Skip to content
CVE-2026-88771, CVE-2026-88772: NetScaler Active Exploitation

CVE-2026-88771, CVE-2026-88772: NetScaler Active Exploitation

Bitsight • September 28, 2026

Citrix disclosed two critical vulnerabilities in NetScaler ADC and NetScaler Gateway that are already being exploited in the wild. CVE-2026-88771 allows unauthenticated attackers to run commands on an affected appliance, while CVE-2026-88772 can lead to remote code execution or denial of service when DTLS is turned on. Both received a CVSS v4.0 score of 9.5, and CISA added them to its Known Exploited Vulnerabilities catalog . Because NetScaler appliances sit at the front door of many networks, handling remote access and critical app traffic, simply patching isn't enough, you need to verify whether attackers accessed internal systems before the patch was applied.

According to Bitsight Threat Intelligence

Bitsight Threat Intelligence assigned both flaws a Dynamic Vulnerability Exploit (DVE) score of 10.0 out of 10. DVE is Bitsight's proprietary score that helps security teams prioritize flaws based on how likely they are to be exploited over the 90 days. In this case, active exploitation is already confirmed by Citrix .

Citrix released updates for NetScaler ADC and Gateway 14.1-73.37 and 13.1-64.23, alongside fixed FIPS and NDcPP builds. Check the official security bulletin for the full list of affected versions and corresponding updates.

Disabling DTLS mitigates CVE-2026-88772, but it does nothing to protect against CVE-2026-88771, which affects default configurations out of the box. Teams must address both flaws. Because attackers actively targeted these vulnerabilities before patches were available, updating software is only half the battle. CISA warns that updating can wipe forensic evidence. If you suspect an intrusion, preserve logs and device state before making changes, then patch as quickly as possible.

CVE-2026-88771 and CVE-2026-88772 impact to organizations

Successful exploitation could give attackers control over the appliance or disrupt service. From there, attackers can use a compromised NetScaler handling remote access or core apps to pivot to connected networks, harvest credentials, or breach internal databases. While these risks are severe, the exact scope of public attacks remains unconfirmed.

Risk also extends to third-party vendors. If a key vendor runs an affected NetScaler managing your access or applications, you should confirm that they patched their systems and checked for prior signs of compromise.

Locate and update affected appliances. Cross-reference customer-managed NetScaler ADC and Gateway instances (including hybrid deployments) against Citrix's advisory. Since Citrix disclosed eight total vulnerabilities in this release, review the full bulletin when planning updates.

Locate and update affected appliances. Cross-reference customer-managed NetScaler ADC and Gateway instances (including hybrid deployments) against Citrix's advisory. Since Citrix disclosed eight total vulnerabilities in this release, review the full bulletin when planning updates.

Preserve forensic evidence before rebooting. Save appliance logs and check external sources (firewall, DNS, authentication logs) before rebooting or rebuilding. Balance forensic preservation carefully so it does not unduly delay urgent patching.

Preserve forensic evidence before rebooting. Save appliance logs and check external sources (firewall, DNS, authentication logs) before rebooting or rebuilding. Balance forensic preservation carefully so it does not unduly delay urgent patching.

Investigate beyond automated checks. Citrix provides generic indicator-of-compromise checks in NetScaler Console (or via Support), but warns these checks may miss sophisticated intrusions. Bring in experienced incident responders if you notice suspicious activity.

Investigate beyond automated checks. Citrix provides generic indicator-of-compromise checks in NetScaler Console (or via Support), but warns these checks may miss sophisticated intrusions. Bring in experienced incident responders if you notice suspicious activity.

Engage critical vendors. Ask third-party vendors operating NetScaler appliances which software builds they use, when they patched, and whether they investigated historical activity. If compromise occurred, ask how they assessed potential impacts on your connection.

Engage critical vendors. Ask third-party vendors operating NetScaler appliances which software builds they use, when they patched, and whether they investigated historical activity. If compromise occurred, ask how they assessed potential impacts on your connection.

Threat landscape & context

Citrix confirmed active exploitation of these two vulnerabilities on unmitigated devices, and CISA reported worldwide targeting. Public data is still too limited to confirm which industries or how many organizations have been impacted overall.

How Bitsight TI and TPRM support you

Threat monitoring: Bitsight Threat Intelligence helps teams follow exploitation activity and attacker interest as the situation develops.

Vulnerability prioritization: DVE adds a view of exploitation likelihood alongside severity, helping teams decide what needs attention first.

First- and third-party exposure: Bitsight can help organizations identify relevant external exposure and prioritize outreach to vendors that may operate affected technology.

Supply chain monitoring: Bitsight Beacon provides validated alerts and supporting evidence to help security teams assess emerging threats across critical vendors.

These vulnerabilities require immediate remediation. Active exploitation is happening, and default NetScaler setups are vulnerable to CVE-2026-88771. Identify exposed appliances, apply the official updates, and verify that attackers haven't already gained a foothold. Finally, reach out to critical vendors running NetScaler on your behalf to ensure they've done the same.

Bitsight Recognized as a Visionary in 2026 Gartner® Magic Quadrant™ for Cyber Threat Intelligence Technologies

Get the report and see why Bitsight was named a Visionary.

Extracted Entities