◆ NOISE IN → SIGNAL OUT◆ READALCHEMIST.COM◆ FREE / NO PAYWALL◆ NOISE IN → SIGNAL OUT◆ READALCHEMIST.COM◆ FREE / NO PAYWALL
THE DIGITAL ALCHEMIST
SecurityIMPACT 85

How Many Zero-Days Before Citrix Loses You?

Two new 9.5-severity NetScaler bugs are under active exploitation, one needing zero configuration to weaponize. It is the third exploited zero-day cycle from Citrix since June, and the pattern says the front door is now the risk.

2026-09-284 MIN READ#Citrix · #NetScaler · #zero-day · #vulnerability management · #perimeter security · #CVE-2026-88771
The Digital Alchemist
The Digital Alchemist

TITLE: How Many Zero-Days Before Citrix Loses You?

Someone's phone rang last weekend. One administrator wrote that their IT supplier's security team called with orders to "shut our Netscalers down immediately." Other administrators said law enforcement, CERTs, and national cybersecurity agencies were contacting organizations too. No CVE. No patch. Just a phone tree telling admins to unplug the box between the internet and everything they run.

By September 27, Citrix confirmed two critical NetScaler remote code execution vulnerabilities—CVE-2026-88771 and CVE-2026-88772—being actively exploited. CVE-2026-88771 allows unauthenticated attackers to execute arbitrary commands with a 9.5 severity score. Every NetScaler ADC and Gateway deployment is affected, including default configurations. CVE-2026-88772 leads to remote code execution or denial of service when DTLS is enabled, and Citrix ships DTLS enabled by default.

Translation: your out-of-the-box install is the attack surface.

watchTowr flagged the exposure before a CVE existed, alerting clients on September 26, a day before Citrix's bulletin.

Three strikes since June

This isn't the year's first fire drill. In June, Citrix shipped what it called a denial-of-service bug; by August, watchTowr showed successful exploitation allows remote code execution as root on unpatched instances. That's CVE-2026-8452. Weeks later came an authentication bypass. On September 9, CVE-2026-19490 hit CISA's Known Exploited Vulnerabilities catalog with active attacks already underway on a device sitting in front of enterprise remote access—fifteen days between patch and attacks. Now: two more 9.5 critical bugs, both weaponized before patches existed.

Three critical, actively exploited NetScaler chains in four months isn't bad luck. It's a release process that ships the vulnerability and lets outside researchers find the exploit.

NetScaler's 2026 Zero-Day Severity Climb
5CVSS score10CVSS score8.8CVSS scoreCVE-2026-8452 (Aug)9.3CVSS scoreCVE-2026-19490 (Sept 9)9.5CVSS scoreCVE-2026-88771/88772 (Sept 27)
CVSS scores for Citrix's three exploited NetScaler zero-day cycles in 2026, per Rapid7, SecurityWeek, and BleepingComputer.

Shadowserver tracks over 22,000 NetScaler ADC appliances and nearly 1,800 Gateway instances exposed online.

The Digital Alchemist
The Digital Alchemist
The NetScaler Exposure Snapshot
22,000NetScaler ADCappliances exposedonline3Exploited criticalzero-day cycles sinceJune9.5CVSS severity of thetwo newest flaws
Exposure and severity data from Shadowserver, Citrix, and CISA as of September 2026.

The isolation tax

Here's what "shut it down" actually costs. NetScaler ADC and Gateway handle VPN, load balancing, and authentication for remote workers and internal apps. Taking it offline closes the door your workforce walks through daily.

And patching doesn't clear the board. Because flaws were exploited as zero-days before patches existed, shutting down or patching won't remove attackers already inside. After a prior NetScaler zero-day hit Dutch organizations, the Netherlands' National Cyber Security Centre said that updating alone didn't remove the risk—attackers kept access gained before the patch.

Your remote-access perimeter doesn't need three shutdown orders in four months to be rented out to whoever finds the bug first. Any CISO still calling NetScaler "managed and monitored" is signing off on a control they don't control.

What to watch

Whether Citrix's next earnings call names the trust problem or buries it in security-investment language. Whether large NetScaler shops start replacement RFPs—a direct gift to F5, Cloudflare, and cloud-native vendors. Whether cyber insurance renewals start asking pointed questions about NetScaler exposure. At three cycles in four months, the next KEV addition for this product line won't read as surprise. It will read as routine.

Sources
  1. Citrix admins warned to shut down NetScalers over 2 exploited zero-days
  2. Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
  3. Citrix NetScaler Zero-Day RCE FAQ: CVE-2026-88771 and CVE-2026-88772
  4. CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday
  5. CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
  6. Citrix NetScaler Zero-Day RCE vulnerabilities: FAQ
  7. Inside the NetScaler Zero-Day Siege: Chained Pre-Auth RCEs Weaponized in the Wild (watchTowr Disclosure) | Shellcode (Sh3llc0d3)
  8. Citrix Patches Two Exploited NetScaler RCE Zero-Days - Cyber Kendra
  9. Unpatched NetScaler Zero-Days Exploited, watchTowr Says - Cyber Kendra
  10. Citrix NetScaler’s 2 Zero-Days Ship With No CVE [2026]
  11. Citrix NetScaler Zero-Days Under Active Attack: Two Critical RCE Flaws Force Emergency Patching
  12. Citrix admins warned to shut down NetScalers over 2 exploited zero-days | daily.dev
  13. Citrix admins warned to shut down NetScalers over 2 exploited zero-days
  14. Citrix admins warned to shut down NetScalers over 2 exploited zero-days - Live Threat Intelligence - Threat Radar | OffSeq.com
  15. Citrix confirms two NetScaler RCE zero-days exploited in attacks
  16. Citrix confirms two NetScaler RCE zero-days exploited in attacks - We Fix PC
  17. Citrix confirms two NetScaler RCE zero-days exploited in attacks - PRSOL:CC
  18. PoC Exploit Available for Citrix NetScaler ADC and Gateway CVE- 2026-8452
  19. CVE-2026-8452 | Arctic Wolf
  20. CVE-2026-8452: NetScaler DoS Flaw Now Unauthenticated RCE – Lab Space
  21. You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?))
  22. H-ISAC TLP White Threat Bulletin: PoC Exploit Available for Citrix NetScaler ADC and Gateway CVE-2026-8452 | AHA
  23. CVE Record: CVE-2026-8452 - NetScaler
  24. Citrix NetScaler CVE-2026-8452 Exploited as Root | Obiguard
  25. CVE-2026-8452: Citrix NetScaler Pre-Auth Root RCE
  26. CISA Adds 6 Exploited Flaws to KEV, Feds Get 3 Days
  27. Exploitation of CitrixBleed 2 (CVE-2025-5777) Began Before PoC Was Public
  28. Check for CitrixBleed 2 exploitation even if you patched quickly! (CVE-2025-5777) - Help Net Security
  29. CitrixBleed 2: When Memory Leaks Become Session Hijacks | Splunk
  30. Citrix Bleed 2 exploited weeks before PoCs as Citrix denied attacks
  31. CVE‑2025‑5777: Critical Citrix NetScaler Vulnerability Exploited
  32. GitHub - win3zz/CVE-2025-5777: CVE-2025-5777 (CitrixBleed 2) - Critical memory leak vulnerability affecting Citrix NetScaler ADC and Gateway devices · GitHub
  33. CVE-2025-5777: CitrixBleed 2 Write-Up… Maybe?
  34. Critical NetScaler Flaw Exposes Sensitive Memory Contents to Remote…
  35. Updates on Actively Exploited Information Disclosure Vulnerability “Citrix Bleed 2” in Citrix NetScaler ADC and Gateway I Arctic Wolf
  36. What is CitrixBleed 2 (CVE-2025-5777)? - Cyberwarzone
  37. Early exploitation of Citrix NetScaler authentication bypass vulnerability
  38. Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScaler - SecurityWeek
  39. Citrix NetScaler CVE-2026-19490: Fifteen Days From Patch to Exploitation - DEV Community
  40. Active Exploitation Alert: Citrix NetScaler ADC/Gateway Authentication Bypass (CVE-2026-19490) Added to CISA KEV — Patch and Forensic Triage Guidance
  41. CISA Warns of Citrix NetScaler Authentication Bypass Vulnerability Exploited in Attacks
  42. Critical Citrix NetScaler auth bypass now leveraged in attacks
  43. Citrix NetScaler CVE-2026-19490: The Auth Bypass That Went From PoC to Probes in a Day - CyberExperts.com
  44. CVE-2026-19490: Critical Citrix NetScaler Flaw
  45. CVE-2026-19490 Citrix NetScaler Auth Bypass: Patch Now
  46. What 239,000 Exposed NetScaler Instances Tell You About Remote Access Risk - DEV Community
  47. Citrix urges admins to patch NetScaler flaws as soon as possible
  48. Active Attacks Exploit Citrix NetScaler Flaw CVE-2026-19490
  49. Citrix NetScaler CVE-2026-19490: From Patch to PoC in Weeks — Defenders Are Out of Time | Shield53 Insights
  50. Citrix NetScaler Faces New Security Crisis as Bleed Vulnerabilities Resurface
← back to the feed
NVDA 230.86 ▲ 1.09%AAPL 330.32 ▼ 0.81%MSFT 512.80 ▼ 0.02%GOOGL 338.24 ▼ 1.70%AMZN 248.23 ▼ 0.37%META 725.93 ▲ 0.10%TSLA 354.11 ▼ 0.20%AMD 615.73 ▲ 0.65%AVGO 343.64 ▼ 2.15%PLTR 190.04 ▲ 1.60%COIN 189.29 ▲ 1.54%MSTR 160.50 ▲ 4.84%NVDA 230.86 ▲ 1.09%AAPL 330.32 ▼ 0.81%MSFT 512.80 ▼ 0.02%GOOGL 338.24 ▼ 1.70%AMZN 248.23 ▼ 0.37%META 725.93 ▲ 0.10%TSLA 354.11 ▼ 0.20%AMD 615.73 ▲ 0.65%AVGO 343.64 ▼ 2.15%PLTR 190.04 ▲ 1.60%COIN 189.29 ▲ 1.54%MSTR 160.50 ▲ 4.84%