Two NetScaler zero-days exploited in the wild, one in default configuration
Citrix disclosed eight vulnerabilities in NetScaler ADC and NetScaler Gateway on 27 September, and two of them were already being exploited as zero-days before the advisory went out. Both carry a critical CVSSv4 score of 9.5 and allow remote code execution, according to a Rapid7 analysis published on 28 September.
CVE-2026-88771 is the more dangerous of the pair. It is an improper input validation flaw that affects NetScaler in its default configuration, with no additional features required, and the vendor rates its attack complexity as low. Rapid7 concludes that reliable code execution is likely against any vulnerable appliance regardless of how it is configured. CVE-2026-88772 is a memory corruption flaw that requires the DTLS feature to be enabled, and its attack complexity is rated high. The remaining six include memory overflows that apply only to specific configurations, such as an Oracle-type load balancer or CGNAT and NAT64 setups.
The US Cybersecurity and Infrastructure Security Agency added both exploited flaws to its Known Exploited Vulnerabilities catalog on 27 September and reports exploitation globally. Fixed releases are NetScaler ADC and Gateway 14.1-73.37 and later, 13.1-64.23 and later releases of 13.1, 14.1-FIPS 14.1-73.37 FIPS and later, and 13.1.37.279 and later for the 13.1-FIPS and 13.1-NDcPP builds.
Rapid7 recommends updating on an emergency basis, outside normal patch cycles, and checking vulnerable appliances for signs of compromise.

What it means
A default-configuration bug with low attack complexity on an internet-facing gateway leaves no configuration argument to hide behind. Because both flaws were exploited before the fix existed, patching closes the door but says nothing about who came through it earlier: the second half of the advice, looking for compromise, is the part most likely to be skipped.