vuln
Image: Marek Piwnicki via Unsplash

US, UK warn of exploited Citrix NetScaler zero-day bugs

Several governments sent out urgent warnings this weekend about zero-day vulnerabilities impacting Citrix NetScaler application delivery controllers (ADC) and Gateway devices, which serve as front doors for users connecting to an organization’s environment.

Incident responders began warning of potential vulnerabilities in NetScaler Gateway products on Saturday before cybersecurity agencies in the Netherlands, U.S. and U.K. released advisories on Sunday confirming vulnerabilities. Citrix itself confirmed eight new vulnerabilities. 

Of the eight, CVE-2026-88771 and CVE-2026-88772 have been exploited, according to Citrix. Both carry severity scores of 9.5 out of 10 and patches have been released for all of the bugs. 

The Cybersecurity and Infrastructure Security Agency (CISA) gave all federal agencies until Wednesday to patch the two exploited vulnerabilities and said “forensic triage” will need to be conducted at any agency using the products.  

“CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally,” the agency said. “Given the potential consequences of successful exploitation and the fact that malicious actors are exploiting at least some of these vulnerabilities, CISA urges users and administrators to review Citrix’s advisories.”

The tools are used by large organizations to manage traffic and authentication. 

Citrix provided detailed guidance on what customers should do if they suspect they have been compromised through any of the bugs. 

The incident caused alarm online because several private security companies urged customers to take their NetScaler appliances offline on Saturday without providing any evidence of vulnerabilities. Some reported exploitation of the bugs dating back to last Thursday. 

CVE-2026-88771 was exploited before any fix existed, according to cybersecurity researchers at watchTowr, which provided a tool that allows organizations to determine how susceptible they are to the bug. 

Citrix NetScaler appliances are frequent targets for hackers because of their centrality and popularity. WatchTowr explained that Citrix NetScaler is a “family of application delivery controllers and VPN gateway appliances found in virtually every large enterprise network on the planet.” 

High-profile hacking campaigns targeting the products — colloquially known as Citrix Bleed One and Two — led to hundreds of breaches and another Citrix NetScaler ADC bug emerged in March.

Recorded Future
No previous article
No new articles
Jonathan Greig

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.