watchTowr Reports Actively Exploited Zero-Days in Citrix NetScaler ADC and Gateway
Two unpatched vulnerabilities allow remote code execution; Citrix has not confirmed or patched the flaws

Key Takeaways
- Two unpatched zero-day vulnerabilities in Citrix NetScaler ADC and Gateway are under active exploitation.
- The flaws enable remote code execution without authentication.
- Citrix has not confirmed the vulnerabilities or released a patch.
- Administrators are taking appliances offline as a precaution while waiting for a fix.
Related Security News

Hackers exploit Citrix NetScaler zero-day to deploy web shells
Cybersecurity firms report that attackers are exploiting a zero-day vulnerability in Citrix NetScaler to deploy custom web shells and tunneling malware. The exploitation grants root access, enables credential theft, and facilitates lateral movement into internal networks. Citrix has released patches and security advisories addressing CVE-2026-88772.



