US, UK warn of exploited Citrix NetScaler zero-day bugs

Several governments sent out urgent warnings this weekend about zero-day vulnerabilities impacting Citrix NetScaler application delivery controllers (ADC) and Gateway devices, which serve as front doors for users connecting to an organization’s environment.
Incident responders began warning of potential vulnerabilities in NetScaler Gateway products on Saturday before cybersecurity agencies in the Netherlands, U.S. and U.K. released advisories on Sunday confirming vulnerabilities. Citrix itself confirmed eight new vulnerabilities.
Of the eight, CVE-2026-88771 and CVE-2026-88772 have been exploited, according to Citrix. Both carry severity scores of 9.5 out of 10 and patches have been released for all of the bugs.
The Cybersecurity and Infrastructure Security Agency (CISA) gave all federal agencies until Wednesday to patch the two exploited vulnerabilities and said “forensic triage” will need to be conducted at any agency using the products.
“CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally,” the agency said. “Given the potential consequences of successful exploitation and the fact that malicious actors are exploiting at least some of these vulnerabilities, CISA urges users and administrators to review Citrix’s advisories.”
The tools are used by large organizations to manage traffic and authentication.
Citrix provided detailed guidance on what customers should do if they suspect they have been compromised through any of the bugs.
The incident caused alarm online because several private security companies urged customers to take their NetScaler appliances offline on Saturday without providing any evidence of vulnerabilities. Some reported exploitation of the bugs dating back to last Thursday.
CVE-2026-88771 was exploited before any fix existed, according to cybersecurity researchers at watchTowr, which provided a tool that allows organizations to determine how susceptible they are to the bug.
Citrix NetScaler appliances are frequent targets for hackers because of their centrality and popularity. WatchTowr explained that Citrix NetScaler is a “family of application delivery controllers and VPN gateway appliances found in virtually every large enterprise network on the planet.”
High-profile hacking campaigns targeting the products — colloquially known as Citrix Bleed One and Two — led to hundreds of breaches and another Citrix NetScaler ADC bug emerged in March.
References in this story
- NCSC NL | Security Advisories advisories.ncsc.nl NCSC NL | Security Advisories
- Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway | CISA www.cisa.gov
- Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway www.ncsc.gov.uk The NCSC is urging UK organisations to promptly mitigate vulnerabilities affecting Citrix NetScaler ADC and Gateway, two of which are being actively exploited.
- Steps to Take if NetScaler ADC is Suspected to be Compromised support.citrix.com Steps to Take if NetScaler ADC is Suspected to be Compromised
- Andrew Thompson (@ImposeCost) on X x.com GreyNoise saw exploitation activity starting at least 24 September against a target in Japan.
- Oh Look, The Foot Gun Went Off Again (Citrix NetScaler PreAuth Command Injection CVE-2026-88771) labs.watchtowr.com God damn it, we're back in the room again. Yes, that sound in your ears is screaming. The footgun has gone off again, shockingly, and we are yet again dealing with a situation where the entire world apparently knew…
- HHS warns of ‘Citrix Bleed’ attacks after hospital outages therecord.media The U.S. Department of Health and Human Services is warning hospitals and healthcare facilities across the country to patch a vulnerability known as “Citrix Bleed” that is being used in attacks by ransomware gangs.
- Citrix warns of exploitation of Netscaler devices through new bugs therecord.media Citrix is sounding the alarm about vulnerabilities affecting Netscaler products that security researchers say are reminiscent of the widely exploited "Citrix Bleed" bug.
- ‘Citrix Bleed’ vulnerability targeted by nation-state and criminal hackers: CISA therecord.media The bug has caused alarm for weeks as cybersecurity experts warned that many government agencies and major companies were leaving their appliances exposed to the internet — opening themselves up to attacks.
- CISA tells federal agencies to patch Citrix NetScaler bug by Thursday therecord.media The bug enables threat actors to send requests that disclose sensitive information and carries a severity score of 9.3 out of 10, indicating a critical risk.
- Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
- Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
- jon greig (@jgreigj) on X twitter.com @TheRecord_Media cybersecurity reporter. formerly @zdnet @cambodiadaily @haitiantimes_ — send tips to [email protected] or signal: jgreig.51
- jon greig (@jgreig.bsky.social) bsky.app cybersecurity reporter for The Record. formerly: zdnet, techrepublic, blavity, haitian times, cambodia daily — send tips to [email protected] or signal: jgreig.51



