Two Critical NetScaler Flaws Exploited in the Wild Allow Remote Code Execution

Two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway are being actively exploited in the wild and can allow remote code execution on affected appliances.

Citrix confirmed the exploitation on September 27, 2026, and released security updates addressing both vulnerabilities along with six additional security flaws.

The affected products sit at the edge of enterprise networks and are commonly used for VPN access, remote connectivity, load balancing, and authentication.

Two Exploited Vulnerabilities

CVE-2026-88771

CVSS v4: 9.5

CVE-2026-88771 is an improper input validation vulnerability that allows an unauthenticated remote attacker to execute arbitrary commands.

The vulnerability affects all NetScaler ADC and NetScaler Gateway deployments running affected versions and does not require any additional feature to be enabled.

CVE-2026-88772

CVSS v4: 9.5

CVE-2026-88772 is a memory overflow vulnerability that can result in remote code execution or denial-of-service.

It affects appliances with DTLS enabled. DTLS is enabled by default for VPN virtual servers, meaning NetScaler Gateway deployments remain exposed unless DTLS has been explicitly disabled.

Citrix confirmed that exploitation of both vulnerabilities has been observed against unpatched NetScaler deployments.

The company has not disclosed how widely the vulnerabilities have been exploited, when exploitation began, or who is behind the attacks.

Security Updates

Citrix recommends that affected customers install the following fixed versions:

  • NetScaler ADC and NetScaler Gateway 14.1-73.37 and later
  • NetScaler ADC and NetScaler Gateway 13.1-64.23 and later
  • NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later

The updates also apply to customer-managed appliances, including NetScaler instances used with Secure Private Access Hybrid deployments.

Citrix-managed cloud services are updated by Citrix.

Six Additional Vulnerabilities

Citrix also disclosed six other vulnerabilities in the same security bulletin.

  • CVE-2026-88773, CVSS 9.3: HTTP request smuggling vulnerability affecting certain load balancing, content switching, VPN, and authentication configurations.
  • CVE-2026-88774, CVSS 7.0: Policy bypass vulnerability involving HTTP URL-based expressions.
  • CVE-2026-88775, CVSS 8.8: Memory overflow affecting Gateway and AAA virtual server configurations.
  • CVE-2026-88776, CVSS 8.8: Memory overflow affecting Oracle load balancing virtual servers.
  • CVE-2026-88777, CVSS 8.8: Memory overflow affecting certain non-HTTP Layer 7 protocol configurations.
  • CVE-2026-88778, CVSS 8.8: TCP Initial Sequence Number prediction vulnerability affecting certain TCP-based virtual servers when Enhanced ISN Generation is disabled.

For CVE-2026-88778, Citrix recommends enabling Enhanced ISN Generation through the TCP configuration.

Previous NetScaler Updates Do Not Protect Against These Flaws

NetScaler appliances running versions that fixed the previously disclosed CVE-2026-19490 vulnerability in August can still be affected by the newly disclosed flaws.

Organizations should therefore verify their exact NetScaler version and apply the latest security updates rather than assuming that an earlier security update is sufficient.

Exploitation Happened Before Public Disclosure

The vulnerabilities were exploited before Citrix publicly disclosed them and before fixes became available.

This means installing the security update alone cannot determine whether an appliance was compromised before patching.

Organizations should investigate affected appliances for signs of unauthorized access or persistence, particularly if the management interface or vulnerable services were exposed to untrusted networks.

What to Do If Compromise Is Suspected

Citrix recommends preserving evidence before making major changes to a potentially compromised appliance.

Administrators should:

  1. Preserve available forensic evidence, including VPX snapshots, remote syslog data, NetScaler Console logs, technical support bundles, and packet-engine core dumps.
  2. Isolate the affected appliance from the network.
  3. Change service account passwords and secrets stored on the appliance.
  4. Reset passwords for users who authenticated through the affected appliance.
  5. Revoke certificates and private keys associated with the appliance.
  6. Keep the NetScaler management interface inaccessible from the public Internet.

Organizations can also use available forensic checking tools to look for signs of compromise, although such checks do not guarantee that every compromise will be detected.

Key Takeaway

The exploitation of CVE-2026-88771 and CVE-2026-88772 makes immediate NetScaler patching important for organizations running affected versions.

Because both vulnerabilities were exploited before fixes became public, administrators should not treat patch installation as proof that an appliance was never compromised. Affected organizations should patch, investigate for signs of prior intrusion, and rotate credentials and cryptographic material if compromise is suspected.