Citrix has released emergency security updates for two critical zero-day vulnerabilities affecting NetScaler ADC and NetScaler Gateway after confirming that attackers are already exploiting both flaws in real-world attacks. Tracked as CVE-2026-88771 and CVE-2026-88772, the vulnerabilities each carry a CVSS v4.0 score of 9.5 and can enable unauthenticated remote code execution on vulnerable appliances.
The flaws are particularly dangerous because NetScaler appliances commonly sit at the edge of enterprise networks, providing application delivery, VPN access, authentication, and remote connectivity. Successful compromise can therefore give attackers a strategically valuable foothold between external users and internal infrastructure.
CVE-2026-88771 is caused by improper input validation and can allow an unauthenticated attacker to execute arbitrary commands remotely. No optional feature or special configuration is required: vulnerable NetScaler ADC and Gateway deployments are exposed even in their default configuration.
CVE-2026-88772 is a memory overflow vulnerability that can result in remote code execution or denial of service. Exploitation requires DTLS to be enabled, but Citrix notes that DTLS is enabled by default on VPN virtual servers, making many NetScaler Gateway deployments potentially exposed without administrators having explicitly turned the feature on.
CISA added both vulnerabilities to its Known Exploited Vulnerabilities catalog on September 27, 2026, citing reports and partner intelligence confirming global exploitation. Federal Civilian Executive Branch agencies were given until September 30 to apply Citrix’s fixes.
CVE-2026-88771 and CVE-2026-88772 analysis
The two zero-days provide different technical paths to compromise but lead to similarly severe outcomes.
CVE-2026-88771 analysis centers on an improper input validation weakness classified as CWE-20. Citrix states that an unauthenticated network attacker can exploit the flaw to execute arbitrary commands on a vulnerable NetScaler appliance.
The vulnerability requires no special deployment mode. CVE-2026-88771 affects all vulnerable NetScaler ADC and NetScaler Gateway installations, including systems running the default configuration.
Its CVSS 4.0 vector is:
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
The vulnerability is remotely reachable, requires no attacker privileges or victim interaction, and can have high impact across confidentiality, integrity, and availability.
CVE-2026-88772 takes a different path. The vulnerability is classified as CWE-119, Improper Restriction of Operations within the Bounds of a Memory Buffer. Memory corruption triggered through the vulnerable DTLS path can cause either remote code execution or denial of service.
The key details for CVE-2026-88772 are configuration-related. The vulnerable condition exists when DTLS is enabled on NetScaler ADC or Gateway. Citrix specifically warns that DTLS is enabled by default on VPN virtual servers.
For example, a configuration such as:
add vpn vserver vpn1 SSL 10.0.0.0 443 -Listenpolicy NONE
does not explicitly disable DTLS, meaning the VPN virtual server remains exposed.
A configuration containing:
-dtls OFF
does not meet the documented prerequisite for this particular vulnerability.
Other virtual servers configured directly with the DTLS type can also expose the vulnerable functionality.
CVE-2026-88772 has the following CVSS 4.0 vector:
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Although Citrix rates its attack complexity higher than CVE-2026-88771, successful exploitation can still provide unauthenticated RCE and potentially complete compromise of the affected appliance.
Both vulnerabilities affect the following supported NetScaler releases before their respective fixed builds:
- NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
- NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
- NetScaler ADC FIPS 14.1 before 14.1-73.37 FIPS
- NetScaler ADC FIPS and NDcPP 13.1 before 13.1-37.279
Secure Private Access Hybrid deployments that use affected NetScaler instances also require upgrades.
Citrix-managed cloud services and Citrix-managed Adaptive Authentication are handled by Cloud Software Group, which applies the required software updates to those managed services.
The disclosure followed unusual warnings over the preceding weekend. Before Citrix published CVE identifiers and patches, security researchers and incident responders had reported evidence of multiple previously undisclosed NetScaler RCE vulnerabilities being exploited against internet-facing appliances. Some organizations were reportedly advised to isolate or temporarily shut down vulnerable systems while awaiting official remediation.
Citrix published CTX697096 on September 27, confirming that exploitation of both vulnerabilities had been observed on unmitigated deployments.
The exact private discovery dates have not been publicly disclosed, and Citrix has not identified the threat actors responsible for the attacks or provided a definitive start date for the exploitation campaign.
The attacks are significant because edge appliances provide an attractive initial foothold. Successful command or code execution on a NetScaler system could potentially allow attackers to deploy persistent payloads, access authentication material, inspect traffic, steal credentials, alter configuration, or pivot toward systems reachable from the appliance.
These are potential consequences of appliance compromise. Citrix has not publicly documented the complete post-exploitation chain used in every observed attack.
At present, there is no credible, independently verified fully weaponized public CVE-2026-88771 PoC referenced in Citrix’s advisory or the two requested reports. This does not lower the immediate risk: Citrix and CISA have already confirmed that attackers possess working exploitation capabilities.
Citrix has made generic compromise-detection capabilities available through the NetScaler Console Security Advisory workflow. The feature requires telemetry and is available through the Console service as well as supported on-premises Console deployments using Cloud Connect.
There is no comprehensive public set of attacker-specific CVE-2026-88772 IOCs such as IP addresses, malware hashes, domains, or command strings in the source material. Organizations should therefore avoid treating the absence of a known IOC match as evidence that an appliance is clean.
Citrix specifically warns that its available checks cannot cover every attacker technique and may fail to identify every compromise. External logs and forensic evidence are therefore important.
CVE-2026-88771 and CVE-2026-88772 Mitigation
Citrix strongly recommends upgrading every affected NetScaler ADC and Gateway appliance immediately.
The fixed builds are:
- NetScaler ADC / Gateway 14.1-73.37 or later
- NetScaler ADC / Gateway 13.1-64.23 or later
- NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS or later
- NetScaler ADC 13.1-FIPS / NDcPP 13.1-37.279 or later
Administrators running 13.1 should also review Citrix’s latest upgrade guidance. Citrix notes that some deployments using NetScaler variables may encounter a reboot-loop issue during upgrade to 13.1-64.23 and advises planning for 13.1-64.24 where applicable.
For CVE-2026-88771 there is no configuration prerequisite that administrators can simply disable. The vulnerability affects default configurations, so reducing exposure does not replace installation of the vendor update.
The primary CVE-2026-88772 mitigation is also upgrading to a fixed build. Administrators can additionally determine whether the vulnerable DTLS condition exists and, where operationally appropriate, explicitly disable DTLS on VPN virtual servers until patching is complete. This should be viewed only as exposure reduction for that CVE, not as a substitute for updating the appliance.
Because exploitation has already occurred, defenders should approach remediation as both a patching and incident-response exercise.
CVE-2026-88771 detection should start by identifying every customer-managed NetScaler ADC and Gateway appliance, determining its exact running build, and establishing whether it was internet-accessible before remediation.
For the second flaw, security teams should inspect the running configuration for VPN or other virtual servers with DTLS enabled.
To Detect CVE-2026-88772 exploitation or suspicious activity related to either zero-day, defenders should investigate:
- Unexpected commands or processes on NetScaler appliances
- Newly created or modified files with no legitimate administrative explanation
- Unexplained configuration changes
- New or modified authentication settings
- Abnormal outbound connections from the appliance
- Unexpected connections from NetScaler toward internal servers
- Appliance crashes or unexplained restarts
- Timestamps showing unauthorized changes during periods of suspicious external access
- New persistence mechanisms or web-accessible files
- Unusual authentication activity associated with the appliance
- Differences between local device logs and externally stored SIEM or network telemetry
These behaviors are investigation leads rather than unique signatures for the vulnerabilities.
Organizations should run Citrix’s available IOC scan through NetScaler Console but should not stop there. Citrix cautions that a clean scan cannot conclusively prove that exploitation did not occur.
Forwarding appliance logs to an external SIEM is particularly valuable. An attacker with code execution on an edge appliance may be able to alter or remove local evidence, while externally stored firewall, authentication, DNS, NetFlow, proxy, and SIEM records remain outside the compromised system.
CISA has also emphasized forensic triage as part of its remediation guidance for the two vulnerabilities.
If compromise is suspected, recommended response actions include:
- Preserve evidence from the affected NetScaler instance
- Isolate the appliance
- Revoke affected credentials and access
- Investigate systems the appliance communicated with
- Rebuild the compromised device
- Upgrade to a fixed firmware release
- Rotate local account passwords
- Rotate Key Encryption Keys where appropriate
- Replace restored SSL certificates if rebuilding from a known-good backup
- Harden the rebuilt appliance according to Citrix security guidance
Patching a previously compromised appliance does not remove persistence, web shells, stolen credentials, or other attacker artifacts that may already exist.
Organizations should therefore treat any vulnerable internet-facing appliance that was exposed during the known exploitation period as requiring retrospective investigation.
FAQ
What are CVE-2026-88771 and CVE-2026-88772 and how does it work?
CVE-2026-88771 is an improper input validation vulnerability in NetScaler ADC and Gateway that allows an unauthenticated remote attacker to execute arbitrary commands. CVE-2026-88772 is a memory overflow affecting deployments with DTLS enabled and can cause remote code execution or denial of service. DTLS is enabled by default on NetScaler VPN virtual servers.
When were CVE-2026-88771 and CVE-2026-88772 first discovered?
Citrix has not publicly disclosed the exact original discovery dates. Reports of exploited NetScaler RCE zero-days emerged immediately before the vendor advisory, and Citrix formally disclosed both vulnerabilities on September 27, 2026 in bulletin CTX697096. CISA added them to the KEV catalog the same day.
What is the impact of CVE-2026-88771 and CVE-2026-88772 on systems?
Both vulnerabilities can enable unauthenticated remote code execution on affected NetScaler appliances. CVE-2026-88772 can additionally cause denial of service. Successful compromise of an edge gateway may expose sensitive configuration, authentication material, and connected systems and can provide attackers with a foothold for further intrusion.
Can CVE-2026-88771 and CVE-2026-88772 still affect me in 2026?
Yes. NetScaler ADC and Gateway systems running versions earlier than 14.1-73.37 or 13.1-64.23 remain vulnerable, along with the corresponding affected FIPS and NDcPP builds. Both vulnerabilities are already being exploited globally and are listed in CISA’s Known Exploited Vulnerabilities catalog.
How can I protect myself from CVE-2026-88771 and CVE-2026-88772?
Upgrade immediately to the appropriate fixed NetScaler release. Verify DTLS exposure, run Citrix’s compromise checks, preserve logs and forensic evidence, and investigate appliances that were exposed before patching. If compromise is suspected, isolate and rebuild the appliance, rotate credentials and encryption material, and investigate systems that were reachable from the compromised NetScaler device.