Citrix NetScaler critical flaws under active attack, CISA warns

Two 9.5-rated vulnerabilities allow unauthenticated remote code execution; vendor releases patched OS refreshes

By LineZotpaper
Published
Read Time2 min
Citrix has disclosed eight vulnerabilities in its NetScaler application delivery controller and gateway products, including two critical flaws that are already being actively exploited globally, according to the company and the US Cybersecurity and Infrastructure Security Agency (CISA). The most severe issues, CVE-2026-88771 and CVE-2026-88772, carry CVSS scores of 9.5 and can let unauthenticated attackers run arbitrary commands or trigger remote code execution and denial of service.

Citrix published a security bulletin on Sunday covering eight CVEs affecting NetScaler. CVE-2026-88771 is a remote code execution vulnerability that allows an unauthenticated attacker to execute arbitrary commands. CVE-2026-88772 is a memory overflow vulnerability that can lead to remote code execution or denial of service. Both are rated critical with a CVSS score of 9.5.

A third critical issue, CVE-2026-88773, is rated 9.3 and allows HTTP request smuggling, an attack technique that can bypass security controls on front-end servers. The bulletin also describes three 8.8-rated memory overflow bugs that can make NetScaler appliances unstable, an 8.8-rated bug related to TCP Initial Sequence Number prediction, and a 7.0-rated feature policy bypass caused by improper HTTP URL-based expression usage.

CISA issued an alert on Sunday, stating that it "has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally." The alert notes that updating Citrix NetScaler appliances can be complex and may require downtime, and is intended to help organizations assess exposure, prioritize mitigation, and account for the vulnerabilities in risk-management activities.

Citrix said it has observed both critical vulnerabilities under attack and has published guidance on detecting whether a NetScaler appliance needs a fix, along with OS refreshes that contain the patches.

A Reddit thread alleges that at least one Citrix channel partner knew of the flaws on Saturday and urged users to take their NetScalers offline a day before Citrix's disclosure. That claim has not been independently confirmed.

NetScaler has a long history of security problems. Critical vulnerabilities disclosed in March 2026 were quickly attacked, the same occurred twice in 2025 and once in 2023, and NetScaler flaws appeared on the Five Eyes alliance's annual list of most-exploited bugs from 2020 to 2023. Despite this, some users choose not to patch the product, often because finding a maintenance window is difficult. Security vendors have been building compensating controls to make flawed devices safer to operate without patches.

§

Analysis

Why This Matters

  • The two 9.5-rated vulnerabilities allow unauthenticated remote code execution, meaning exposed NetScaler appliances can be compromised without valid credentials.
  • NetScaler devices sit at the network edge and control access to enterprise applications, making compromise a potential gateway to wider network intrusion.
  • CISA's alert confirms global active exploitation, so organizations using NetScaler face immediate pressure to patch or apply compensating controls.

Background

Citrix NetScaler is a widely used enterprise product that functions as an application delivery controller and gateway, handling traffic routing, load balancing, and remote access. It has been a recurring target for attackers, with multiple critical vulnerabilities disclosed and exploited in recent years. The product's role at the perimeter of corporate networks makes flaws in it especially valuable to threat actors. CISA and allied cyber agencies have repeatedly flagged NetScaler bugs in their annual lists of routinely exploited vulnerabilities, and this latest disclosure follows that pattern.

Key Perspectives

Citrix: The company published a bulletin with detection guidance and OS refreshes containing fixes, and has acknowledged that both critical vulnerabilities are already under attack. CISA: The agency issued an alert to help organizations assess exposure and prioritize mitigation, citing confirmed reports of global active exploitation. Administrators and users: Patching NetScaler can require downtime, and finding a change window is often difficult. Some users may rely on compensating controls or delay updates despite the risk, a stance that is hard to justify given how frequently the product is targeted. Skeptics: The Reddit allegation that a channel partner knew of the vulnerabilities before disclosure raises questions about early information sharing and whether customers were given enough time to prepare before attackers could exploit the flaws.

What to Watch

  • Whether Citrix releases additional emergency updates or workarounds as exploitation continues.
  • Whether CISA adds these CVEs to its Known Exploited Vulnerabilities catalog, which would create a binding patch deadline for federal agencies.
  • Reports of ransomware or intrusions linked to these NetScaler vulnerabilities, which would indicate how widely attackers are using them.
  • Whether the Reddit allegation about early partner knowledge is confirmed or addressed by Citrix.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.