrastructure campaign. LockBit affiliates exploited multiple Citrix vulnerabilities in 2022-2023. The pattern of pre-patch exploitation suggests organized groups with consistent vulnerability research investment in this device class.
What to watch
Watch for threat actor attribution as incident responders analyze compromised appliances. Mandiant, Volexity, and Rapid7 have historically been first to publish technical indicators of compromise for Citrix zero-day campaigns. The presence of web shells would indicate the attacker moved to establish persistence before the advisory was public, suggesting intelligence about the vulnerability before the public disclosure cycle. Organizations with managed detection and response coverage should proactively request NetScaler-specific IOC coverage from their provider today.
Gigia Tsiklauri is a Security Architect and founder of Infosec.ge. Get in touch if you want to discuss this post or our security research.