How Many Zero-Days Before Citrix Loses You?
Two new 9.5-severity NetScaler bugs are under active exploitation, one needing zero configuration to weaponize. It is the third exploited zero-day cycle from Citrix since June, and the pattern says the front door is now the risk.

TITLE: How Many Zero-Days Before Citrix Loses You?
Someone's phone rang last weekend. One administrator wrote that their IT supplier's security team called with orders to "shut our Netscalers down immediately." Other administrators said law enforcement, CERTs, and national cybersecurity agencies were contacting organizations too. No CVE. No patch. Just a phone tree telling admins to unplug the box between the internet and everything they run.
By September 27, Citrix confirmed two critical NetScaler remote code execution vulnerabilities—CVE-2026-88771 and CVE-2026-88772—being actively exploited. CVE-2026-88771 allows unauthenticated attackers to execute arbitrary commands with a 9.5 severity score. Every NetScaler ADC and Gateway deployment is affected, including default configurations. CVE-2026-88772 leads to remote code execution or denial of service when DTLS is enabled, and Citrix ships DTLS enabled by default.
Translation: your out-of-the-box install is the attack surface.
watchTowr flagged the exposure before a CVE existed, alerting clients on September 26, a day before Citrix's bulletin.
Three strikes since June
This isn't the year's first fire drill. In June, Citrix shipped what it called a denial-of-service bug; by August, watchTowr showed successful exploitation allows remote code execution as root on unpatched instances. That's CVE-2026-8452. Weeks later came an authentication bypass. On September 9, CVE-2026-19490 hit CISA's Known Exploited Vulnerabilities catalog with active attacks already underway on a device sitting in front of enterprise remote access—fifteen days between patch and attacks. Now: two more 9.5 critical bugs, both weaponized before patches existed.
Three critical, actively exploited NetScaler chains in four months isn't bad luck. It's a release process that ships the vulnerability and lets outside researchers find the exploit.
Shadowserver tracks over 22,000 NetScaler ADC appliances and nearly 1,800 Gateway instances exposed online.

The isolation tax
Here's what "shut it down" actually costs. NetScaler ADC and Gateway handle VPN, load balancing, and authentication for remote workers and internal apps. Taking it offline closes the door your workforce walks through daily.
And patching doesn't clear the board. Because flaws were exploited as zero-days before patches existed, shutting down or patching won't remove attackers already inside. After a prior NetScaler zero-day hit Dutch organizations, the Netherlands' National Cyber Security Centre said that updating alone didn't remove the risk—attackers kept access gained before the patch.
Your remote-access perimeter doesn't need three shutdown orders in four months to be rented out to whoever finds the bug first. Any CISO still calling NetScaler "managed and monitored" is signing off on a control they don't control.
What to watch
Whether Citrix's next earnings call names the trust problem or buries it in security-investment language. Whether large NetScaler shops start replacement RFPs—a direct gift to F5, Cloudflare, and cloud-native vendors. Whether cyber insurance renewals start asking pointed questions about NetScaler exposure. At three cycles in four months, the next KEV addition for this product line won't read as surprise. It will read as routine.
- Citrix admins warned to shut down NetScalers over 2 exploited zero-days
- Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
- Citrix NetScaler Zero-Day RCE FAQ: CVE-2026-88771 and CVE-2026-88772
- CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday
- CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
- Citrix NetScaler Zero-Day RCE vulnerabilities: FAQ
- Inside the NetScaler Zero-Day Siege: Chained Pre-Auth RCEs Weaponized in the Wild (watchTowr Disclosure) | Shellcode (Sh3llc0d3)
- Citrix Patches Two Exploited NetScaler RCE Zero-Days - Cyber Kendra
- Unpatched NetScaler Zero-Days Exploited, watchTowr Says - Cyber Kendra
- Citrix NetScaler’s 2 Zero-Days Ship With No CVE [2026]
- Citrix NetScaler Zero-Days Under Active Attack: Two Critical RCE Flaws Force Emergency Patching
- Citrix admins warned to shut down NetScalers over 2 exploited zero-days | daily.dev
- Citrix admins warned to shut down NetScalers over 2 exploited zero-days
- Citrix admins warned to shut down NetScalers over 2 exploited zero-days - Live Threat Intelligence - Threat Radar | OffSeq.com
- Citrix confirms two NetScaler RCE zero-days exploited in attacks
- Citrix confirms two NetScaler RCE zero-days exploited in attacks - We Fix PC
- Citrix confirms two NetScaler RCE zero-days exploited in attacks - PRSOL:CC
- PoC Exploit Available for Citrix NetScaler ADC and Gateway CVE- 2026-8452
- CVE-2026-8452 | Arctic Wolf
- CVE-2026-8452: NetScaler DoS Flaw Now Unauthenticated RCE – Lab Space
- You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?))
- H-ISAC TLP White Threat Bulletin: PoC Exploit Available for Citrix NetScaler ADC and Gateway CVE-2026-8452 | AHA
- CVE Record: CVE-2026-8452 - NetScaler
- Citrix NetScaler CVE-2026-8452 Exploited as Root | Obiguard
- CVE-2026-8452: Citrix NetScaler Pre-Auth Root RCE
- CISA Adds 6 Exploited Flaws to KEV, Feds Get 3 Days
- Exploitation of CitrixBleed 2 (CVE-2025-5777) Began Before PoC Was Public
- Check for CitrixBleed 2 exploitation even if you patched quickly! (CVE-2025-5777) - Help Net Security
- CitrixBleed 2: When Memory Leaks Become Session Hijacks | Splunk
- Citrix Bleed 2 exploited weeks before PoCs as Citrix denied attacks
- CVE‑2025‑5777: Critical Citrix NetScaler Vulnerability Exploited
- GitHub - win3zz/CVE-2025-5777: CVE-2025-5777 (CitrixBleed 2) - Critical memory leak vulnerability affecting Citrix NetScaler ADC and Gateway devices · GitHub
- CVE-2025-5777: CitrixBleed 2 Write-Up… Maybe?
- Critical NetScaler Flaw Exposes Sensitive Memory Contents to Remote…
- Updates on Actively Exploited Information Disclosure Vulnerability “Citrix Bleed 2” in Citrix NetScaler ADC and Gateway I Arctic Wolf
- What is CitrixBleed 2 (CVE-2025-5777)? - Cyberwarzone
- Early exploitation of Citrix NetScaler authentication bypass vulnerability
- Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScaler - SecurityWeek
- Citrix NetScaler CVE-2026-19490: Fifteen Days From Patch to Exploitation - DEV Community
- Active Exploitation Alert: Citrix NetScaler ADC/Gateway Authentication Bypass (CVE-2026-19490) Added to CISA KEV — Patch and Forensic Triage Guidance
- CISA Warns of Citrix NetScaler Authentication Bypass Vulnerability Exploited in Attacks
- Critical Citrix NetScaler auth bypass now leveraged in attacks
- Citrix NetScaler CVE-2026-19490: The Auth Bypass That Went From PoC to Probes in a Day - CyberExperts.com
- CVE-2026-19490: Critical Citrix NetScaler Flaw
- CVE-2026-19490 Citrix NetScaler Auth Bypass: Patch Now
- What 239,000 Exposed NetScaler Instances Tell You About Remote Access Risk - DEV Community
- Citrix urges admins to patch NetScaler flaws as soon as possible
- Active Attacks Exploit Citrix NetScaler Flaw CVE-2026-19490
- Citrix NetScaler CVE-2026-19490: From Patch to PoC in Weeks — Defenders Are Out of Time | Shield53 Insights
- Citrix NetScaler Faces New Security Crisis as Bleed Vulnerabilities Resurface