Citrix Confirms NetScaler 0-Day RCE Vulnerabilities Actively Exploited in Attack
Citrix confirms attackers are exploiting two critical unauthenticated NetScaler RCE zero-days, CVE-2026-88771 and CVE-2026-88772.
Citrix released emergency updates after confirming attackers are exploiting two critical unauthenticated remote code execution flaws in NetScaler ADC and NetScaler Gateway. CVE-2026-88771 (CVSS 9.5) is improper input validation enabling arbitrary command execution on all deployments, including defaults. CVE-2026-88772 (CVSS 9.5) is a memory overflow that can cause RCE or denial of service when DTLS is enabled, which is default on VPN virtual servers. Six more issues, including HTTP request smuggling CVE-2026-88773 (9.3), are patched in 14.1-73.37 and 13.1-64.23; updating does not remove artifacts from prior compromise.
- CVE-2026-88771 allows unauthenticated remote command execution on every NetScaler ADC and Gateway deployment.
- CVE-2026-88772 is a memory-overflow RCE or DoS when DTLS is enabled, the VPN default.
- Six additional flaws cover request smuggling, policy bypass, memory overflows, and TCP ISN prediction.
- Upgrade to 14.1-73.37 or 13.1-64.23 or later; patching does not remove prior persistence.
Vulnerabilities mentionedAll →
- CVE-2026-887729.51%Unauthenticated RCE/DoS in Citrix NetScaler ADC and Gatewaypublished · Citrix NetScaler ADC KEV PoC ×2+1 related
Full article817 words · extracted from cybersecuritynews.com · click to collapse
Citrix has released emergency security updates for NetScaler ADC and NetScaler Gateway after confirming that attackers are exploiting two critical remote code execution vulnerabilities against unmitigated appliances.
The flaws, CVE-2026-88771 and CVE-2026-88772, each carry a CVSS v4.0 score of 9.5 and can let remote, unauthenticated adversaries execute code, placing internet-facing gateways at immediate risk. Because these appliances sit at the network edge and broker trusted traffic, successful exploitation may provide a powerful foothold for lateral movement and credential theft.
The confirmation validates warnings covered yesterday by Cyber Security News, when watchTowr reported two previously undisclosed NetScaler RCE zero-days found during forensic investigations.
At that time, Citrix had not released CVE identifiers, affected builds, indicators of compromise, or patches, forcing some organizations to consider isolating exposed appliances while awaiting authoritative guidance.
NetScaler 0-Day RCE Exploited
CVE-2026-88771 results from improper input validation and can permit arbitrary command execution. Its exposure is unusually broad: every NetScaler ADC and NetScaler Gateway deployment is affected, including default configurations, with no optional feature required. CVE-2026-88772 is a memory-overflow flaw capable of causing RCE or denial of service when DTLS is enabled; DTLS is enabled by default on VPN virtual servers.
The bulletin addresses six additional vulnerabilities. CVE-2026-88773, rated 9.3, enables HTTP request smuggling in deployments using HTTP configurations.
CVE-2026-88774, scored 7.0, involves policy bypass through improper HTTP URL-based expressions, potentially allowing non-normalized URLs to evade WAF or security rules.
Three 8.8-rated memory-overflow flaws—CVE-2026-88775, CVE-2026-88776 and CVE-2026-88777—affect Gateway or AAA virtual servers, Oracle load-balancing virtual servers, and LB/CS or CGNAT-LSN/NAT64 devices using non-HTTP Layer 7 features, respectively.
CVE-2026-88778, also rated 8.8, permits TCP initial sequence number prediction when Enhanced ISN Generation is disabled on relevant TCP configurations.
Administrators should upgrade immediately to NetScaler ADC and Gateway 14.1-73.37 or later, or 13.1-64.23 or later. Fixed specialized builds are 14.1-73.37 FIPS and 13.1-37.279 for FIPS and NDcPP deployments.
Because CVE-2026-88771 affects default installations, configuration-based exposure reduction cannot replace patching. Teams should still inspect configurations for DTLS, HTTP or SSL virtual servers, Gateway and AAA services, Oracle load balancing, non-HTTP Layer 7 protocols, and disabled Enhanced ISN Generation.
| CVE ID | Vulnerability | Technical impact | Required configuration | CVSS v4.0 | Exploited |
|---|---|---|---|---|---|
| CVE-2026-88771 | Improper input validation | Unauthenticated attackers can execute arbitrary commands remotely | All deployments, including default configurations; no additional feature required | 9.5 Critical | Yes |
| CVE-2026-88772 | Memory overflow | Remote code execution or denial of service | DTLS enabled; DTLS is enabled by default on VPN virtual servers | 9.5 Critical | Yes |
| CVE-2026-88773 | HTTP request smuggling | Enables conflicting HTTP request interpretation, potentially affecting downstream systems | HTTP configuration enabled, including applicable HTTP or SSL virtual servers | 9.3 Critical | Not reported |
| CVE-2026-88774 | HTTP URL policy bypass | Non-normalized URLs may bypass WAF policies or other URL-based security rules | Policy configured with an HTTP URL-based expression | 7.0 High | Not reported |
| CVE-2026-88775 | Memory overflow | Unpredictable behavior, memory corruption or denial of service | Gateway services, including SSL VPN, ICA Proxy, CVPN and RDP Proxy, or an AAA virtual server | 8.8 High | Not reported |
| CVE-2026-88776 | Memory overflow | Unpredictable behavior, memory corruption or denial of service | Load-balancing virtual server configured with the Oracle protocol | 8.8 High | Not reported |
| CVE-2026-88777 | Memory overflow | Unpredictable behavior, memory corruption or denial of service | LB/CS or CGNAT-LSN/NAT64 deployment using a non-HTTP Layer 7 protocol feature | 8.8 High | Not reported |
| CVE-2026-88778 | Predictable TCP initial sequence numbers | May enable TCP connection prediction, manipulation or related network attacks | Relevant TCP virtual server configured and Enhanced ISN Generation disabled | 8.8 High | Not reported |
Citrix is providing generic indicators of compromise through NetScaler Console’s Security Advisory workflow. The capability requires telemetry and is available through the Console service and on-premises Console with Cloud Connect, beginning with version 14.1-73.36.
Citrix cautions that these checks cannot cover every attacker technique and may miss compromises; organizations finding suspicious activity should preserve evidence and engage qualified forensic responders. Logs should be forwarded to an external SIEM, while File Integrity Monitoring can help identify unauthorized changes.
A deployment running 13.1-64.23 may enter a reboot loop during upgrade when NetScaler variables are configured. Administrators can run show ns variable; if variables are returned, Citrix advises planning for 13.1-64.24. The Console may also temporarily mislabel 13.1-64.23 as vulnerable.
Given confirmed exploitation, defenders should treat the update as an incident-response priority, not routine patch management. Patch every node, verify the running build, scan for compromise, review authentication and network activity, and investigate unexpected files, processes, configuration changes or outbound connections.
Updating closes the vulnerabilities, but it does not remove persistence or other artifacts left by attackers who exploited an appliance before remediation.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.