NEWS

Citrix Patches Actively Exploited NetScaler Zero-Days After a Weekend of Unofficial Warnings

Citrix stayed publicly silent for days while CERTs, insurers, and researchers warned of active NetScaler exploitation ahead of its own advisory.

Dylan H.

News Desk

September 28, 2026
8 min read
Citrix Patches Actively Exploited NetScaler Zero-Days After a Weekend of Unofficial Warnings

Citrix's Silence Left NetScaler Admins Guessing While Attackers Were Already Inside

Citrix spent most of a weekend publicly silent while attackers actively exploited two unpatched NetScaler ADC and NetScaler Gateway zero-days — and while CERTs, incident-response firms, cyber insurers, and independent researchers scrambled to warn NetScaler operators through informal, unofficial channels. According to CyberScoop (reported by Matt Kapko, published September 28, 2026), the vendor did not confirm the vulnerabilities or ship a patch until Sunday, September 27, nearly two days after the first credible rumors of in-the-wild exploitation began circulating — a gap that left some customers making high-stakes shutdown decisions with incomplete or no official information at all.

The two flaws, tracked as CVE-2026-88771 and CVE-2026-88772, were both confirmed by Citrix as actively exploited before any patch existed — a textbook zero-day scenario. CosmicBytez Labs has already published standalone technical advisories covering individual flaws bundled into the same Citrix bulletin (CTX697096), including CVE-2026-88773 and CVE-2026-88775. This article focuses on a different problem: the communication gap between when the security community knew something dangerous was happening and when Citrix officially said so.


Incident Details

AttributeValue
VendorCitrix
Products affectedNetScaler ADC, NetScaler Gateway (all deployments for CVE-2026-88771; DTLS-enabled VPN virtual servers for CVE-2026-88772)
Zero-day CVEsCVE-2026-88771 (CVSS v4 9.5, unauthenticated arbitrary command execution), CVE-2026-88772 (CVSS v4 9.5, memory overflow enabling RCE/DoS)
BulletinCitrix Security Bulletin CTX697096 — 8 CVEs total, including 6 non-zero-day defects
Earliest known attack signalSeptember 24, 2026 — GreyNoise observed a failed exploitation attempt against a NetScaler Gateway
First public rumorSeptember 26, 2026 — watchTowr posted on X that "the information is credible" regarding unpatched NetScaler RCE vulnerabilities being exploited in the wild
Official Citrix confirmationSunday, September 27, 2026
Gap between rumor and official bulletinApproximately 36–48 hours
Patched versionsNetScaler ADC/Gateway 14.1-73.37, 13.1-64.23, and corresponding FIPS/NDcPP builds
CISA KEV statusAdded September 27, 2026; federal remediation deadline September 30, 2026

How the Weekend Unfolded

The First Signals Nobody Official Would Confirm

GreyNoise logged the earliest documented attack attempt on September 24, a failed exploitation try against a NetScaler Gateway appliance — a signal that, in hindsight, marked the start of active targeting well before anyone outside the security research community knew what was happening. Two days later, on September 26, threat-hunting firm watchTowr posted publicly on X that it was reacting to rumors of "several unpatched NetScaler RCE vulnerabilities" being exploited in the wild, adding that "while details are scarce, the information is credible." A follow-up post at 22:19 UTC that same day said the two flaws had been discovered during forensic investigations and that Citrix's communications and patches were expected "early in the week" of September 28 — a timeline that, for customers actively under attack, was not fast enough.

Admins Told to "Shut It Down" — Without Being Told Why

Over that same weekend, NetScaler administrators reported on Reddit that their IT suppliers, CERT contacts, and MDR (managed detection and response) providers were instructing them to shut down their appliances immediately — frequently without any explanation of what the underlying threat actually was. Some of those warnings traced back to a private, TLP:AMBER-restricted pre-notification from the Dutch National Cyber Security Centre (NCSC-NL), which said it had learned of the two zero-days from a European partner CERT and that exploitation had already been identified at multiple Citrix customers worldwide. In effect, defenders with the right connections to CERTs, insurers, or MDR vendors got actionable warning; everyone else was left watching social media rumors and guessing.

Industry Criticism Reaches a Fever Pitch

By Sunday, the criticism of Citrix's silence was sharp and public. Joe Toomey of cyber insurer Coalition called the vendor's roughly 36 hours of silence after exploitation rumors first circulated "unconscionably irresponsible." Ben Harris, founder and CEO of watchTowr, told CyberScoop: "The information vacuum was most striking. Customers were receiving warnings through unofficial channels while Citrix remained publicly silent." Harris argued Citrix could have issued interim guidance — confirming active exploitation and offering defensive steps — without disclosing the technical details an attacker would need, and stressed that "when active exploitation is underway, hours matter." Harris also posted on LinkedIn that Sunday warning that "Monday will be too late" for organizations waiting on an official Citrix statement before acting.

Citrix Finally Confirms — and Patches Eight Flaws at Once

Citrix published its bulletin, CTX697096, on Sunday, September 27, confirming that both CVE-2026-88771 and CVE-2026-88772 had been observed being exploited against unmitigated customer deployments, and releasing fixed builds (14.1-73.37 and 13.1-64.23, plus FIPS/NDcPP variants) that also close six additional, non-zero-day vulnerabilities bundled into the same release. Citrix's advisory listed no workaround for either zero-day and no published indicators of compromise, meaning patching was — and remains — the only mitigation. CISA added both CVEs to its Known Exploited Vulnerabilities (KEV) catalog the same day, giving federal civilian agencies until September 30, 2026 to remediate, and stated it had "received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally."

Impact Assessment

Impact AreaDescription
Decision-making under uncertaintyAdministrators without CERT/MDR/insurer relationships had to decide whether to take NetScaler appliances offline based on social-media rumors, not vendor guidance
Unequal access to warningOrganizations with ties to NCSC-NL, MDR providers, or threat-intel firms received actionable warning roughly a day or more before Citrix's public bulletin; others did not
Extended attacker windowConfirmed exploitation activity as early as September 24 means some attackers had up to three days of operating against unpatched, internet-facing appliances before an official fix existed
Vendor trust and reputationPublic criticism from a cyber insurer and a prominent research firm puts renewed scrutiny on Citrix's incident-communication practices following prior NetScaler zero-day incidents
Regulatory pressureCISA's same-day KEV addition and three-day federal remediation deadline underscore the urgency the vendor's own timeline did not initially reflect
Operational disruptionUnofficial "shut it down now" guidance, absent technical context, likely drove some organizations to take VPN/ADC infrastructure offline defensively — a business-continuity cost separate from the vulnerability itself

Recommendations

For NetScaler Administrators

  1. Patch immediately to NetScaler ADC/Gateway 14.1-73.37 or 13.1-64.23 (or the applicable FIPS/NDcPP build) if you have not already — there is no published workaround for CVE-2026-88771 or CVE-2026-88772.
  2. Assume compromise on any internet-facing appliance that was unpatched between September 24 and September 27, and review logs for the window even in the absence of published indicators of compromise.
  3. Do not rely solely on vendor bulletins as your first signal. Subscribe to CERT advisories (including NCSC-NL, CISA, and sector-specific ISACs) and reputable independent researchers who often surface credible exploitation activity before an official vendor confirmation.

For Security Teams and MDR/CERT Consumers

  1. Build a rapid-escalation path for "shut it down now" guidance that includes at least a threat category and rough severity, even under TLP:AMBER constraints — a directive with zero context makes it harder for downstream teams to prioritize against competing incidents.
  2. Track CISA KEV additions and treat the deadline as a floor, not a ceiling — private-sector organizations are not legally bound by the federal remediation window, but the same urgency applies given confirmed global exploitation.

For Vendors (a Broader Lesson)

  1. Interim acknowledgement beats silence. Confirming that a credible threat is under active investigation — without disclosing exploit details — lets defenders make informed decisions while a full patch is still being finalized, closing the "information vacuum" that drew the sharpest criticism here.

Key Takeaways

  1. Two Citrix NetScaler zero-days, CVE-2026-88771 and CVE-2026-88772, were exploited in the wild before any official patch existed, with the earliest known attack signal dating to September 24, 2026.
  2. Citrix did not publicly confirm or patch the flaws until Sunday, September 27 — roughly 36 to 48 hours after credible rumors of active exploitation first surfaced publicly via watchTowr on September 26.
  3. Unofficial warnings reached some administrators faster than Citrix did, via CERTs (including a TLP:AMBER pre-notification traced to NCSC-NL), MDR providers, and IT suppliers — creating unequal access to actionable warning.
  4. Industry reaction was pointed: Coalition's Joe Toomey called the silence "unconscionably irresponsible," and watchTowr's Ben Harris said Citrix's information vacuum left customers making decisions blind.
  5. CISA added both CVEs to its KEV catalog on September 27, setting a September 30 remediation deadline for federal agencies — underscoring the urgency the vendor's own communication timeline lagged behind.
  6. There is no workaround for either zero-day — patching to 14.1-73.37 / 13.1-64.23 (or later, including FIPS/NDcPP builds) is the only mitigation available.

Sources