# Citrix Faces Criticism Over Delayed Disclosure of NetScaler Vulnerabilities

*Published September 30, 2026*
*Source: [https://cyberscoop.com/citrix-zero-days-delayed-disclosure/](https://cyberscoop.com/citrix-zero-days-delayed-disclosure/)*

## Executive Summary

Citrix delayed disclosing actively exploited zero-day vulnerabilities in its NetScaler products, leading to criticism from the cybersecurity community. The lack of timely communication left customers relying on unofficial warnings before Citrix released patches and advisories.

## Article

Citrix recently faced significant backlash for its delayed response to actively exploited zero-day vulnerabilities in its NetScaler products. The company took the better part of a weekend to confirm that attackers were exploiting these vulnerabilities, identified as CVE-2026-88771 and CVE-2026-88772. By the time Citrix released patches and a security advisory, many customers had already been informed through unofficial channels, leading to widespread criticism about the company's communication practices. Security professionals and organizations such as CERTs, advisory firms, and insurance providers had been warning peers of the threat prior to Citrix's official acknowledgment. Ben Harris, CEO at watchTowr, highlighted the lack of communication from Citrix, stating that customers were left without guidance as rumors circulated. Citrix's statement confirmed the discovery of critical vulnerabilities, rated 9.5 on the CVSS scale, which allowed remote code execution. Particularly concerning is CVE-2026-88771, a command-injection vulnerability affecting all NetScaler appliances in default configurations. Palo Alto Networks identified over 50,000 vulnerable instances of Citrix NetScaler devices. The earliest known exploitation attempt occurred on September 24, though researchers suspect it began earlier. Attribution for the attacks remains unclear, with Citrix products being consistent targets for various threat actors. The Cybersecurity and Infrastructure Security Agency added the vulnerabilities to its known exploited vulnerabilities catalog. Industry leaders, including Charles Carmakal from Mandiant Consulting and Wendi Whitmore from Palo Alto Networks, issued warnings about the threat. Despite Citrix eventually releasing patches, the delay in alerting customers has raised questions about the company's approach to vulnerability disclosure and customer communication.
