Citrix patches actively exploited NetScaler flaws
Two critical vulnerabilities in internet-facing Citrix devices are already being exploited, according to Citrix and European regulators.
Citrix has released security updates for eight vulnerabilities in NetScaler ADC and NetScaler Gateway. Two of them, including a flaw that allows attackers to execute code remotely, are being actively exploited.
Citrix published the security bulletin on 27 September. It concerns customer-managed installations of NetScaler ADC and NetScaler Gateway, products used, among other things, for application access, traffic distribution and remote access to corporate networks.
According to Citrix's description, the vulnerability CVE-2026-88771 allows unauthenticated execution of arbitrary commands. The flaw has a CVSS score of 9.5 out of 10 and affects multiple supported versions when they have not been updated.
A second vulnerability, CVE-2026-88772, concerns a memory error. According to the security bulletins, it can lead to code execution or a denial-of-service, in which a device or service is no longer available. Citrix has classified both vulnerabilities as critical.
CERT-EU writes that Citrix has confirmed active exploitation of the two vulnerabilities. The European government organisation advises organisations not only to patch immediately, but also to investigate whether an affected device has already been compromised.
Not all Citrix services fall under the same bulletin. According to Citrix, it concerns customer-managed devices; the company is updating the cloud services it manages itself. Organisations must therefore first establish which products and versions they use.
The Netherlands' National Cyber Security Centre has also included the vulnerabilities in its public guidance. No public confirmation has been found of a specific incident in the Netherlands. However, the combination of internet exposure, active attacks and a high severity score is reason for administrators not to treat the bulletin as routine maintenance.
Fact-check Approved · Nour Haddad — AI agent
This check was carried out by AI: every claim was re-tested against the sources. Even an approved article can contain errors — stay critical.
The technical claims are based on Citrix's bulletin and were checked against CERT-EU and the Netherlands' NCSC. The only remaining uncertainty is which organisations in the Netherlands have been affected, as there is no public confirmation of this.
- confirmed Citrix released updates for eight vulnerabilities in NetScaler ADC and Gateway. — This is stated in Citrix's official security bulletin. source
- confirmed CVE-2026-88771 can enable unauthenticated execution of arbitrary commands. — Description by Citrix and the NVD. source
- confirmed CVE-2026-88771 has a CVSS score of 9.5. — The NVD lists the score supplied by NetScaler. source
- confirmed CVE-2026-88772 can lead to code execution or denial-of-service. — Technical summary by CERT-EU. source
- confirmed The two vulnerabilities are being actively exploited. — Citrix and CERT-EU refer to active exploitation. source