Citrix has confirmed active exploitation of two critical NetScaler remote code execution vulnerabilities, CVE-2026-88771 and CVE-2026-88772. The company has released emergency security updates for NetScaler ADC and NetScaler Gateway and is urging affected organizations to upgrade immediately.
Both flaws carry a CVSS v4.0 score of 9.5 and can allow remote, unauthenticated attackers to execute code on vulnerable appliances under the required conditions.
Citrix NetScaler CVE-2026-88771 RCE Affects Default Deployments
According to Citrix’s official NetScaler security bulletin CTX697096, CVE-2026-88771 is an improper input validation vulnerability that can allow an unauthenticated attacker to execute arbitrary commands.
The vulnerability is particularly serious because Citrix says it affects all NetScaler ADC and NetScaler Gateway deployments and does not require an optional feature or special configuration.
Citrix assigns CVE-2026-88771 a CVSS v4.0 base score of 9.5 Critical.
CVE-2026-88772 Can Lead to RCE or Denial of Service
The second actively exploited vulnerability, CVE-2026-88772, is a memory overflow issue that can result in remote code execution or denial of service.
This flaw requires DTLS to be enabled on the vulnerable NetScaler ADC or NetScaler Gateway appliance. Citrix notes that DTLS is enabled by default on VPN virtual servers, making the vulnerability relevant to many internet-facing remote-access deployments.
CVE-2026-88772 also carries a CVSS v4.0 score of 9.5 Critical.
Citrix Confirms Active Exploitation
Citrix states that exploits targeting CVE-2026-88771 and CVE-2026-88772 have been observed against unmitigated NetScaler deployments.
This confirmation follows earlier reports from security researchers that two previously undisclosed NetScaler remote code execution zero-days were being used during real-world attacks.
Because NetScaler appliances often sit directly at the enterprise network perimeter and provide VPN, authentication and application-delivery services, successful exploitation can give attackers a highly privileged foothold inside an organization.
Eight NetScaler Vulnerabilities Fixed in the Security Update
The Citrix bulletin addresses eight vulnerabilities in total:
| CVE | Impact | Severity |
|---|---|---|
| CVE-2026-88771 | Unauthenticated arbitrary command execution | Critical — CVSS 9.5 |
| CVE-2026-88772 | Memory overflow leading to RCE or DoS | Critical — CVSS 9.5 |
| CVE-2026-88773 | HTTP request smuggling | Critical — CVSS 9.3 |
| CVE-2026-88774 | HTTP policy bypass | High |
| CVE-2026-88775 | Memory overflow | High |
| CVE-2026-88776 | Memory overflow | High |
| CVE-2026-88777 | Memory overflow | High |
| CVE-2026-88778 | TCP-related security issue requiring configuration mitigation | See vendor advisory |
Organizations should review the official bulletin for the exact prerequisites associated with each vulnerability rather than assuming every flaw affects every deployment in the same way.
Affected NetScaler Versions
Citrix says the following supported versions are affected:
- NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
- NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
- NetScaler ADC 14.1-FIPS before 14.1-73.37 FIPS
- NetScaler ADC 13.1-FIPS and 13.1-NDcPP before 13.1-37.279
Secure Private Access Hybrid deployments that use affected NetScaler instances are also impacted.
Fixed NetScaler Builds
Citrix recommends upgrading to the following builds or later:
- 14.1: 14.1-73.37
- 13.1: 13.1-64.23
- 14.1 FIPS: 14.1-73.37 FIPS
- 13.1 FIPS / NDcPP: 13.1-37.279
Citrix-managed cloud services and Citrix-managed Adaptive Authentication are updated by Cloud Software Group and are not handled like customer-managed appliances.
Why CVE-2026-88771 Is Especially Dangerous
CVE-2026-88771 stands out because it does not depend on a specialized optional configuration. Citrix says the vulnerability affects default NetScaler ADC and Gateway deployments.
An unauthenticated attacker able to reach a vulnerable appliance may therefore have a path to arbitrary command execution without first compromising a user account.
That makes internet-facing NetScaler systems particularly attractive targets for attackers seeking perimeter access.
What NetScaler Administrators Should Do Now
- Upgrade affected appliances to the fixed NetScaler builds immediately.
- Prioritize internet-facing Gateway and ADC systems.
- Identify whether DTLS is enabled, particularly on VPN virtual servers.
- Review appliance logs for suspicious authentication, configuration and command activity.
- Investigate systems that were exposed before patching for possible compromise.
- Do not assume patch installation alone removes persistence established before the update.
For CVE-2026-88778, Citrix also directs administrators to apply the TCP configuration change described in its official NetScaler documentation where applicable.
Do Not Confuse These Flaws With CVE-2026-8452
The newly disclosed CVE-2026-88771 and CVE-2026-88772 vulnerabilities are separate from the earlier NetScaler vulnerability tracked as CVE-2026-8452.
CyberUpdates365 previously covered CVE-2026-8452 and its demonstrated pre-authentication root-level RCE impact.
The new September security bulletin introduces a different set of vulnerabilities and requires another round of NetScaler updates.
Why NetScaler Remains a High-Value Attack Target
NetScaler appliances frequently handle VPN access, identity flows and application delivery at the edge of enterprise environments.
A vulnerability that enables unauthenticated command execution on such systems can provide attackers with a strategic foothold before they encounter internal endpoint security controls.
For broader tracking of actively exploited enterprise vulnerabilities, see the CyberUpdates365 CVE & Vulnerability Exploits hub.
Administrators should also review our coverage of the actively exploited F5 BIG-IP vulnerability for another recent example of security risks affecting internet-facing enterprise infrastructure.
Security Summary
Citrix has confirmed active exploitation of CVE-2026-88771 and CVE-2026-88772 against unmitigated NetScaler systems.
CVE-2026-88771 is especially concerning because it affects default NetScaler ADC and Gateway deployments and can allow unauthenticated arbitrary command execution. CVE-2026-88772 can lead to remote code execution or denial of service on DTLS-enabled systems.
Organizations operating affected NetScaler appliances should upgrade immediately and investigate systems that were exposed before the fixes were applied.




