Two Critical Citrix NetScaler Vulnerabilities Exploited in the Wild

· Original article ↗

Summary

Citrix reported active exploitation of two critical NetScaler vulnerabilities that can enable remote code execution or denial of service. CISA added both to its KEV Catalog; organizations should identify affected systems and apply updates or mitigations.

Key points

  • Citrix disclosed eight vulnerabilities affecting NetScaler ADC and NetScaler Gateway on September 27, 2026.
  • The two critical flaws, CVE-2026-88771 and CVE-2026-88772, have CVSS scores of 9.5 and are being exploited against unmitigated deployments.
  • CVE-2026-88771 involves improper input validation and can allow unauthenticated command execution; CVE-2026-88772 is a memory overflow that can cause remote code execution or denial of service.
  • CISA added both actively exploited vulnerabilities to its Known Exploited Vulnerabilities Catalog.
  • The other six flaws can lead to HTTP request smuggling, policy bypass, denial of service, or TCP sequence number prediction.
  • Organizations should identify affected appliances, prioritize internet-facing systems, and apply Citrix updates or mitigations.
  • Updating a previously compromised appliance may not remove attacker access; suspected compromises require assessment, recovery, and validation.

Article Details

Vulnerability Types
  • Improper input validation
  • Memory overflow
  • HTTP request smuggling
  • Policy bypass
  • TCP sequence number prediction
Severity
CVE-2026-88771 and CVE-2026-88772 are critical, each with a CVSS score of 9.5. The other six vulnerabilities have CVSS scores ranging from 7.0 to 9.3.
Exploitation Status
active
Exploit Availability
unknown
Patch Status
available

CVE

Vendors

Products

Related Articles