Menu
VULNERABILITIES & FIXES

Citrix NetScaler CVE-2026-88771 and CVE-2026-88772 Actively Exploited for RCE

Uday Patil Sep 28, 2026 5 min read 13 views
Citrix NetScaler CVE-2026-88771 and CVE-2026-88772 Actively Exploited for RCE

Citrix has confirmed active exploitation of two critical NetScaler remote code execution vulnerabilities, CVE-2026-88771 and CVE-2026-88772. The company has released emergency security updates for NetScaler ADC and NetScaler Gateway and is urging affected organizations to upgrade immediately.

Both flaws carry a CVSS v4.0 score of 9.5 and can allow remote, unauthenticated attackers to execute code on vulnerable appliances under the required conditions.

Citrix NetScaler CVE-2026-88771 RCE Affects Default Deployments

According to Citrix’s official NetScaler security bulletin CTX697096, CVE-2026-88771 is an improper input validation vulnerability that can allow an unauthenticated attacker to execute arbitrary commands.

The vulnerability is particularly serious because Citrix says it affects all NetScaler ADC and NetScaler Gateway deployments and does not require an optional feature or special configuration.

Citrix assigns CVE-2026-88771 a CVSS v4.0 base score of 9.5 Critical.

CVE-2026-88772 Can Lead to RCE or Denial of Service

The second actively exploited vulnerability, CVE-2026-88772, is a memory overflow issue that can result in remote code execution or denial of service.

This flaw requires DTLS to be enabled on the vulnerable NetScaler ADC or NetScaler Gateway appliance. Citrix notes that DTLS is enabled by default on VPN virtual servers, making the vulnerability relevant to many internet-facing remote-access deployments.

CVE-2026-88772 also carries a CVSS v4.0 score of 9.5 Critical.

Citrix Confirms Active Exploitation

Citrix states that exploits targeting CVE-2026-88771 and CVE-2026-88772 have been observed against unmitigated NetScaler deployments.

This confirmation follows earlier reports from security researchers that two previously undisclosed NetScaler remote code execution zero-days were being used during real-world attacks.

Because NetScaler appliances often sit directly at the enterprise network perimeter and provide VPN, authentication and application-delivery services, successful exploitation can give attackers a highly privileged foothold inside an organization.

Eight NetScaler Vulnerabilities Fixed in the Security Update

The Citrix bulletin addresses eight vulnerabilities in total:

CVEImpactSeverity
CVE-2026-88771Unauthenticated arbitrary command executionCritical — CVSS 9.5
CVE-2026-88772Memory overflow leading to RCE or DoSCritical — CVSS 9.5
CVE-2026-88773HTTP request smugglingCritical — CVSS 9.3
CVE-2026-88774HTTP policy bypassHigh
CVE-2026-88775Memory overflowHigh
CVE-2026-88776Memory overflowHigh
CVE-2026-88777Memory overflowHigh
CVE-2026-88778TCP-related security issue requiring configuration mitigationSee vendor advisory

Organizations should review the official bulletin for the exact prerequisites associated with each vulnerability rather than assuming every flaw affects every deployment in the same way.

Affected NetScaler Versions

Citrix says the following supported versions are affected:

  • NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
  • NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
  • NetScaler ADC 14.1-FIPS before 14.1-73.37 FIPS
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP before 13.1-37.279

Secure Private Access Hybrid deployments that use affected NetScaler instances are also impacted.

Fixed NetScaler Builds

Citrix recommends upgrading to the following builds or later:

  • 14.1: 14.1-73.37
  • 13.1: 13.1-64.23
  • 14.1 FIPS: 14.1-73.37 FIPS
  • 13.1 FIPS / NDcPP: 13.1-37.279

Citrix-managed cloud services and Citrix-managed Adaptive Authentication are updated by Cloud Software Group and are not handled like customer-managed appliances.

Why CVE-2026-88771 Is Especially Dangerous

CVE-2026-88771 stands out because it does not depend on a specialized optional configuration. Citrix says the vulnerability affects default NetScaler ADC and Gateway deployments.

An unauthenticated attacker able to reach a vulnerable appliance may therefore have a path to arbitrary command execution without first compromising a user account.

That makes internet-facing NetScaler systems particularly attractive targets for attackers seeking perimeter access.

What NetScaler Administrators Should Do Now

  • Upgrade affected appliances to the fixed NetScaler builds immediately.
  • Prioritize internet-facing Gateway and ADC systems.
  • Identify whether DTLS is enabled, particularly on VPN virtual servers.
  • Review appliance logs for suspicious authentication, configuration and command activity.
  • Investigate systems that were exposed before patching for possible compromise.
  • Do not assume patch installation alone removes persistence established before the update.

For CVE-2026-88778, Citrix also directs administrators to apply the TCP configuration change described in its official NetScaler documentation where applicable.

Do Not Confuse These Flaws With CVE-2026-8452

The newly disclosed CVE-2026-88771 and CVE-2026-88772 vulnerabilities are separate from the earlier NetScaler vulnerability tracked as CVE-2026-8452.

CyberUpdates365 previously covered CVE-2026-8452 and its demonstrated pre-authentication root-level RCE impact.

The new September security bulletin introduces a different set of vulnerabilities and requires another round of NetScaler updates.

Why NetScaler Remains a High-Value Attack Target

NetScaler appliances frequently handle VPN access, identity flows and application delivery at the edge of enterprise environments.

A vulnerability that enables unauthenticated command execution on such systems can provide attackers with a strategic foothold before they encounter internal endpoint security controls.

For broader tracking of actively exploited enterprise vulnerabilities, see the CyberUpdates365 CVE & Vulnerability Exploits hub.

Administrators should also review our coverage of the actively exploited F5 BIG-IP vulnerability for another recent example of security risks affecting internet-facing enterprise infrastructure.

Security Summary

Citrix has confirmed active exploitation of CVE-2026-88771 and CVE-2026-88772 against unmitigated NetScaler systems.

CVE-2026-88771 is especially concerning because it affects default NetScaler ADC and Gateway deployments and can allow unauthenticated arbitrary command execution. CVE-2026-88772 can lead to remote code execution or denial of service on DTLS-enabled systems.

Organizations operating affected NetScaler appliances should upgrade immediately and investigate systems that were exposed before the fixes were applied.

Official Sources

Uday Patil
About The Author

Uday Patil

Uday Patil is a Cybersecurity Researcher, DevSecOps Engineer, and the Founder of CyberUpdates365. Specializing in Threat Intelligence and Zero-Day vulnerability analysis, Uday is dedicated to breaking down complex cyber threats into actionable insights. His mission is to empower developers, security teams, and aspiring tech talent with rapid alerts, practical guidance, and career mentorship.