Two Critical Citrix NetScaler Vulnerabilities Exploited in the Wild

Summary
Citrix reported active exploitation of two critical NetScaler vulnerabilities that can enable remote code execution or denial of service. CISA added both to its KEV Catalog; organizations should identify affected systems and apply updates or mitigations.
Key points
- Citrix disclosed eight vulnerabilities affecting NetScaler ADC and NetScaler Gateway on September 27, 2026.
- The two critical flaws, CVE-2026-88771 and CVE-2026-88772, have CVSS scores of 9.5 and are being exploited against unmitigated deployments.
- CVE-2026-88771 involves improper input validation and can allow unauthenticated command execution; CVE-2026-88772 is a memory overflow that can cause remote code execution or denial of service.
- CISA added both actively exploited vulnerabilities to its Known Exploited Vulnerabilities Catalog.
- The other six flaws can lead to HTTP request smuggling, policy bypass, denial of service, or TCP sequence number prediction.
- Organizations should identify affected appliances, prioritize internet-facing systems, and apply Citrix updates or mitigations.
- Updating a previously compromised appliance may not remove attacker access; suspected compromises require assessment, recovery, and validation.
Article Details
- Vulnerability Types
- Improper input validation
- Memory overflow
- HTTP request smuggling
- Policy bypass
- TCP sequence number prediction
- Severity
- CVE-2026-88771 and CVE-2026-88772 are critical, each with a CVSS score of 9.5. The other six vulnerabilities have CVSS scores ranging from 7.0 to 9.3.
- Exploitation Status
- active
- Exploit Availability
- unknown
- Patch Status
- available
CVE
CVE-2026-88771CVE-2026-88771 results from improper input validation and can allow an unauthenticated attacker to execute arbitrary commands. CVE-2026-88772CVE-2026-88772 involves a memory overflow that can lead to remote code execution or denial of service. CVE-2026-88773The remaining six vulnerabilities (CVE-2026-88773 through CVE-2026-88778) have been assigned CVSS scores ranging from 7.0 to 9.3. Exploitation of these issues can result in HTTP request smuggling, policy bypass, denialCVE-2026-88774CVE-2026-88775CVE-2026-88776CVE-2026-88777CVE-2026-88778The remaining six vulnerabilities (CVE-2026-88773 through CVE-2026-88778) have been assigned CVSS scores ranging from 7.0 to 9.3. Exploitation of these issues can result in HTTP request smuggling, policy bypass, denial
Vendors
Products
NetScaler ADCCounter Threat Unit™ (CTU) researchers recommend that organizations identify affected NetScaler ADC and NetScaler Gateway instances in their environments, prioritize internet-facing systems, and apply Citrix securityNetScaler Gatewaydisclosed eight vulnerabilities affecting NetScaler Application Delivery Controller (ADC) and NetScaler Gateway. Two of these vulnerabilities are critical (CVSS score of 9.5) and can allow an unauthenticated