INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Citrix Zero-Day Vulnerabilities Exploited in NetScaler RCE

| 2026-09-28 08:30 CRITICAL HIGH
Executive Summary AI-generated
The US Cybersecurity and Infrastructure Security Agency has ordered federal agencies to patch by Wednesday, 30 September due to a critical vulnerability in Citrix NetScaler ADC and Gateway deployments. The flaw, CVE-2026-88771, enables an unauthenticated attacker to execute arbitrary commands via remote code execution (RCE). With CVSS scores ranging from 7 to 9.5, the vulnerabilities pose significant risks to organizations with default configuration enabled for DTLS. Citrix has issued a bulletin warning of the potential exploitation and urging patching before disclosure by federal agencies. The Australian Signals Directorate's alert on September 28 also highlights the urgent need for immediate action.
Technical Mitigations AI-generated
* Implement secure coding practices and input validation mechanisms to prevent exploitation of CVE-2026-88771 and CVE-2026-88772. * Configure Citrix NetScaler ADC and Citrix NetScaler Gateway with default configuration settings disabled or set to DTLS (Domain-Tolerant Security System) mode, which reduces the attack surface. * Regularly update and patch operating systems, applications, and services that are not managed by Citrix, as these can be vulnerable to exploitation of CVE-2026-88771 and CVE-2026-88772. * Monitor network traffic for suspicious activity related to NetScaler appliances and take immediate action if any signs of exploitation are detected.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Salt TyphoonSalt Typhoon CVE-2026-88775CVE-2026-88775 CVE-2026-88771CVE-2026-88771 CVE-2026-88777CVE-2026-88777 CVE-2026-88776CVE-2026-88776 CVE-2026-88773CVE-2026-88773 CVE-2026-88778CVE-2026-88778 CVE-2026-88772CVE-2026-88772 CVE-2026-88774CVE-2026-88774
Target & Sectors
BENELUX BENELUX
Incident Timeline
‎September 27
Threat actors exploited an eight new flaws in Citrix NetScaler ADC and Citrix NetScaler Gateway.
organisation Citrix NetScaler ADC
organisation Citrix ADC
‎September 28
The Australian Signals Directorate's Australian Cyber Security Centre issued a critical alert on September 28 urging organizations to patch the Citrix NetScaler RCE zero-day vulnerability.
organisation The Australian Signals Directorate’s
‎2026/09/28
Threat actors exploited a memory overflow vulnerability in Citrix NetScaler RCE zero-day CVE-2026-88771 to target all NetScaler ADC and NetScaler Gateway deployments with default configuration.
threat_actor Salt Typhoon
organisation NetScaler
organisation CVE-2026
organisation NetScaler Console
organisation Citrix NetScaler
organisation NetScaler ADC
organisation NetScaler Gateway
organisation RCE
organisation Citrix NetScaler ADC
organisation CVE-2026-88778
organisation Citrix NetScaler Gateway
organisation CVSS
organisation DTLS
organisation the Dutch National Cyber Security Center
organisation NCSC-NL
organisation Adaptive Authentication
organisation the National CSIRT
infrastructure 14.1
infrastructure 14.1-73
infrastructure 13.1
infrastructure 13.1-64
infrastructure 13.1-37
organisation NetScaler Gateway 14.1
organisation NetScaler ADC FIPS
organisation Secure Private Access Hybrid
financial 73.37 NetScaler ADC
infrastructure 13.1 NetScaler ADC FIPS
infrastructure 14.1 NetScaler ADC FIPS
infrastructure 73.37 NetScaler ADC FIPS
organisation the European Union's
organisation NetScaler RCE
organisation NCSC
organisation BleepingComputer
organisation NFL
organisation CHANEL
‎30 September
Threat actors exploited a previously unknown vulnerability in Citrix NetScaler, allowing them to gain unauthorized access.
source_region United States
Tactical Metrics
Metrics
infrastructure
‎14.1
Software Version
Metrics
infrastructure
‎14.1-73
Software Version
Metrics
infrastructure
‎13.1
Software Version
Metrics
infrastructure
‎13.1-64
Software Version
Metrics
infrastructure
‎13.1-37
Software Version
Metrics
financial
73
Netscaler Adc
Metrics
infrastructure
13
Netscaler Adc Fips
Metrics
infrastructure
14
Netscaler Adc Fips
Metrics
infrastructure
73
Netscaler Adc Fips
Intelligence Sources