Executive Summary
Multiple critical vulnerabilities have been disclosed in Citrix NetScaler ADC and NetScaler Gateway, most notably CVE-2026-88771 and CVE-2026-88772, which are confirmed to be exploited in the wild. These vulnerabilities enable unauthenticated remote code execution (RCE), denial of service (DoS), and other high-impact attacks on affected appliances. The vulnerabilities are trivial to exploit in default configurations, and immediate action is required for all organizations running impacted versions. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-88771 to its Known Exploited Vulnerabilities (KEV) catalog as of 2026-09-27, mandating urgent remediation.
Technical Information
The vulnerabilities span a range of critical and high-severity issues in NetScaler ADC and NetScaler Gateway. The most severe, CVE-2026-88771, is a remote code execution flaw caused by improper input validation (CWE-20). This allows an unauthenticated attacker to execute arbitrary commands on the appliance over the network, with no user interaction or special configuration required. The attack complexity is low, and exploitation can result in full compromise of the device and potential lateral movement into internal networks.
CVE-2026-88772 is a memory overflow vulnerability (CWE-119) affecting appliances with Datagram Transport Layer Security (DTLS) enabled, which is the default on VPN vServers. Successful exploitation can result in RCE or DoS, and has also been observed in the wild.
Additional vulnerabilities (CVE-2026-88773 through CVE-2026-88778) include HTTP request smuggling, policy bypass, further memory overflows, and TCP Initial Sequence Number (ISN) prediction. These issues can enable attackers to bypass security controls, poison caches, or hijack sessions, depending on the configuration.
The vulnerabilities are present in all default deployments of the affected products, and exploitation does not require authentication or user interaction. Attackers are leveraging these flaws to gain initial access, execute arbitrary code, and establish persistence on compromised appliances.
Exploitation in the Wild
Exploitation of CVE-2026-88771 and CVE-2026-88772 has been confirmed by multiple independent sources, including the official Citrix advisory, CERT-EU, and reputable cybersecurity news outlets. Public reports indicate that attackers are scanning for and exploiting exposed NetScaler appliances globally. The vulnerabilities are being leveraged for initial access, with observed post-exploitation activity including the deployment of webshells, credential theft, and lateral movement.
CISA has officially confirmed active exploitation of CVE-2026-88771 by adding it to the KEV catalog on 2026-09-27. Organizations are required to apply mitigations in accordance with vendor instructions and CISA BOD 26-04 guidance, with a remediation due date of 2026-09-30.
APT Groups using this vulnerability
As of the time of writing, there is no public attribution of these vulnerabilities to specific Advanced Persistent Threat (APT) groups. However, similar vulnerabilities in Citrix NetScaler have historically been exploited by both ransomware operators and state-sponsored espionage actors. The tactics, techniques, and procedures (TTPs) observed align with MITRE ATT&CK techniques T1190 (Exploit Public-Facing Application) for initial access and T1059 (Command and Scripting Interpreter) for post-exploitation command execution. Given the criticality and ubiquity of the affected products, it is highly likely that both financially motivated and nation-state actors will continue to target these vulnerabilities.
Affected Product Versions
The following versions of NetScaler ADC and NetScaler Gateway are affected:
NetScaler ADC and Gateway 14.1 before 14.1-73.37, NetScaler ADC and Gateway 13.1 before 13.1-64.23, NetScaler ADC FIPS before 14.1-73.37 FIPS, and NetScaler ADC FIPS and NDcPP before 13.1-37.279. Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds. The vulnerabilities apply only to customer-managed appliances; Citrix-managed cloud services are being remediated by the vendor.
Workaround and Mitigation
Immediate upgrade is the only effective mitigation. Organizations must upgrade to NetScaler ADC and Gateway 14.1-73.37 or later, 13.1-64.23 or later, 14.1-73.37 FIPS or later, or 13.1-37.279 for FIPS/NDcPP. For CVE-2026-88778, TCP configuration changes must be applied as per the official Citrix documentation. Administrators should also review the official Citrix blog for published Indicators of Compromise (IOCs) and detection guidance. If immediate upgrade is not possible, appliances should be isolated from the internet and closely monitored for signs of compromise.
Indicators of Compromise
The following caveat applies: Indicators of Compromise (IOCs) are point-in-time and should be validated before enforcement. No public indicators of compromise were available at the time of writing.
References
Citrix Security Bulletin CTX697096, Citrix Official Blog, CERT-EU Advisory, Reddit Community Alert, WatchTowr FAQ, TheHackerNews, LinkedIn cybersecurity executive post, BleepingComputer
Rescana is here for you
Rescana empowers organizations to manage third-party risk and supply chain security with our advanced TPRM platform, providing continuous monitoring, automated risk assessments, and actionable intelligence. For any questions or further assistance, we are happy to help at info@rescana.com.



