Citrix Releases Patches for Two Critical NetScaler Zero-Days
High · SecurityWeek ·
Exploited
Key points
- Citrix confirmed two zero-day flaws in NetScaler.
- The vulnerabilities are rated critical and tracked as CVE-2026-88771 and CVE-2026-88772.
- Patches are now available from the vendor.
- Some administrators shut down NetScaler systems as a precaution.
Citrix has acknowledged that two security flaws in its NetScaler product are zero-days, meaning they were unknown to the vendor until recently and lacked a fix. The company has now released patches to address both issues. Two flaws, identified by the identifiers CVE-2026-88771 and CVE-2026-88772, carry a critical severity rating. This disclosure came in 2026.
NetScaler is a widely deployed application delivery controller used for load balancing, secure remote access, and traffic management. Any organization relying on it for critical network functions could be affected. The exact technical details of the flaws are not fully public, but the zero-day status and critical rating suggest a high potential for exploitation. Attackers could use these vulnerabilities to gain unauthorized access or disrupt services.
The fact that some administrators chose to shut down their NetScaler systems highlights the urgency and perceived risk. Taking systems offline is a drastic step that can interrupt business operations, but it may be necessary if patching cannot be done immediately. Zero-days are particularly dangerous because they can be exploited before defenders have any chance to protect their assets. Even with patches available, many organizations may face delays in testing and deployment.
Organizations should act quickly to apply the vendor's fixes. They should also monitor for signs of compromise and review their exposure. The situation is evolving, and further details may emerge. IT teams should stay tuned to Citrix advisories and be prepared to implement additional mitigations if needed.
What to do now
- Apply the Citrix patches for CVE-2026-88771 and CVE-2026-88772 immediately.
- If immediate patching is not possible, take affected NetScaler appliances offline or isolate them from the network.
- Review system and network logs for unusual activity that could indicate exploitation.
- Restrict management access to trusted IP addresses and enforce strong authentication.
- Monitor Citrix advisories and security news for further updates or indicators of compromise.
- After patching, verify that the fixes are correctly installed and that systems are functioning as expected.
CVE references
- CVE-2026-88771
- CVE-2026-88772
Original source
Original AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.