Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway
Two critical Citrix NetScaler zero-days, CVE-2026-88771 and CVE-2026-88772, are exploited for remote code execution.
CISA amplified Citrix’s disclosure of eight vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway, CVE-2026-88771 through CVE-2026-88778. CVE-2026-88771 and CVE-2026-88772 were added to the Known Exploited Vulnerabilities Catalog; both are critical zero-days that can independently enable remote code execution. CISA and partner intelligence confirm threat actors are actively exploiting these vulnerabilities globally. CISA urges administrators to review Citrix’s bulletin, check for compromise before patching, and preserve forensic evidence because updates may remove visibility. Citrix published indicators of compromise through NetScaler Console.
- Citrix disclosed eight NetScaler ADC and Gateway flaws, CVE-2026-88771 through CVE-2026-88778.
- CVE-2026-88771 and CVE-2026-88772 are critical zero-days that independently enable remote code execution.
- CISA added both to KEV after reports of active global exploitation.
- Administrators should hunt for compromise and preserve forensics before patching.
Vulnerabilities mentionedAll →
- CVE-2026-887729.51%Unauthenticated RCE/DoS in Citrix NetScaler ADC and Gatewaypublished · Citrix NetScaler ADC KEV PoC ×2+1 related
Full article326 words · extracted from cisa.gov · click to collapse
CISA is amplifying Citrix’s disclosure of eight new vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway products: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778.
CISA has added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) Catalog. Both are critical, zero-day vulnerabilities that can independently enable remote code execution. CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally.
Because updating Citrix NetScaler appliances can be complex and may require downtime, CISA is issuing this Alert to help organizations assess exposure, prioritize mitigation, and account for these vulnerabilities into their risk-management activities.
Given the potential consequences of successful exploitation and the fact that malicious actors are exploiting at least some of these vulnerabilities, CISA urges users and administrators to review Citrix’s advisories. If possible, users are encouraged to check for indication of compromise prior to patching. Citrix has made indicators of compromise available through NetScaler Console and published additional guidance in their recent publication, Security Bulletin for CVE-2026-88771 through CVE-2026-88778, to support organizations in assessing potential compromise. Should your organization suspect compromise, it is important to preserve forensic evidence prior to applying updates, as updates may result in loss of forensic visibility.
- Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778 - Security Updates - Citrix Community
- Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778
- Steps to Take if NetScaler ADC is Suspected to be Compromised
Disclaimer
The information in this report is being provided “as is” for informational purposes only. CISA does not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this document. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by CISA.