Two zero-day vulnerabilities in Citrix NetScaler appliances are reportedly being exploited in attacks.
The reports first emerged after Citrix administrators said they were privately warned by security teams and IT providers to shut down their NetScaler appliances. Cybersecurity firm watchTowr later said it had confirmed reports of active exploitation involving multiple unpatched NetScaler remote code execution (RCE) flaws.
The Dutch National Cyber Security Center (NCSC-NL) also warned organizations about two critical NetScaler zero-days. According to a pre-notification shared with organizations, each vulnerability can allow attackers to execute code remotely. One of the flaws reportedly allows attackers to place shellcode directly into memory.
According to the NCSC-NL notification, Citrix discovered the new zero-days during incident response investigations involving customer environments. Active exploitation was observed in multiple Citrix customers worldwide, although the agency said it did not know whether the attacks were widespread.
Citrix has released security updates to address multiple vulnerabilities, including CVE-2026-88771 and CVE-2026-88772, which, the vendor has confirmed, are being exploited in the wild. The first is a remote code execution that can allow an unauthenticated attacker to execute arbitrary commands, and the second is described as a memory overflow issue leading to RCE or denial of service.
The flaws affect Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later releases; Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1; Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS; Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.279 and later releases of 13.1-FIPS and 13.1-NDcPP.
Organizations using NetScaler appliances are strongly recommended to apply security patches as soon as possible.