Citrix took most of the weekend to confirm that attackers were actively exploiting the newest round of NetScaler zero-days, leaving network defenders and threat hunters to react without official confirmation.
Yet, behind the scenes, multiple CERTs, advisory firms, insurance providers, researchers and chatty security professionals warned their respective peers and communities of a live and serious threat.
Nearly two days after the first unconfirmed rumors, Citrix published a security advisory Sunday disclosing the exploited zero-days, CVE-2026-88771 and CVE-2026-88772, releasing patches for them and six additional defects.
By then, criticism was at a fever pitch, and for some NetScaler customers the warning came too late.
“The information vacuum was most striking. Customers were receiving warnings through unofficial channels while Citrix remained publicly silent,” Ben Harris, founder and CEO at watchTowr, told CyberScoop.
“Customers were left without communication, guidance, or even acknowledgement that the vulnerability that was rumored to exist was real. Citrix could have warned customers that active exploitation was occurring and provided immediate defensive guidance without disclosing technical details that would help attackers,” he added.
“When active exploitation is underway, hours matter,” Harris said.
Citrix did not directly answer questions about the lengthy communication delay.
“We recently identified critical vulnerabilities in Citrix NetScaler ADC and Citrix NetScaler Gateway that led us to immediately develop and release a new version of the software that addresses the issues,” the company said in a prepared statement.
The critical defects are both rated 9.5 on the CVSS scale and allow attackers to achieve remote code execution.
Researchers are particularly concerned about CVE-2026-88771, a command-injection vulnerability that affects all NetScaler appliances in a default configuration. That gives attackers a broad pool of targets and a better chance at successful exploitation. A proof-of-concept exploit for the vulnerability is also publicly available.
Palo Alto Networks said it identified more than 50,000 publicly exposed instances of Citrix NetScaler devices potentially vulnerable to both of the zero-days as of Sunday.
The earliest known exploitation attempt occurred Sept. 24 when GreyNoise said it observed an unsuccessful exploitation attempt against a Citrix NetScaler Gateway under its control for malicious activity scanning purposes. But researchers warn that exploitation likely started before then.
Citrix did not say how many customers have been compromised thus far and researchers are still assessing the fallout.
Citrix said it is making generic indicators of compromise available to customers in their user consoles, and the company referred to previously issued guidance for customers who suspect compromise.
Attribution for the attacks is also still under investigation, yet NetScaler products are a common, recurring target for financially-motivated cybercriminals and state-sponsored espionage groups.
The Cybersecurity and Infrastructure Security Agency issued an alert Sunday after Citrix publicly confirmed the attacks on its customers, and added CVE-2026-88771 and CVE-2026-88772 to its known exploited vulnerabilities catalog. The vendor has appeared on the agency’s list of vulnerabilities known to be exploited five times this year, and a total of 26 times since late 2021.
Security leaders across the industry — including Charles Carmakal, chief technology officer at Mandiant Consulting, and Wendi Whitmore, chief security intelligence officer at Palo Alto Networks — also sprung into action Sunday, with direct warnings on LinkedIn about the urgent threat.
The information vacuum that persisted through most of the weekend put cybersecurity professionals in sometimes unique positions. Joe Toomey, vice president of underwriting at insurance carrier Coalition, said the company notified potentially vulnerable customers with limited official data and no confirmation from CISA or Citrix.
In a LinkedIn post Sunday, he called Citrix “unconscionably irresponsible” for remaining silent for more than 36 hours after word began circulating about in-the-wild exploitation.
“I fully understand a vendor embargoing specific details about a vulnerability when a patch has not yet been published, but once the vuln is exploited in the wild, some of those rules no longer apply,” Toomey wrote.
Citrix and its customers are in familiar territory. The vendor’s products have been widely targeted in previous attack sprees, often involving zero-day exploits and some infamously referred to as CitrixBleed and CitrixBleed 2.
“Citrix has a history of delaying the publication of vulnerabilities, even when they’re being exploited in the wild and affecting customers. Citrix eventually released patches and an advisory, but an adequate response also requires timely, clear communication,” Harris said.
“Customers shouldn’t have to rely on unofficial warnings, security researchers, and third parties to learn that critical infrastructure may already be compromised,” he added. “This latest incident raises serious questions about whether Citrix has learned from previous crises and meaningfully improved how it protects and informs customers.”
The post Citrix patches actively exploited NetScaler zero-days after a weekend of unofficial warnings appeared first on CyberScoop.