Two Citrix NetScaler zero-day RCE vulnerabilities, now formally identified as CVE-2026-88771 and CVE-2026-88772, were actively exploited against customer environments worldwide before Citrix published patches on 27 September 2026. The story began not with an official advisory but with administrators receiving urgent, detail-free phone calls from their IT suppliers telling them to pull their NetScaler appliances offline immediately.
Warnings Spread Through Private Channels Before Any Official Disclosure
The first public signs of alarm surfaced on Reddit, where Citrix administrators described being contacted by IT suppliers, security teams, law enforcement, CERTs and national cybersecurity agencies, all advising the same thing: shut down exposed NetScalers, and do it now. ‘We got a call from our IT supplier’s security team, they couldn’t give any details but they advised to shut our Netscalers down immediately,’ one administrator wrote.
Cybersecurity firm watchTowr then went public, saying it was ‘rapidly reacting to rumors that multiple unpatched Citrix NetScaler RCE vulnerabilities are circulating in the wild.’ watchTowr confirmed it had verified the information with ‘authoritative sources,’ and was careful to distinguish the new flaws from CVE-2026-19490 and CVE-2026-19489, two separate NetScaler vulnerabilities Citrix had disclosed in August. (CVE-2026-19490, a critical authentication bypass, was added to CISA’s Known Exploited Vulnerabilities catalogue on 9 September after a proof-of-concept exploit became public.)
watchTowr later sharpened its description: ‘Two vulnerabilities, both RCE. Unpatched, 0days. Exploited in-the-wild, discovered during forensics.’ The firm added that Citrix communications and patches were expected early the following week. Citrix did not respond to requests for comment at that stage.
Dutch NCSC Advisory Fills In the Technical Picture
Additional detail came from the Dutch National Cyber Security Centre (NCSC-NL), which circulated a pre-notification advisory to organisations in the Netherlands after receiving information from a European partner CERT. Copies of the notice were shared online. According to the advisory, each vulnerability could independently lead to remote code execution, with one allowing attackers to place shellcode directly into memory. Technical analysis of the second flaw was still under way at the time.
The NCSC-NL notice confirmed that Citrix had discovered the vulnerabilities during an incident response investigation in customer environments, and that Citrix had subsequently filed a notification under the EU’s Cyber Resilience Act. No CVE identifiers had been assigned and no indicators of compromise were available when the advisory circulated. The NCSC-NL declined to confirm the advisory to BleepingComputer, but stated it ‘monitors relevant developments and cyber threats affecting the Netherlands 24/7’ and provides information to organisations so they can take appropriate measures.
Exploitation had been identified across multiple Citrix customers worldwide, though the NCSC-NL said it did not know whether attacks were occurring at widespread scale. The agency warned that exploitation attempts could accelerate once Citrix published patches and technical details, reasoning that the publication window would give threat actors a clearer roadmap. Because updating NetScaler appliances typically causes downtime, the pre-notification was intended to give organisations a running start.
Citrix NetScaler Zero-Day RCE Details Confirmed at Patch Release
When Citrix did publish, on 27 September 2026, the scale of the bulletin was broader than the initial warnings had suggested. Security bulletin CTX697096 disclosed eight vulnerabilities in total, running from CVE-2026-88771 through CVE-2026-88778, and confirmed that two of them had already been weaponised against customer environments worldwide, according to the Cloud Security Alliance.
Both CVE-2026-88771 and CVE-2026-88772 carry a CVSS 4.0 base score of 9.5 and can each independently produce unauthenticated remote code execution on internet-facing edge devices, the Cloud Security Alliance noted. Tenable confirmed the CVE assignments and patch release date in its own analysis.
Of the two exploited flaws, CVE-2026-88771 is particularly broad in scope. According to WaterISAC, it allows an unauthenticated attacker to execute arbitrary commands and affects all NetScaler deployments, including those running the default configuration. That means there is no niche or non-standard setup required to be exposed: a default out-of-the-box NetScaler reachable from the internet was a viable target.
Until organisations have applied the CTX697096 patches, the standing advice remains to take internet-exposed NetScaler appliances offline where possible, or restrict access to trusted networks and IP addresses. At a minimum, management interfaces should not face the public internet. With patches now available, the urgency shifts from ‘shut it down’ to ‘patch it now, before the next wave of opportunistic scanning begins.’

