Citrix NetScaler Zero-Days Exploited Globally; Patches Available

· Original article ↗

Summary

Citrix patched two critical NetScaler vulnerabilities that CISA says are being actively exploited globally. Affected organizations should upgrade; one flaw affects all deployments, while the other requires DTLS to be enabled.

Key points

  • CVE-2026-88771 and CVE-2026-88772 each have a CVSS score of 9.5 and are listed in CISA’s Known Exploited Vulnerabilities catalog.
  • CVE-2026-88771 affects all NetScaler ADC and Gateway deployments and could let an unauthenticated attacker execute commands.
  • CVE-2026-88772 can enable remote code execution or denial of service; it requires DTLS, enabled by default on VPN virtual servers.
  • Supported affected versions include ADC and Gateway 14.1 before 14.1-73.37 and 13.1 before 13.1-64.23, plus specified FIPS and NDcPP versions.
  • Citrix patches are available, and the vendor recommends upgrading affected systems as soon as possible.
  • The article describes exploitation involving malformed HTTP streams and TLS traffic; reports that attacks began as early as Sept. 24 are unconfirmed.

Article Details

Vulnerability Types
  • Improper input validation allowing unauthenticated arbitrary command execution
  • Memory buffer bounds violation and buffer overflow allowing remote code execution or denial of service
Severity
Critical; CVSS 9.5 for each vulnerability.
Affected Versions
  • NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
  • NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
  • NetScaler ADC FIPS before 14.1-73.37 FIPS
  • NetScaler ADC FIPS and NDcPP before 13.1-37.279
Exploitation Status
active
Exploit Availability
unknown
Patch Status
available
Workarounds
  • Use access controls to isolate NetScaler systems.
  • Revoke unused user accounts and reset authentication for active accounts.

MITRE ATT&CK

CVE

People

Vendors

Products

Related Articles