Circuit Wire — a daily news update from the Circuit.
Citrix confirmed on Sunday, September 27, that attackers have exploited two critical flaws in its NetScaler ADC and NetScaler Gateway appliances, prompting urgent warnings from cybersecurity agencies in the US, the UK and the Netherlands, The Record reported. Both flaws were used in attacks before a fix existed.
The vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, each carry a severity score of 9.5 out of 10. Citrix patched eight NetScaler flaws in the same update and said exploitation of the two had been observed on unmitigated deployments.
According to BleepingComputer, CVE-2026-88771 stems from improper input validation and lets an unauthenticated attacker run arbitrary commands. Citrix says it affects all customer-managed NetScaler ADC and Gateway deployments, including those running a default configuration. CVE-2026-88772 is a memory overflow flaw that can lead to remote code execution or denial of service when DTLS is enabled, which is the default setting on VPN virtual servers.
Affected builds include NetScaler ADC and Gateway 14.1 before 14.1-73.37 and 13.1 before 13.1-64.23, along with several FIPS versions. Secure Private Access Hybrid deployments that use NetScaler instances are also exposed. Cloud Software Group is upgrading the Citrix-managed cloud services itself.
The Cybersecurity and Infrastructure Security Agency gave federal agencies until Wednesday, September 30, to patch both flaws and said any agency using the products will need to carry out forensic triage. "CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally," the agency said.
The first signs of trouble surfaced over the weekend. Administrators posted on Reddit that IT suppliers had called and told them to shut down their NetScaler appliances at once, without giving details. Before Citrix published its bulletin, the Dutch National Cyber Security Center reportedly sent a pre-notification to organizations in the Netherlands. That notice said Citrix found the flaws while investigating incidents in customer environments, and that exploitation had been seen at multiple customers worldwide. Some reports cited by The Record date the exploitation back to the previous Thursday.
NetScaler devices are a repeat target because they sit at the network edge and handle remote access and authentication for large organizations. Security firm watchTowr described the product family as present in virtually every large enterprise network. Earlier campaigns known as Citrix Bleed One and Two led to hundreds of breaches, and another NetScaler ADC flaw emerged in March.
The Citrix alerts landed the same weekend that file-sharing vendor Kiteworks told customers to take their servers offline over a separate warning, which we covered here.
Want a weekly roundup of the major stories shaping the security industry? The On The Circuit newsletter is read by more than 12,000 protection professionals.
Spotted something we should cover? Send tips and feedback via circuit-magazine.com.

