Decoding the world of cybersecurity

Citrix patches exploited NetScaler flaws

Citrix says attackers have exploited two critical NetScaler vulnerabilities, including an unauthenticated remote-code-execution flaw affecting all ADC and Gateway deployments covered by the bulletin.

Citrix patches exploited NetScaler flaws
Summary
  • Citrix has observed exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments.
  • CVE-2026-88771 can allow unauthenticated arbitrary command execution and affects all NetScaler ADC and Gateway deployments covered by the advisory.
  • Citrix has released fixed builds and is strongly urging affected customers to install the relevant updates.

Citrix has released fixes for two critical NetScaler vulnerabilities already exploited against unmitigated deployments, including an unauthenticated remote-code-execution flaw affecting all deployments covered by the advisory.

NetScaler ADC and Gateway are affected by CVE-2026-88771 and CVE-2026-88772, both assigned CVSS v4 base scores of 9.5.

Citrix said exploitation of both vulnerabilities has been observed and strongly urged organisations operating affected self-managed systems to install the relevant updated versions as soon as possible.

CVE-2026-88771 is an improper-input-validation flaw that can allow an unauthenticated attacker to execute arbitrary commands. Citrix’s security bulletin says all NetScaler ADC and NetScaler Gateway deployments are affected, including default configurations, with no additional feature required.

CVE-2026-88772 is a memory-overflow vulnerability that can lead to remote code execution or denial of service where DTLS is enabled. Citrix notes that DTLS is enabled by default on VPN virtual servers unless it has been explicitly disabled.

The two exploited vulnerabilities form part of a wider group of eight issues disclosed in the bulletin. The remaining flaws include HTTP request smuggling, policy bypass, memory-overflow conditions, and predictable TCP initial sequence numbers under particular configuration conditions.

Citrix has released NetScaler ADC and Gateway 14.1-73.37 and 13.1-64.23, alongside corrected FIPS and NDcPP builds specified in the advisory.

The exposure is particularly important because NetScaler appliances often sit at the edge of enterprise environments, handling application delivery, remote access, authentication, and VPN traffic. A remotely exploitable vulnerability in that position can provide an entry route without requiring compromise of an ordinary user endpoint first.

The latest advisory follows separate NetScaler exploitation activity covered by Cyber Insider earlier in September. The vulnerabilities are different, but repeated edge-device patching cycles increase the operational burden on organisations running infrastructure that is both internet-facing and privileged.

Where exploitation is already known to have occurred, installing a corrected build addresses the disclosed software weakness but does not establish that a particular appliance was uncompromised before remediation.

Organisations therefore have two separate questions: whether the device is now running a corrected version and whether forensic evidence indicates exploitation while the vulnerable build remained exposed.

Citrix has not identified the threat actors exploiting CVE-2026-88771 or CVE-2026-88772, described individual victim organisations, or quantified the scale of the activity. Attribution and overall prevalence consequently remain unknown.

The broad precondition for CVE-2026-88771 reduces the scope for organisations to dismiss the issue on configuration grounds. Citrix says all relevant ADC and Gateway deployments are vulnerable prior to installation of a corrected build, including those using default configurations.

CVE-2026-88772 is more dependent on configuration because DTLS must be enabled, although that condition is met by default on NetScaler Gateway VPN virtual servers unless administrators have explicitly turned it off.

Citrix is urging customers to install the updated releases. The continuing exploitation means incident review is likely to be as important as patch deployment for organisations whose appliances were exposed before remediation.

×