{"id":290,"date":"2026-09-30T02:19:01","date_gmt":"2026-09-30T02:19:01","guid":{"rendered":"https:\/\/managedt.com\/blog\/citrix-netscaler-zero-day-exploited-us-uk-dutch-warnings\/"},"modified":"2026-09-30T13:07:42","modified_gmt":"2026-09-30T13:07:42","slug":"citrix-netscaler-zero-day-exploited-us-uk-dutch-warnings","status":"publish","type":"post","link":"https:\/\/managedt.com\/blog\/citrix-netscaler-zero-day-exploited-us-uk-dutch-warnings\/","title":{"rendered":"Citrix NetScaler Zero-Days Exploited: What the U.S., U.K. and Dutch Warnings Cover"},"content":{"rendered":"<p>Two vulnerabilities in Citrix NetScaler application delivery controllers and Gateway devices are being actively exploited, and the Cybersecurity and Infrastructure Security Agency has ordered U.S. federal agencies to patch by Wednesday. CVE-2026-88771 and CVE-2026-88772 both carry a severity score of 9.5 out of 10, and Citrix has shipped fixes for every flaw disclosed in its latest batch. The warnings from CISA, the Netherlands and the United Kingdom give administrators a clear, time-bound checklist to close the door on a class of bugs that sits on the edge of nearly every large enterprise network.<\/p>\n<h2>What Citrix disclosed<\/h2>\n<p>Citrix confirmed eight new vulnerabilities affecting NetScaler ADC and NetScaler Gateway. Two of the eight, CVE-2026-88771 and CVE-2026-88772, are being exploited in the wild, according to Citrix. The remaining six were disclosed alongside the exploited pair. Both exploited flaws scored 9.5 on the standard 10-point severity scale. Patches are available for all eight bugs.<\/p>\n<h2>What the government advisories say<\/h2>\n<p>Incident responders began flagging potential problems in NetScaler Gateway on Saturday, before government agencies in the Netherlands, the United States and the United Kingdom released formal advisories on Sunday confirming the vulnerabilities.<\/p>\n<p>The Cybersecurity and Infrastructure Security Agency told federal agencies to apply fixes by Wednesday and said forensic triage is required at any agency running the affected products. The agency wrote that it had received reports and partner threat intelligence confirming that threat actors are actively exploiting the vulnerabilities globally, and urged users and administrators to review Citrix&#8217;s advisories given the potential consequences of a breach.<\/p>\n<p>The urgency reflects where these devices sit in a network. NetScaler appliances are used by large organizations to manage traffic and authentication, which puts them in front of the applications and remote access paths employees and customers use every day.<\/p>\n<h2>Exploitation before a patch existed<\/h2>\n<p>Security researchers reported that CVE-2026-88771 was being exploited before a fix was available. Some exploitation traces have been dated back to the previous Thursday, more than a day before the first public warnings. Researchers also released a tool that lets organizations check how exposed they are to the bug, giving defenders a way to measure risk while patches roll out.<\/p>\n<p>The weekend also raised alarm because several private security companies told customers to take their NetScaler appliances offline on Saturday before any concrete evidence of exploitation was public. That early advisory pattern, combined with later confirmed in-the-wild abuse, is what pushed the government responses.<\/p>\n<h2>Why NetScaler is a frequent target<\/h2>\n<p>NetScaler ADC and Gateway appliances are widely deployed in large enterprise environments and act as the front door for users connecting to internal applications. Researchers have described the product family as an application delivery controller and VPN gateway appliance category found in virtually every large enterprise network on the planet. That centrality is exactly what makes a confirmed exploit attractive to attackers, since a single device often fronts thousands of users and services.<\/p>\n<p>Citrix NetScaler has been hit by several high-profile campaigns in recent years. Two earlier sets of bugs, known in the security community as Citrix Bleed One and Citrix Bleed Two, led to hundreds of breaches. Another Citrix NetScaler ADC vulnerability surfaced in March, which is the most recent prior incident before this month&#8217;s disclosure.<\/p>\n<h2>What organizations should do now<\/h2>\n<p>Citrix published detailed guidance on what customers should do if they suspect compromise through any of the eight bugs. For the two exploited flaws, the immediate steps are: apply the Citrix patches for CVE-2026-88771 and CVE-2026-88772 without delay, run forensic triage on any appliance that was reachable from the internet during the exploitation window, and review authentication and session logs for signs of unauthorized access. Federal civilian agencies operate under the Wednesday deadline set by CISA, but the same timeline is the practical target for any organization running internet-facing NetScaler gear.<\/p>\n<p>Administrators who cannot apply patches immediately should consider taking affected appliances offline until fixes are installed, which matches the early advice several security firms issued over the weekend.<\/p>\n<h2>FAQ<\/h2>\n<h3>Which Citrix NetScaler vulnerabilities are being exploited?<\/h3>\n<p>CVE-2026-88771 and CVE-2026-88772 are the two vulnerabilities under active exploitation. Both carry a severity score of 9.5 out of 10, and Citrix has released patches for both.<\/p>\n<h3>How many vulnerabilities did Citrix disclose in this batch?<\/h3>\n<p>Citrix confirmed eight new vulnerabilities affecting NetScaler ADC and NetScaler Gateway. Two of those eight are confirmed as exploited.<\/p>\n<h3>What is the CISA deadline for federal agencies?<\/h3>\n<p>The Cybersecurity and Infrastructure Security Agency gave federal agencies until Wednesday to patch CVE-2026-88771 and CVE-2026-88772, and said forensic triage will need to be conducted at any agency using the affected products.<\/p>\n<p><script type=\"application\/ld+json\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"FAQPage\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"Which Citrix NetScaler vulnerabilities are being exploited?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"CVE-2026-88771 and CVE-2026-88772 are the two vulnerabilities under active exploitation. Both carry a severity score of 9.5 out of 10, and Citrix has released patches for both.\"}},{\"@type\":\"Question\",\"name\":\"How many vulnerabilities did Citrix disclose in this batch?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Citrix confirmed eight new vulnerabilities affecting NetScaler ADC and NetScaler Gateway. Two of those eight are confirmed as exploited.\"}},{\"@type\":\"Question\",\"name\":\"What is the CISA deadline for federal agencies?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"The Cybersecurity and Infrastructure Security Agency gave federal agencies until Wednesday to patch CVE-2026-88771 and CVE-2026-88772, and said forensic triage will need to be conducted at any agency using the affected products.\"}}]}]}<\/script><\/p>\n<hr style=\"margin:2.5em 0 1em;opacity:.35\" \/>\n<p style=\"font-size:.85em;opacity:.7\">This article summarizes reporting from <a href=\"https:\/\/therecord.media\/us-uk-warn-of-citrix-netscaler-zero-day-bug\" target=\"_blank\" rel=\"nofollow noopener\">therecord.media<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Two Citrix NetScaler zero-days (CVE-2026-88771 and CVE-2026-88772) are under active exploitation. CISA has set a federal patch deadline of Wednesday.<\/p>\n","protected":false},"author":3,"featured_media":299,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-290","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/290","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/comments?post=290"}],"version-history":[{"count":1,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/290\/revisions"}],"predecessor-version":[{"id":291,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/290\/revisions\/291"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/media\/299"}],"wp:attachment":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/media?parent=290"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/categories?post=290"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/tags?post=290"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}