Citrix Confirms Two Unpatched Zero-Day Vulnerabilities in NetScaler Under Active Exploitation
Citrix has disclosed two unpatched remote code execution flaws affecting its NetScaler ADC and Gateway appliances, with active exploitation already observed in the wild. The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning as administrators await official patches.
By Lila Morgan
- Enterprise Defenders
- Security administrators frustrated by the weekend disclosure of a zero-day without an accompanying patch or CVE.
- Threat Intelligence Analysts
- Researchers focused on the rapid weaponization of the flaw and the risk of attackers bypassing temporary mitigations.
- Government and Vendors
- Agencies and the manufacturer prioritizing immediate manual workarounds to stem active exploitation while a fix is developed.
Perspectives this story doesn't cover
- Ransomware operators exploiting the flaw
When the "Citrix Bleed" vulnerability compromised thousands of corporate networks in late 2023, administrators at least had a patch to apply the day the flaw was announced. The two zero-day vulnerabilities Citrix confirmed on Sunday differ in one critical respect: they are already being exploited globally, and no fix currently exists. The vendor issued a security bulletin acknowledging active remote code execution (RCE) attacks against its NetScaler ADC and NetScaler Gateway appliances, stating, "We are aware of targeted attacks in the wild exploiting these vulnerabilities."[1][3]
The flaws, which currently lack formal Common Vulnerabilities and Exposures (CVE) designations but are tracked internally as CVE-2026-88771 through CVE-2026-88778, allow unauthenticated attackers to execute arbitrary code on the affected devices. While vendor communications often frame such disclosures around limited, targeted attacks, the reality of internet-facing appliance vulnerabilities is that automated scanning typically follows disclosure within hours. The capability here is total system compromise: an attacker who successfully exploits the flaw gains the ability to pivot into the internal network, bypassing the very perimeter defense the NetScaler appliance is designed to provide.[1][5]
The Cybersecurity and Infrastructure Security Agency (CISA) escalated the situation by publishing an immediate alert on September 27, 2026. "CISA urges users and administrators to review the Citrix security bulletin and apply the recommended mitigations immediately," the agency stated. This directive underscores the severity of the threat, particularly for federal agencies and critical infrastructure operators who rely heavily on NetScaler for application delivery and remote access. CISA's rapid response highlights a growing intolerance for delayed patching cycles when perimeter devices are compromised, signaling to federal civilian executive branch agencies that they must prioritize these mitigations ahead of standard maintenance windows.[2]
Because no firmware update has shipped, Citrix has provided a series of configuration changes intended to block the specific HTTP requests used in the observed exploits. Security researchers note that these mitigations, which involve applying responder policies via the command line, are temporary band-aids rather than structural fixes. Administrators must manually implement these rules across their fleets, a process that carries its own risks of misconfiguration or service disruption. In complex enterprise environments, applying global drop rules can inadvertently sever legitimate traffic, forcing network engineers to balance the immediate security threat against the risk of taking critical internal applications offline.[3][4]
Because no firmware update has shipped, Citrix has provided a series of configuration changes intended to block the specific HTTP requests used in the observed exploits.
The cybersecurity community has expressed frustration over the disclosure timeline and the lack of immediate CVE assignments. Independent analysts point out that releasing a critical zero-day warning on a weekend without a deployable patch forces security operations centers into emergency weekend shifts. The absence of standard CVE identifiers also complicates automated vulnerability scanning, as enterprise security tools rely on those standardized tags to flag vulnerable assets. Without a CVE to track, security teams must rely on custom scripts and manual log analysis to determine if their specific NetScaler builds are vulnerable or if they have already been compromised by the active exploit.[4][5]
The vulnerability affects multiple supported versions of the NetScaler operating system, including the 14.1, 13.1, and 13.0 branches. However, Citrix clarified that appliances configured strictly as load balancers without the gateway or authentication virtual servers enabled are not susceptible to this specific attack path. This distinction is crucial for organizations triaging their exposure, as it narrows the immediate attack surface to devices actively handling remote user access. Enterprises that only use NetScaler to distribute internal web traffic can defer the emergency mitigations, while those using it as a VPN replacement or zero-trust network access gateway must act immediately.[1][3]
NetScaler appliances hold a massive footprint in enterprise environments, with internet scanning engines routinely identifying over 80,000 exposed instances globally. Historically, vulnerabilities in these devices have been highly prized by ransomware syndicates and state-sponsored actors alike. During the 2023 Citrix Bleed campaign, threat actors compromised over 300 organizations within weeks, extracting terabytes of data before patches could be universally applied. The current zero-days present a similar, if not more severe, risk profile, given that attackers have a head start while defenders are left waiting for a compiled firmware update to secure their perimeters.[3]
The temporary mitigation requires administrators to drop specific crafted HTTP GET requests that attempt to traverse the appliance's directory structure. While Citrix's provided responder policy effectively neutralizes the current exploit chain, security researchers warn that threat actors frequently modify their payloads to bypass such pattern-matching defenses. This dynamic means the mitigation is only reliable until attackers reverse-engineer the filter and adjust their syntax. Security teams are advised to continuously monitor Citrix's support channels, as the vendor may need to update the responder policy syntax if attackers discover a way to encode or obfuscate their malicious requests to slip past the initial blocklist.[4][5]
The timeline for a permanent resolution remains undefined. Citrix has committed to notifying customers as soon as the firmware updates clear quality assurance testing and are ready for deployment. For now, the burden rests entirely on enterprise defenders to implement the manual workarounds and monitor their perimeters, hoping the temporary policies hold against an increasingly automated threat landscape. The next critical juncture will arrive when the patches are finally released, triggering a global race between administrators attempting to update their appliances and threat actors scanning for networks that failed to apply the fix in time.[1][2]
The stakes
NetScaler appliances sit at the edge of corporate networks, acting as the front door for remote employees and critical applications. An unauthenticated remote code execution flaw allows attackers to bypass all perimeter defenses and pivot directly into the internal network, making immediate mitigation essential to prevent ransomware deployment.
The essentials
- Citrix has confirmed two unpatched zero-day vulnerabilities in NetScaler ADC and Gateway appliances.
- The flaws allow unauthenticated remote code execution and are currently being exploited in the wild.
- No firmware patch is available; administrators must manually apply command-line responder policies to block malicious requests.
- CISA has issued an urgent alert urging immediate mitigation across federal and critical infrastructure networks.
Perspectives explored
Enterprise Defenders
Security administrators frustrated by the weekend disclosure of a zero-day without an accompanying patch or CVE.
For the teams managing corporate perimeters, the timing and nature of the disclosure represent a worst-case scenario. Releasing a critical vulnerability warning on a weekend without a deployable patch forces security operations centers to manually implement command-line mitigations across their entire fleet. The lack of standard CVE identifiers further complicates the response, as automated vulnerability scanners cannot easily flag the exposed assets, leaving defenders to rely on custom scripts and manual log reviews.
Threat Intelligence Analysts
Researchers focused on the rapid weaponization of the flaw and the risk of attackers bypassing temporary mitigations.
Independent security researchers view the temporary responder policies as a fragile defense mechanism. Because the mitigation relies on pattern-matching specific HTTP GET requests, threat actors can often reverse-engineer the filter and adjust their payload syntax to bypass the blocklist. Analysts warn that this creates a cat-and-mouse dynamic where the mitigation is only effective until the attackers iterate their exploit, leaving networks vulnerable again before the official firmware patch is even released.
Government and Vendors
Agencies and the manufacturer prioritizing immediate manual workarounds to stem active exploitation while a fix is developed.
From the perspective of Citrix and federal agencies like CISA, the immediate priority is halting the active exploitation by any means necessary. Acknowledging the flaw before a patch is ready is a calculated risk designed to alert critical infrastructure operators that their perimeters are under attack. The vendor's focus is on providing actionable, albeit manual, configuration changes to sever the known attack paths while engineering teams rush to compile and test a stable firmware update.
Sources
[1]CitrixGovernment and VendorsNetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778
Read on Citrix →
[2]CISAGovernment and VendorsCritical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway
Read on CISA →
[3]Bleeping ComputerEnterprise DefendersCitrix confirms two NetScaler RCE zero-days exploited in attacks
Read on Bleeping Computer →
[4]Security AffairsEnterprise DefendersCitrix Confirmed Two New NetScaler Flaws Exploited as Zero-Day
Read on Security Affairs →
[5]shattered.ioThreat Intelligence AnalystsCitrix NetScaler's 2 Zero-Days Ship With No CVE
Read on shattered.io →
Comments
More in Technology
See all →AI Containment
OpenAI Halts Frontier Model Training After AI Agent Uses DNS Exploit to Escape Sandbox
4 sources
Ecosystem Bridge
Google Bridges the iOS Divide: Android's Quick Share Now Natively Supports Apple AirDrop
3 sources
Digital Identity
Are Passkeys Actually Safer Than Passwords? The 2026 Evidence Pack
2 sources
Industrial AI
Jeff Bezos' $41B Startup Prometheus Aims to Build an 'Artificial General Engineer'
6 sources
Every angle. Every day.
Get Technology stories with full source coverage and perspective breakdowns delivered to your inbox.




