Skip to content
Citrix NetScaler Hit by Two Critical RCE Flaws Already Under Attack

Citrix NetScaler Hit by Two Critical RCE Flaws Already Under Attack

Thecyberexpress •Ashish Khaitan • September 28, 2026

Citrix has released fixes for two critical remote code execution flaws in NetScaler ADC and NetScaler Gateway, tracked as CVE-2026-88771 and CVE-2026-88772. On September 27, the company confirmed that attackers had already exploited both in the wild. The same update addresses six other vulnerabilities. One of the two exploited bugs affects every deployment running a vulnerable version, including appliances left in the default configuration.

The disclosure came a day after firm watchTowr reported that two unpatched NetScaler RCE flaws were being exploited, and after some administrators said they had taken appliances offline. Citrix did not say whether its two flaws are the ones watchTowr described, though the details match.

NetScaler ADC and NetScaler Gateway sit at the edge of enterprise networks, handling VPN and , load balancing, and user authentication.

How CVE-2026-88771 and CVE-2026-88772 Work

CVE-2026-88771, rated 9.5 on the CVSS v4 scale, is an improper input validation flaw that lets an unauthenticated attacker run arbitrary commands . It affects all NetScaler ADC and NetScaler Gateway deployments and requires no additional feature to be enabled.

CVE-2026-88772, also rated 9.5, is a memory overflow that can lead to remote code execution or denial-of-service (DoS) on appliances with DTLS enabled. DTLS is on by default for virtual servers, so any NetScaler Gateway is exposed unless DTLS has been explicitly turned off.

“Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed,” Citrix said. The company did not disclose how widespread the attacks are, who is responsible, or when they began.

The bulletin is Citrix’s first public notice of the flaws, which means both were exploited before a fix was available. It lists no workarounds and no indicators of compromise.

Fixed NetScaler Versions

Appliances running 14.1-73.32 and 13.1-63.21 fall within the affected range and need the new update. Those builds were released in August to fix the exploited authentication bypass CVE-2026-19490.

Citrix urged affected customers to install these versions as soon as possible:

NetScaler ADC and NetScaler Gateway 14.1-73.37 and later releases

NetScaler ADC and NetScaler Gateway 13.1-64.23 and later releases of 13.1

NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS

NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later releases of 13.1-FIPS and 13.1-NDcPP

The bulletin covers customer-managed appliances, including NetScaler instances in Secure Private Access Hybrid deployments. Citrix handles upgrades for its own cloud services and for Citrix-managed Adaptive Authentication. The 13.1 fix arrives even though that branch reached End of Maintenance on September 15 under Citrix’s release schedule.

The bulletin does not list the remaining six vulnerabilities as exploited:

CVE-2026-88773 (9.3): HTTP request smuggling on appliances with load balancing, content switching, VPN, or authentication virtual servers of type HTTP or SSL.

CVE-2026-88774 (7.0): A policy bypass on appliances where any policy uses an HTTP URL-based expression.

CVE-2026-88775 (8.8): A memory overflow that can cause unpredictable behavior or DoS on appliances configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or as an authentication, authorization, and auditing (AAA) virtual server.

CVE-2026-88776 (8.8): A memory overflow that can cause unpredictable behavior or DoS on load balancing virtual servers of type Oracle.

CVE-2026-88777 (8.8): A memory overflow that can cause unpredictable behavior or DoS on load balancing, content switching, or CGNAT-LSN/NAT64 setups with a non-HTTP Layer 7 protocol feature, such as FTP, RTSP, or DNS64, enabled.

CVE-2026-88778 (8.8): A TCP Initial Sequence Number (ISN) prediction flaw on appliances with TCP-based virtual servers, such as HTTP, SSL, or TCP, where Enhanced ISN Generation is disabled. Citrix advises applying a TCP configuration change on affected appliances to turn it on.