Citrix's Silent Patch: Two Zero-Days Already Under Attack
Michael Miller ·
Listen to this article~3 min
Citrix confirms two critical NetScaler RCE zero-days (CVE-2026-88771 and CVE-2026-88772) are being exploited in attacks. Security updates are available—patch now to protect your network.
### Citrix Confirms Active Exploitation of Two NetScaler Zero-Days
Citrix just dropped some unsettling news. Two critical remote code execution (RCE) vulnerabilities in NetScaler are already being exploited in the wild. The flaws, tracked as CVE-2026-88771 and CVE-2026-88772, allow attackers to run arbitrary code on affected systems. Citrix has released security updates, but the clock is ticking. If you manage NetScaler, you need to act now.
### What Exactly Are These Vulnerabilities?
Both are RCE bugs, which means an attacker could take full control of your NetScaler appliance. That's about as bad as it gets. NetScaler sits at the edge of your network, handling traffic and authentication. If it's compromised, your entire infrastructure is at risk. Citrix hasn't shared technical details yet, but the fact that they're being actively exploited tells you everything. This isn't theoretical.
### Who's at Risk?
If you're running NetScaler ADC or NetScaler Gateway, you're a potential target. That includes:
- On-premises deployments
- Cloud-hosted instances
- Any version not patched with the latest updates
Even if you think you're not a target, attackers are scanning for vulnerable systems right now. They don't discriminate.
### What You Need to Do Right Now
First, check your NetScaler version. Citrix has released patches for supported versions. Apply them immediately. If you can't patch right away, consider isolating your NetScaler from the internet or adding extra monitoring. But let's be real: patching is the only real fix.
- Apply the latest security updates from Citrix
- Review logs for any signs of compromise
- Limit administrative access to trusted IPs
- Enable multi-factor authentication on management interfaces
### Why This Matters Beyond Citrix
This isn't just a Citrix problem. It's a reminder that edge devices are prime targets. They're exposed, often unpatched, and provide a direct path into your network. As we rely more on remote access and cloud services, these appliances become more critical. And attackers know it.
> "The only secure system is one that's powered off, unplugged, and buried in concrete." – But since that's not practical, patch fast.
### The Bottom Line
Citrix has confirmed active exploitation. The patches are out. Every hour you wait increases your risk. Don't be the low-hanging fruit. Update your NetScaler, check for indicators of compromise, and tighten your defenses. Your network's security depends on it.