Active Exploitation of Citrix NetScaler ADC and Gateway Zero-Day Vulnerabilities (CVE-2026-88771, CVE-2026-88772) – Urgent Patch Required

Active Exploitation of Citrix NetScaler ADC and Gateway Zero-Day Vulnerabilities (CVE-2026-88771, CVE-2026-88772) – Urgent Patch Required

Executive Summary

Multiple critical vulnerabilities have been disclosed in Citrix NetScaler ADC and NetScaler Gateway, most notably CVE-2026-88771 and CVE-2026-88772, which are confirmed to be exploited in the wild. These vulnerabilities enable unauthenticated remote code execution (RCE), denial of service (DoS), and other high-impact attacks on affected appliances. The vulnerabilities are trivial to exploit in default configurations, and immediate action is required for all organizations running impacted versions. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-88771 to its Known Exploited Vulnerabilities (KEV) catalog as of 2026-09-27, mandating urgent remediation.

Technical Information

The vulnerabilities span a range of critical and high-severity issues in NetScaler ADC and NetScaler Gateway. The most severe, CVE-2026-88771, is a remote code execution flaw caused by improper input validation (CWE-20). This allows an unauthenticated attacker to execute arbitrary commands on the appliance over the network, with no user interaction or special configuration required. The attack complexity is low, and exploitation can result in full compromise of the device and potential lateral movement into internal networks.

CVE-2026-88772 is a memory overflow vulnerability (CWE-119) affecting appliances with Datagram Transport Layer Security (DTLS) enabled, which is the default on VPN vServers. Successful exploitation can result in RCE or DoS, and has also been observed in the wild.

Additional vulnerabilities (CVE-2026-88773 through CVE-2026-88778) include HTTP request smuggling, policy bypass, further memory overflows, and TCP Initial Sequence Number (ISN) prediction. These issues can enable attackers to bypass security controls, poison caches, or hijack sessions, depending on the configuration.

The vulnerabilities are present in all default deployments of the affected products, and exploitation does not require authentication or user interaction. Attackers are leveraging these flaws to gain initial access, execute arbitrary code, and establish persistence on compromised appliances.

Exploitation in the Wild

Exploitation of CVE-2026-88771 and CVE-2026-88772 has been confirmed by multiple independent sources, including the official Citrix advisory, CERT-EU, and reputable cybersecurity news outlets. Public reports indicate that attackers are scanning for and exploiting exposed NetScaler appliances globally. The vulnerabilities are being leveraged for initial access, with observed post-exploitation activity including the deployment of webshells, credential theft, and lateral movement.

CISA has officially confirmed active exploitation of CVE-2026-88771 by adding it to the KEV catalog on 2026-09-27. Organizations are required to apply mitigations in accordance with vendor instructions and CISA BOD 26-04 guidance, with a remediation due date of 2026-09-30.

APT Groups using this vulnerability

As of the time of writing, there is no public attribution of these vulnerabilities to specific Advanced Persistent Threat (APT) groups. However, similar vulnerabilities in Citrix NetScaler have historically been exploited by both ransomware operators and state-sponsored espionage actors. The tactics, techniques, and procedures (TTPs) observed align with MITRE ATT&CK techniques T1190 (Exploit Public-Facing Application) for initial access and T1059 (Command and Scripting Interpreter) for post-exploitation command execution. Given the criticality and ubiquity of the affected products, it is highly likely that both financially motivated and nation-state actors will continue to target these vulnerabilities.

Affected Product Versions

The following versions of NetScaler ADC and NetScaler Gateway are affected:

NetScaler ADC and Gateway 14.1 before 14.1-73.37, NetScaler ADC and Gateway 13.1 before 13.1-64.23, NetScaler ADC FIPS before 14.1-73.37 FIPS, and NetScaler ADC FIPS and NDcPP before 13.1-37.279. Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds. The vulnerabilities apply only to customer-managed appliances; Citrix-managed cloud services are being remediated by the vendor.

Workaround and Mitigation

Immediate upgrade is the only effective mitigation. Organizations must upgrade to NetScaler ADC and Gateway 14.1-73.37 or later, 13.1-64.23 or later, 14.1-73.37 FIPS or later, or 13.1-37.279 for FIPS/NDcPP. For CVE-2026-88778, TCP configuration changes must be applied as per the official Citrix documentation. Administrators should also review the official Citrix blog for published Indicators of Compromise (IOCs) and detection guidance. If immediate upgrade is not possible, appliances should be isolated from the internet and closely monitored for signs of compromise.

Indicators of Compromise

The following caveat applies: Indicators of Compromise (IOCs) are point-in-time and should be validated before enforcement. No public indicators of compromise were available at the time of writing.

References

Citrix Security Bulletin CTX697096, Citrix Official Blog, CERT-EU Advisory, Reddit Community Alert, WatchTowr FAQ, TheHackerNews, LinkedIn cybersecurity executive post, BleepingComputer

Rescana is here for you

Rescana empowers organizations to manage third-party risk and supply chain security with our advanced TPRM platform, providing continuous monitoring, automated risk assessments, and actionable intelligence. For any questions or further assistance, we are happy to help at info@rescana.com.

Contact us / Book a demo

Talk to Rescana about this advisory, or book a demo of the platform.