www.ncsc.nl Critical Vulnerabilities in Citrix NetScaler ADC and Gateway Disclosed
Article Content
- •Eight vulnerabilities in Citrix NetScaler ADC and Gateway have been patched.
- •CVE-2026-88771 and CVE-2026-88772 are actively exploited, allowing RCE.
- •Immediate patching is recommended to protect against potential attacks.
Citrix has addressed eight vulnerabilities in its NetScaler ADC and Gateway products, with three critical CVEs identified: CVE-2026-88771, CVE-2026-88772, and CVE-2026-88773. These vulnerabilities can lead to Remote Code Execution (RCE), Denial-of-Service, and HTTP Request Smuggling. CVE-2026-88771 and CVE-2026-88772 have been confirmed to be actively exploited in the wild. All versions prior to specified updates are affected, including Citrix NetScaler ADC and Gateway 14.1 before 14.1-73.37 and 13.1 before 13.1-64.23. Citrix has released patches, and the NCSC advises immediate installation to mitigate risks. The vulnerabilities pose significant risks to organizations using these systems, as they could allow attackers to gain control over internal networks. The CVSS scores for the critical vulnerabilities are notably high, indicating severe risk to affected systems.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-88771 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Citrix NetScaler Zero-Days Exploited: Urgent Patching Required Citrix has confirmed active exploitation of two critical zero-day vulnerabilities in its NetScaler ADC and Gateway products, identified as CVE-2026-88771 and CVE-2026-88772, both rated 9.5 on the CVSS scale. These vulnerabilities allow unauthenticated attackers to execute arbitrary commands and potentially cause…
Critical Zero-Day Vulnerabilities in Citrix NetScaler Under Active Exploitation On September 26, 2026, security firm watchTowr reported two unpatched zero-day vulnerabilities in Citrix NetScaler ADC and Gateway appliances, allowing remote code execution (RCE) and actively exploited in the wild. Citrix has confirmed the existence of these vulnerabilities, tracked as CVE-2026-88771 and…