Citrix NetScaler — Global Active Exploitation of Two Critical Zero-Day Vulnerabilities (CVE-2026-88771 and CVE-2026-88772)

Publication date: September 28, 2026
Category: Vulnerability / Network Security

Introduction

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an urgent alert after confirming through threat intelligence reports that threat actors are actively exploiting two critical vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway globally. The flaws, tracked as CVE-2026-88771 and CVE-2026-88772, were immediately added to the Known Exploited Vulnerabilities (KEV) catalog. Due to the complexity of patching perimeter network appliances, CISA urged organizations to prioritize urgent mitigation and established strict remediation deadlines for federal civilian agencies.

What is Citrix NetScaler ADC and Gateway? (General Analysis)

Citrix NetScaler ADC (Application Delivery Controller) and NetScaler Gateway are critical infrastructure solutions designed to optimize web application performance, manage network traffic, and provide secure corporate remote access (VPN). Positioned typically at the perimeter of corporate networks and serving as authentication entry points, any critical vulnerability in these appliances represents a severe systemic risk, allowing attackers to pivot into the internal network.

The flaws added to the KEV catalog exhibit the following formal characteristics confirmed by NVD:

  • CVE-2026-88771: Improper input validation vulnerability in Citrix NetScaler ADC and Gateway, allowing an unauthenticated attacker to execute arbitrary commands.
    • CVSS v4.0 Score: 9.5 (CRITICAL)
    • CVSS v4.0 Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
    • CWE Classification: CWE-20 (Improper Input Validation)
    • CISA KEV Status: Confirmed (Included in catalog)
  • CVE-2026-88772: Improper restriction of operations within the bounds of a memory buffer vulnerability leading to remote code execution or denial of service.
    • CVSS v4.0 Score: 9.5 (CRITICAL)
    • CVSS v4.0 Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
    • CWE Classification: CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer)
    • CISA KEV Status: Confirmed (Included in catalog)

How Does It Work? (Technical Analysis)

Third-party research published by WatchTowr Labs details that the primary attack vector for CVE-2026-88771 resides in a Perl script named ns_monuploadd_err.pl, which is utilized internally by the appliance operating system to process error information and crash logs.

  • Initial Infection Flow: The script constructs shell commands using input data that can be externally influenced. An unauthenticated attacker can send a crafted HTTP request via the pre-authentication endpoint (/nf/auth/doAuthentication.do).
  • Command Injection and Execution: By inserting controlled input into login fields or log metadata written by NetScaler, the processing engine treats the content as direct shell commands. This achieves remote code execution with root privileges without requiring prior authentication credentials.
  • Conditions for CVE-2026-88772: Unlike the former flaw affecting all default deployments, CVE-2026-88772 requires the DTLS (Datagram Transport Layer Security) configuration to be enabled on NetScaler ADC or Gateway. This option is enabled by default on VPN virtual servers via directives such as add vpn vserver vpn1 SSL 10.0.0.0 443 -Listenpolicy NONE, facilitating memory buffer exploitation and code execution.

Affected Systems / Environments

The vulnerabilities impact the following NetScaler deployment versions:

  • Citrix NetScaler ADC and NetScaler Gateway: Versions prior to 14.1-73.37 and prior to 13.1-64.23.
  • Citrix NetScaler ADC FIPS: Versions 14.1 FIPS prior to 14.1-73.37 FIPS and 13.1 FIPS prior to 13.1.37.279 FIPS.
  • Citrix NetScaler ADC NDcPP: Versions 13.1 NDcPP prior to 13.1.37.279.
CVE Category (CWE) Impact CVSS Vector (summarized)
CVE-2026-88771 CWE-20 Arbitrary command execution (Pre-auth) 9.5 (Critical) AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H
CVE-2026-88772 CWE-119 Remote code execution / DoS (via DTLS) 9.5 (Critical) AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H

Mitigation and Detection

Remediation

  • Firmware Update: Immediately apply official patches released by Citrix by updating to versions 14.1-73.37, 13.1-64.23, or later releases corresponding to the deployment branch.
  • Perimeter Service Restriction: Temporarily disable unnecessary DTLS configurations if patches cannot be applied immediately, limiting the attack surface for CVE-2026-88772.
  • Post-Compromise Procedures: If a compromise is suspected, preserve VPX instance evidence, isolate the appliance from the network, revoke credentials, rebuild firmware, and rotate encryption keys and local accounts.

Detection

  • Indicators of Compromise (IoCs): Use NetScaler Console to review generic indicators of compromise provided by the vendor and audit access logs targeting the /nf/auth/doAuthentication.do endpoint.
  • Defensive Monitoring:

“Active exploitation of pre-authentication perimeter flaws in remote access appliances requires thorough log analysis for anomalous HTTP requests attempting to inject control characters or shell commands into authentication parameters.”

Wrapping Up

The emergence of these critical vulnerabilities in Citrix NetScaler ADC and Gateway highlights the ongoing risk enterprise edge appliances face against unauthenticated remote execution attacks. The rapid addition of CVE-2026-88771 and CVE-2026-88772 to CISA’s KEV catalog proves that active global exploitation is occurring, compelling security teams to prioritize patching and forensic audits of exposed infrastructures.

References