Zero-Day Exploitation of Citrix NetScaler ADC and Gateway: CVE-2026-88771 and CVE-2026-88772
Attackers are exploiting critical Citrix NetScaler zero-days CVE-2026-88771 and CVE-2026-88772 for unauthenticated remote code execution.
On September 27, 2026, Citrix disclosed eight NetScaler ADC and Gateway flaws, including two critical unauthenticated RCEs scored CVSS 9.5. CVE-2026-88771 yields remote code execution in the default configuration with low attack complexity, while CVE-2026-88772 is a DTLS memory-corruption RCE with high complexity. CISA confirmed both were exploited as zero-days before disclosure and added them to the KEV catalog; CVE-2026-88773 through CVE-2026-88778 are not confirmed exploited. Patches are in 14.1-73.37, 13.1-64.23, and corresponding FIPS and NDcPP builds.
- CVE-2026-88771 enables unauthenticated RCE on default NetScaler configurations with low complexity.
- CVE-2026-88772 is a DTLS memory-corruption RCE rated high attack complexity.
- CISA confirmed pre-disclosure zero-day exploitation and added both flaws to KEV.
- Six other NetScaler bugs were fixed but are not confirmed exploited.
- Fixed in 14.1-73.37, 13.1-64.23, and corresponding FIPS and NDcPP releases.
Vulnerabilities mentionedAll →
- CVE-2026-887729.51%Unauthenticated RCE/DoS in Citrix NetScaler ADC and Gatewaypublished · Citrix NetScaler ADC KEV PoC ×2+1 related
Full article480 words · extracted from rapid7.com · click to collapse
Overview
On September 27, 2026, Citrix disclosed eight new vulnerabilities affecting NetScaler ADC and NetScaler Gateway, including two critical remote code execution (RCE) vulnerabilities: CVE-2026-88771 and CVE-2026-88772. Both of these RCE vulnerabilities carry a critical CVSSv4 score of 9.5, and both have been confirmed as being actively exploited in the wild as zero-days prior to the vendor disclosure.
CVE-2026-88771 affects vulnerable NetScaler deployments in their default configuration, with no additional product features required. The vendor has also indicated that the attack complexity for exploiting CVE-2026-88771 is low, meaning reliable RCE is likely against all vulnerable NetScaler appliances regardless of their configuration. This is especially concerning due to the prevalence of NetScaler appliances.
CVE-2026-88772 is a memory corruption vulnerability and requires the DTLS feature to be enabled on the appliance. The vendor has indicated that the attack complexity is high, meaning achieving reliable exploitation may be more difficult for an attacker than that of CVE-2026-88771.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) reports active exploitation is occurring globally, and added both CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) catalog on September 27, 2026. Multiple CERTs worldwide have begun issuingalerts due to the critical nature of this situation.
The following table summarizes all eight vulnerabilities:
CVE | CVSSv4 | Vulnerability | Exploitation confirmed |
|---|---|---|---|
Improper input validation leading to RCE in a default configuration (CWE-20) | Yes (CISA) | ||
Memory overflow leading to RCE in a DTLS configuration (CWE-119) | Yes (CISA) | ||
HTTP request smuggling (CWE-444) | No | ||
Policy bypass involving URL expressions (CWE-16) | No | ||
Memory overflow in Gateway or AAA configuration (CWE-119) | No | ||
Memory overflow in load balancer of type Oracle configuration (CWE-119) | No | ||
Memory overflow in a LB/CS or CGNAT-LSN/NAT64 configuration (CWE-119) | No | ||
Predictable TCP initial sequence numbers (CWE-342) | No |
Mitigation guidance
The following vendor-supplied updates are available to remediate all eight vulnerabilities. Rapid7 strongly recommends updating affected NetScaler appliances on an emergency basis, outside of normal patching cycles, and investigating vulnerable appliances for signs of compromise.
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later releases.
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1.
Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS.
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.279 and later releases of 13.1-FIPS and 13.1-NDcPP.
For the latest mitigation guidance, please refer to the vendor advisory.
Rapid7 customers
Exposure Command, InsightVM, and Nexpose
Exposure Command, InsightVM, and Nexpose customers can assess exposure to all the CVEs listed in this blog with authenticated vulnerability checks expected to be available in today’s (September 28) content release.
Intelligence Hub
Customers leveraging Rapid7’s Intelligence Hub can track the latest developments surrounding CVE-2026-88771 and CVE-2026-88772, including indicators of compromise (IOCs).
Updates
September 28, 2026: Initial publication.