Citrix Confirms Two NetScaler RCE Zero-Days Are Being Exploited

· Original article ↗

Summary

Citrix confirmed active exploitation of two critical NetScaler RCE flaws and released updates for affected ADC and Gateway appliances. Administrators should upgrade promptly or reduce internet exposure until they can patch.

Key points

  • Citrix confirmed attackers have exploited CVE-2026-88771 and CVE-2026-88772 as zero-days against unpatched NetScaler devices.
  • CVE-2026-88771 allows unauthenticated command execution due to improper input validation and affects all ADC and Gateway deployments, including default configurations.
  • CVE-2026-88772 is a memory overflow that can enable remote code execution or denial of service when DTLS is enabled; DTLS is enabled by default on VPN virtual servers.
  • Both flaws have a severity score of 9.5. Citrix also fixed six other NetScaler vulnerabilities in the update.
  • Affected versions include ADC and Gateway 14.1 before 14.1-73.37 and 13.1 before 13.1-64.23, as well as specified FIPS and NDcPP builds. Secure Private Access Hybrid deployments using NetScaler instances are also affected.
  • Citrix-managed cloud services are being upgraded by Cloud Software Group; customers should update customer-managed appliances to the recommended builds.
  • Administrators who cannot patch immediately should reduce internet exposure where operationally possible.

Article Details

Event Type
Active exploitation of two NetScaler zero-day vulnerabilities; security updates released
Impact
Citrix confirmed exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments. The flaws can allow remote code execution, and CVE-2026-88772 can also cause denial of service. The extent of compromise was not established.

MITRE ATT&CK

CVE

Vendors

Products

Countries

Related Articles