Citrix Confirms NetScaler Zero-Day RCE Flaws Actively Exploited in Attacks
Citrix confirms two critical NetScaler zero-days, CVE-2026-88771 and CVE-2026-88772, are actively exploited for remote code execution.
Citrix released emergency updates in bulletin CTX697096 after confirming active exploitation of CVE-2026-88771 and CVE-2026-88772, both CVSS 9.5, on customer-managed NetScaler ADC and Gateway appliances. CVE-2026-88771 allows unauthenticated remote command execution on default configurations, while CVE-2026-88772 is a memory overflow that can cause remote code execution or denial of service when DTLS is enabled, which is default on VPN virtual servers. The bulletin also fixes six more flaws, including HTTP request smuggling CVE-2026-88773, in releases 14.1-73.37, 13.1-64.23, and specified FIPS builds.
- Pre-auth RCE CVE-2026-88771 affects default ADC and Gateway configurations
- CVE-2026-88772 allows RCE or denial of service when DTLS is enabled
- Bulletin CTX697096 fixes eight CVEs, several scored 8.8 to 9.5
- Fixed builds include 14.1-73.37, 13.1-64.23, and listed FIPS releases
- Citrix-managed cloud services are being updated separately
Vulnerabilities mentionedAll →
- CVE-2026-887729.51%Unauthenticated RCE/DoS in Citrix NetScaler ADC and Gatewaypublished · Citrix NetScaler ADC KEV PoC ×2+1 related
Full article639 words · extracted from gbhackers.com · click to collapse
Citrix has released emergency security updates for NetScaler ADC and NetScaler Gateway after confirming active exploitation of two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772.
Both bugs have a CVSS v4.0 score of 9.5 and can enable remote code execution (RCE) against vulnerable customer-managed appliances.
The flaws are part of a wider set of eight vulnerabilities addressed in Citrix security bulletin CTX697096. Citrix said exploitation has been observed against unmitigated NetScaler deployments and urged organizations to immediately install the fixed releases, review appliance configurations, and investigate for compromise.
Exploited NetScaler zero-days
CVE-2026-88771 is the most broadly exposed issue. It is an improper input validation vulnerability that allows an unauthenticated remote attacker to execute arbitrary commands.
Citrix states that the flaw affects all vulnerable NetScaler ADC and Gateway deployments, including systems running the default configuration, with no additional feature or service required.
CVE-2026-88772 is a memory-overflow vulnerability that can result in RCE or denial of service. Its exposure condition is DTLS being enabled; critically, DTLS is enabled by default for VPN virtual servers, making many remote-access deployments potentially exposed unless the service was explicitly disabled.
The combination makes internet-facing NetScaler appliances an immediate target. Such devices often sit at the edge of enterprise networks, handle VPN and authentication traffic, and can offer attackers a high-value foothold for credential theft, persistence, lateral movement, or deployment of follow-on payloads.
All CVEs addressed
| CVE | Vulnerability | CVSS v4.0 | Affected precondition | CWE |
|---|---|---|---|---|
| CVE-2026-88771 | Pre-auth remote code execution through improper input validation | 9.5 | All ADC and Gateway deployments, including default configurations | CWE-20 |
| CVE-2026-88772 | Memory overflow allowing RCE or denial of service | 9.5 | DTLS enabled; enabled by default on VPN virtual servers | CWE-119 |
| CVE-2026-88773 | HTTP request smuggling | 9.3 | HTTP configured on ADC or Gateway | CWE-444 |
| CVE-2026-88774 | Feature-policy bypass through improper HTTP URL expression usage | 7.0 | HTTP configured on ADC or Gateway | CWE-16 |
| CVE-2026-88775 | Memory overflow causing erroneous behavior or denial of service | 8.8 | Gateway or AAA virtual server configured | CWE-119 |
| CVE-2026-88776 | Memory overflow causing erroneous behavior or denial of service | 8.8 | Oracle load-balancing virtual server configured | CWE-119 |
| CVE-2026-88777 | Memory overflow causing erroneous behavior or denial of service | 8.8 | LB/CS or CGNAT-LSN/NAT64 deployment using a non-HTTP Layer 7 protocol feature | CWE-119 |
| CVE-2026-88778 | TCP initial sequence number prediction | 8.8 | TCP-enabled deployment where Enhanced ISN Generation is disabled | CWE-342 |
Citrix notes that CVE-2026-88773 can affect HTTP or SSL load-balancing, content-switching, VPN, and authentication virtual servers. CVE-2026-88774 is linked to URL normalization and may allow security controls, including WAF rules, to be bypassed when URLs are not normalized correctly.
Patches and response actions
Organizations should upgrade to one of the following releases or a later version in the same supported branch:
- NetScaler ADC and Gateway 14.1-73.37 or later.
- NetScaler ADC and Gateway 13.1-64.23 or later in the 13.1 branch.
- NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS or later.
- NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 or later.
Administrators should treat the update as an incident-response priority rather than a routine maintenance task. Patch internet-facing instances first, especially appliances supporting VPN, AAA, DTLS, HTTP/SSL virtual servers, Oracle load balancing, FTP, RTSP, DNS64, NAT64, or other non-HTTP Layer 7 services.
Citrix is also providing generic indicators of compromise through NetScaler Console’s Security Advisory workflow. The capability requires the telemetry channel and is available through NetScaler Console service and supported on-premises Console deployments using Cloud Connect beginning with version 14.1-73.36.
Citrix cautions that IoC scanning alone cannot identify every compromise, since attackers can alter infrastructure and techniques.
Citrix-managed cloud services, including Gateway Service and Citrix-managed Adaptive Authentication, are being updated by Citrix; the bulletin primarily applies to customer-managed ADC and Gateway appliances.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.