Citrix Confirms Two NetScaler RCE Zero-Days Are Being Exploited

Summary
Citrix confirmed active exploitation of two critical NetScaler RCE flaws and released updates for affected ADC and Gateway appliances. Administrators should upgrade promptly or reduce internet exposure until they can patch.
Key points
- Citrix confirmed attackers have exploited CVE-2026-88771 and CVE-2026-88772 as zero-days against unpatched NetScaler devices.
- CVE-2026-88771 allows unauthenticated command execution due to improper input validation and affects all ADC and Gateway deployments, including default configurations.
- CVE-2026-88772 is a memory overflow that can enable remote code execution or denial of service when DTLS is enabled; DTLS is enabled by default on VPN virtual servers.
- Both flaws have a severity score of 9.5. Citrix also fixed six other NetScaler vulnerabilities in the update.
- Affected versions include ADC and Gateway 14.1 before 14.1-73.37 and 13.1 before 13.1-64.23, as well as specified FIPS and NDcPP builds. Secure Private Access Hybrid deployments using NetScaler instances are also affected.
- Citrix-managed cloud services are being upgraded by Cloud Software Group; customers should update customer-managed appliances to the recommended builds.
- Administrators who cannot patch immediately should reduce internet exposure where operationally possible.
Article Details
- Event Type
- Active exploitation of two NetScaler zero-day vulnerabilities; security updates released
- Impact
- Citrix confirmed exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments. The flaws can allow remote code execution, and CVE-2026-88772 can also cause denial of service. The extent of compromise was not established.
MITRE ATT&CK
CVE
CVE-2026-88771Citrix has confirmed that two critical NetScaler remote code execution vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks and that it has released security updates to fix theCVE-2026-88772that two critical NetScaler remote code execution vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks and that it has released security updates to fix the flaws.
Vendors
Products
Adaptive AuthenticationCloud Software Group is upgrading Citrix-managed cloud services and Citrix-managed Adaptive Authentication.NetScaler ADCCitrix has now published security bulletin CTX697096, confirming the vulnerabilities and releasing patches for affected NetScaler ADC and NetScaler Gateway appliances.NetScaler GatewayCitrix has now published security bulletin CTX697096, confirming the vulnerabilities and releasing patches for affected NetScaler ADC and NetScaler Gateway appliances.Secure Private Access HybridSecure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds.