Researchers Warn of Citrix NetScaler Exploitation
On Saturday, researchers from watchTowr Labs said they had credible information that attackers were exploiting an unknown RCE vulnerability in Citrix NetScaler boxes.

On Saturday, researchers from watchTowr Labs said they had credible information that attackers were exploiting an unknown RCE vulnerability in Citrix NetScaler boxes.
September 27, 2026 | 3 min read

UPDATE--Citrix has released patches for the two previously undisclosed flaws in its NetScaler products that have been the target of exploitation this weekend.
The patches address two RCE vulnerabilities, CVE-2026-88771 and CVE-2026-88772, that have been used in targeted attacks in the last couple of days, as well as six other bugs that are somewhat less serious.
Researchers and threat intelligence teams are warning about ongoing, targeted exploitation of two undisclosed RCE vulnerabilities in Citrix NetScaler ADC and Gateway appliances.
"Citrix has released updates for NetScaler ADC and NetScaler Gateway to address multiple security vulnerabilities. These vulnerabilities vary by deployment configuration and enabled features, and include issues that could allow remote code execution, denial of service, HTTP request smuggling, policy bypass, and TCP initial sequence number prediction under specific conditions," the company said in its advisory published on Sunday.
"Exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments has been observed. Citrix strongly urges affected customers to install the relevant updated versions as soon as possible."
"Two RCEs, at least one of which allows shellcode to be placed in memory. Technical details still sparse," Ryan Dewhurst of Previdian told Decipher.
What’s Happening
“Nothing in our honeypot network. Likely pretty targeted exploitation so far, rather than mass internet wide exploitation. Could see a smash and grab before patches now they know the game’s going to be up soon. If not, going to see a race as soon as patches released anyway,” Dewhurst of Previdian said.
“Either way, if a short VPN outage is doable, remove them from the internet until Citrix publishes a fix. Otherwise, restrict them as much as possible, and apply the update as soon as it is released, and check for released IoCs.”
Data from Censys shows about 36,000 NetScaler appliances exposed to the internet.
What To Do Now
If you're not able to patch right away, researchers recommend that organizations with NetScaler ADC or Gateway Appliances take them offline right now if at all possible. That’s not the easiest recommendation to follow, given that these boxes perform critical security and application delivery functions in enterprises.
“Guidance to organizations leveraging Citrix NetScalers in their environments is extremely clear: take the appliances offline immediately. Unfortunately, as of now, there is no official communication from Citrix publicly but as always, Citrix and your national CERT will remain the best source of information related to this threat as the situation evolves,” watchTowr CEO Benjamin Harris said in a statement.
‘There should be no ambiguity here. This is a serious situation and should not be underestimated. Teams responsible for looking after Citrix NetScaler need to act now - waiting until Monday will be too late.”
September 27, 2026 | 3 min read
Dennis Fisher is an award-winning journalist and author. He is one of the co-founders of Decipher and Threatpost and has been writing about cybersecurity since 2000. Dennis enjoys finding the stories behind the headlines and digging into the motivations and thinking of both defenders and attackers. He is the author of 2.5 novels and once met Shaq. Contact: dennis at decipher.sc.