Citrix NetScaler Zero-Days: No Patches, Active Exploitation, Complete Network Compromise

Citrix confirmed two NetScaler remote code execution vulnerabilities being exploited in attacks right now. No patches exist. The appliances under attack are the edge devices sitting between the internet and corporate networks — the front door.

The Vulnerabilities

CVE-2026-88771 involves improper input validation that allows an unauthenticated attacker to execute arbitrary commands on the appliance. That is complete compromise: read, write, execute, pivot.

CVE-2026-88772 carries the same threat profile. Both disclosed September 2026, both confirmed under active exploitation.

NetScaler appliances are high-value targets. Organizations deploy them as Internet-facing edge devices providing remote access and application delivery for internal corporate networks. An attacker who owns the edge appliance owns a foothold inside the perimeter, with visibility into internal traffic and the credentials it carries.

Source: BleepingComputer and The Hacker News, September 2026.

What This Means

Complete appliance compromise. Lateral movement into corporate networks. Credential harvesting from passing traffic. Persistence.

The math: NetScaler appliances sit at the edge by design. An edge device is the first thing an attacker hits, and the last thing you can afford to lose. A vulnerability there is not a bug to patch next quarter. It is the perimeter collapsing in real time.

No Patches

Citrix disclosed the vulnerabilities. Citrix confirmed active exploitation. Citrix has no patches available yet.

The only mitigation is shutting the appliances down or taking them offline – which defeats the purpose of having remote access infrastructure in the first place.

That leaves organizations with a choice nobody should have to make: run the appliance and accept that it is already or will shortly be compromised, or pull it offline and lose the remote access and application delivery it provides.

Who Owns This

Citrix owns this. The disclosure without a patch is transparency, but it is not a solution. Saying "we know attackers are exploiting this and we have nothing for you yet" is not a remediation plan.

The organizations running NetScaler appliances do not own this failure. They deployed vendor-supported edge infrastructure. The vendor disclosed that the infrastructure is under active attack and provided no fix.

Patching is owed before exploitation, not after. A zero-day is the failure of the development and QA process to catch it first. Two zero-days under simultaneous exploitation is a pattern.

The Verdict

Unpatched zero-days on Internet-facing edge infrastructure under active exploitation is the scenario incident response teams build runbooks to prevent. Citrix disclosed it as the current state.

Organizations are flying blind: they can't patch what doesn't exist, can't take appliances offline without losing critical access, and can't determine whether their edge has already been compromised without forensics that assume the appliance logs are intact and unmodified – an assumption that fails the moment an attacker with RCE gets in.

Citrix needs to ship patches yesterday. Until then, every NetScaler appliance is a countdown.