CompaniesInvestorsPeople
Home
Loading

aVenture is in Beta: research coverage is expanding as we build, so please independently verify key details before making investment decisions.

aVenture is in Beta: research coverage is expanding as we build, so please independently verify key details before making investment decisions.

Get in Touch

  • Contact

  • Request a Demo

  • Request Data Updates

  • Add a Company

Research

  • Companies

  • Investors

  • People

aVenture

  • Download App

  • Pricing

Download the aVenture Research beta for iOS and iPadOSDownload aVenture Research on the Mac App Store

Resources

  • Documentation

  • CLI

  • MCP

  • Feature Requests

  • Sitemap

Member

Backed by

© aVenture Investment Company, 2026. All rights reserved.

San Francisco, CA, USA

Privacy Policy · Terms of Service

aVenture Investment Company ("aVenture") is an independent research platform providing detailed analysis and data on startups, venture capital investments, and key industry individuals. It is not a registered investment adviser, broker-dealer, or investment advisor and does not provide investment advice or recommendations. The data provided by aVenture does not constitute recommendations or advice, whether by methodology, analysis, AI-generated content, or a statement written by a staff member of aVenture.

aVenture is not affiliated with any of the people, companies, organizations, government agencies, regulatory bodies, or investment funds we provide coverage for on this site unless explicitly stated otherwise. Users assume full responsibility for decisions made based on information obtained from this platform. Links to external websites do not imply endorsement or affiliation with aVenture. Any links that provide the ability to invest in a primary or secondary transaction in a company are for convenience only and do not constitute solicitations or offers to buy or sell an investment. Investors should exercise heightened precaution and due diligence when investing in private companies, especially those not independently audited.

While we strive to provide valuable insights with objectivity and professional diligence, we cannot guarantee the accuracy of the information provided on our platform. Before making any investment decisions, you should verify the accuracy of all pertinent details for your decision. To the fullest extent permitted by law, aVenture shall not be liable for any direct, indirect, incidental, consequential, or financial damages arising from use of this site, whether by consumers of its contents directly or by persons or organizations covered by our research, even if we are advised of the possibility. Our best-efforts processes and correction request forms do not create a warranty or duty of care.

Profiles on this platform may include content generated in part by large language models (LLMs, artificial intelligence) that aggregate publicly available sources (e.g., SEC EDGAR, public filings, press releases). Source attribution is provided where known; always verify statements and claims here against original sources before relying on any data. Content on our site may contain inaccuracies, omissions, or what are commonly called 'hallucinations' if generated in part or in full by AI / LLMs. The risk can also exist even when content is written by a human, as internal and third-party sources may also have inaccuracies for the same or different reasons. While we randomly audit a proportion of content, this is not exhaustive.

We recommend that an independent auditor be hired to verify the accuracy of the information before relying on it for any sensitive decisions. By accessing this platform, you agree not to rely solely on any information generated by AI, aggregated, or sourced or written otherwise on this site, for investment, financial, or other decisions. aVenture assumes no responsibility for inaccuracies, omissions, or hallucinations. You must independently verify all data from primary sources. Use of this platform constitutes your waiver of claims for reliance-based damages, including negligent misrepresentation. To report an error, request a correction, or dispute information about a company or individual, contact us via our request data updates form.

Loading
Loading
Home
News
Citrix confirms two NetScaler RCE zero-days exploited in attacks

From BleepingComputer

By Lawrence Abrams

September 27, 2026

Citrix confirms two NetScaler RCE zero-days exploited in attacks

Citrix confirms two NetScaler RCE zero-days exploited in attacks
By
Lawrence Abrams
  • September 27, 2026
  • 12:02 PM
  • 0

Update: Article rewritten with official confirmation from Citrix.

Citrix has confirmed that two critical NetScaler remote code execution vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks and that it has released security updates to fix the flaws.

The vulnerabilities are the same zero-days that cybersecurity researchers, IT providers, and national cybersecurity agencies began privately warning organizations about over the weekend.

NetScaler appliances are particularly valuable targets because organizations commonly deploy them as Internet-facing edge devices that provide remote access and application delivery services for internal corporate networks.

Compromising one of these devices can give attackers an initial foothold at the perimeter of a victim's network and potentially provide a path to internal systems without first compromising an endpoint inside the organization.

The first signs of the incident appeared when Citrix administrators began reporting on Reddit that IT suppliers and security teams were privately contacting their organizations and advising them to shut down their NetScaler appliances.

"We got a call from our IT supplier's security team, they couldn't give any details but they advised to shut our Netscalers down immediately," one administrator wrote.

Other administrators said law enforcement, CERTs, and national cybersecurity agencies had also been contacting organizations about the issue.

Cybersecurity firm watchTowr later publicly warned that it was "rapidly reacting to rumors" that multiple unpatched Citrix NetScaler remote code execution vulnerabilities were being exploited in the wild after verifying the information with "authoratitive sources."

"We are currently rapidly reacting to rumors that multiple unpatched Citrix NetScaler RCE vulnerabilities are circulating in the wild. While details are scarce, the information is credible," watchTowr said.

Citrix confirms active exploitation

Citrix has now published security bulletin CTX697096, confirming the vulnerabilities and releasing patches for affected NetScaler ADC and NetScaler Gateway appliances.

CVE-2026-88771 is a remote code execution vulnerability caused by improper input validation, allowing an unauthenticated attacker to execute arbitrary commands. It has a severity score of 9.5.

Citrix says the flaw affects all NetScaler ADC and NetScaler Gateway deployments, including those using the default configuration, and does not require any additional feature to be enabled.

CVE-2026-88772 is a memory overflow vulnerability that can lead to remote code execution or a denial-of-service condition, also with a severity score of 9.5.

This vulnerability can be exploited when DTLS is enabled on a NetScaler ADC or NetScaler Gateway. Citrix notes that DTLS is enabled by default on VPN virtual servers.

Citrix has confirmed that both flaws have been exploited in attacks against NetScaler devices as zero-days.

"Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed," Citrix said in the security bulletin.

Citrix says the following versions are affected:

  • NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
  • NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
  • NetScaler ADC FIPS before 14.1-73.37 FIPS
  • NetScaler ADC FIPS and NDcPP before 13.1-37.279

Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds.

Citrix says the bulletin only applies to customer-managed NetScaler ADC and NetScaler Gateway appliances. Cloud Software Group is upgrading Citrix-managed cloud services and Citrix-managed Adaptive Authentication.

The security bulletin also fixes six other NetScaler vulnerabilities, bringing the total to eight flaws fixed in this update.

NCSC warned organizations before disclosure

Before Citrix publicly disclosed the vulnerabilities, the Dutch National Cyber Security Center (NCSC-NL) reportedly sent a pre-notification to organizations in the Netherlands warning about two critical NetScaler zero-days.

Multiple people shared copies of the notification online, which said the agency had received information from a European partner CERT regarding two vulnerabilities that could independently lead to remote code execution.

According to the notice, one vulnerability allowed attackers to place shellcode directly into memory, while technical details about the second vulnerability were still being researched.

At the time, no CVE identifiers had been assigned, and Citrix had not yet published an advisory.

The notification said Citrix discovered the vulnerabilities while investigating incidents in customer environments and identified active exploitation.

It also said Citrix submitted a notification under the European Union's Cyber Resilience Act after discovering the attacks.

The NCSC said exploitation had been identified at multiple Citrix customers worldwide, although it did not know whether the attacks were widespread.

The agency also warned that exploitation attempts could increase once Citrix released patches and additional technical details.

Because NetScaler upgrades can cause downtime, the NCSC said the warning was intended to give organizations time to prepare, implement safeguards where possible, and install patches quickly once they became available.

BleepingComputer contacted the Dutch NCSC to confirm whether the advisory circulating online was legitimate.

The agency declined to confirm the notification, saying it could not provide further information to organizations outside its constituency.

"As part of our role as the National CSIRT and sectoral CSIRT for designated organizations, the NCSC-NL monitors relevant developments and cyber threats affecting the Netherlands 24/7," the NCSC-NL told BleepingComputer.

"We provide information and advice to organizations so that they can take appropriate measures. As you're not part of our constituency, we cannot disclose any further information at this time."

Now that Citrix has released fixes and confirmed exploitation, administrators should upgrade affected NetScaler ADC and NetScaler Gateway appliances to the patched versions as soon as possible.

Organizations that cannot apply the updates immediately should reduce Internet exposure where operationally possible until they can patch the appliances.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

Related Articles:

CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday

F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks

N-able patches max severity N-central flaw amid ongoing attacks

Critical Citrix NetScaler auth bypass now leveraged in attacks

SonicWall warns of actively exploited SMA1000 zero-day flaws

View original article on bleepingcomputer.com

Most Recent

Announcing our partnership with OpenAI

Baseten is partnering with OpenAI to serve open models natively via Codex and the Responses API.

Sep 29, 2026

Interviews with Anthropic co-founder Christopher Olah and 20 religious and philosophical leaders about their summits to investigate consciousness in Claude

“To be clear,” Christopher Olah told me, “we don't know if A.I. models are conscious. I don't know. I'm genuinely uncertain.

Sep 29, 2026

Some Oura IPO Investors Were Said to Push Back Citing Valuation

Some investors approached about potentially buying shares in Oura Inc.'s now-delayed initial public offering decided not to go forward …

Sep 29, 2026

Apple Reportedly Planned to Replace 5,000 Support Employees With AI

Apple recently considered laying off about 5,000 support employees, but it has put those plans on hold indefinitely, according to Bloomberg's Mark Gurman. The report said that Apple believed that AI-powered phone and web agents could take over some of the responsibilities performed by the employees

Sep 29, 2026

Similar Posts

Why this month's Microsoft patch release is a doozy

Security gnomes are pumping out patches ahead of an expected onslaught of AI-assisted attacks.

Sep 8, 2026

Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day

A simple ClickFix attack is only one way to completely hijack the new agent.

Sep 21, 2026

Australian Federal Police arrest two Western Australia men, aged 21 and 23, believed to be members of TeamPCP, a prolific cybercrime and data extortion group

Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever.

Aug 27, 2026

Google warns of new Chrome zero-day flaw exploited in attacks

Google has updated the Chrome browser to address an actively exploited high-severity zero-day flaw in the V8 engine and 11 other vulnerabilities.

Sep 4, 2026