Citrix — Two Critical NetScaler Remote Code Execution Zero-Days Exploited in Attacks (CVE-2026-88771)
Publication date: September 27, 2026
Category: News / Zero Days
Introduction
Citrix has issued an official confirmation and released urgent security updates to address two critical remote code execution (RCE) vulnerabilities impacting Citrix NetScaler ADC and Citrix NetScaler Gateway. Tracked as CVE-2026-88771 and CVE-2026-88772, these flaws operated initially as zero-days and have been actively exploited in targeted attacks worldwide. The incidents first came to light following private warnings issued by IT vendors and national cybersecurity agencies to various system administrators, ahead of the vendor’s formal advisory publication and the inclusion of the flaws in CISA’s Known Exploited Vulnerabilities catalog.
What is NetScaler ADC and NetScaler Gateway? (General Analysis)
Citrix NetScaler ADC (Application Delivery Controller) and NetScaler Gateway are core networking infrastructure solutions commonly deployed as Internet-facing edge devices. Their primary function is to manage, optimize, and secure incoming web traffic while providing secure remote access (VPN) and application delivery services for internal corporate networks.
Due to their critical perimeter placement, exposed NetScaler appliances represent high-value targets for threat actors. Compromising one of these devices grants an attacker an immediate initial foothold at the edge of the victim’s network, establishing a pathway to internal systems without requiring the prior compromise of an internal endpoint.
Summary of Confirmed Vulnerabilities (NVD Data)
Official parameters for these vulnerabilities are structured as follows:
| CVE | Category (CWE) | Impact | CVSS | Vector (summarized) |
|---|---|---|---|---|
| CVE-2026-88771 | CWE-20 (Improper Input Validation) | Unauthenticated arbitrary command execution | 9.5 (Critical) | CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
| CVE-2026-88772 | CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) | Remote Code Execution or Denial of Service (DoS) | 9.5 (Critical) | CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Note: The CVSS vector, scores, severities, and CWE classifications provided are official confirmed facts sourced directly from the National Vulnerability Database (NVD).
How Does It Work? (Technical Analysis)
A technical breakdown of the flaws reveals methodologies allowing threat actors to bypass perimeter authentication and memory boundaries:
- Initial Entry Flow (CVE-2026-88771): Stemming from improper input validation, an unauthenticated attacker can transmit maliciously crafted network requests that manipulate system input parameters, successfully executing arbitrary commands on the underlying operating system. Citrix notes that this vulnerability impacts all default deployments and does not require any additional feature to be enabled.
- Memory Overflow and Execution (CVE-2026-88772): This buffer/memory overflow vulnerability can lead to remote code execution or a denial-of-service condition. Exploitation can occur when the Datagram Transport Layer Security (DTLS) protocol is enabled. Notably, DTLS is enabled by default on NetScaler VPN virtual servers.
- Persistence and Lateral Movement: Achieving system-level code execution via these vectors enables malicious actors to inject shellcode directly into memory or establish firmware-level persistence, facilitating internal network reconnaissance without triggering traditional endpoint security alarms.
Affected Systems / Environments
The vulnerabilities impact the following customer-managed versions of NetScaler ADC and NetScaler Gateway:
- NetScaler ADC and NetScaler Gateway: Versions 14.1 prior to 14.1-73.37
- NetScaler ADC and NetScaler Gateway: Versions 13.1 prior to 13.1-64.23
- NetScaler ADC FIPS: Versions prior to 14.1-73.37 FIPS
- NetScaler ADC FIPS and NDcPP: Versions prior to 13.1-37.279
- Secure Private Access: Hybrid deployments utilizing affected NetScaler instances.
Note: Citrix’s advisory does not apply to Cloud Software Group-managed cloud services or managed Adaptive Authentication, which have been updated by the provider.
Mitigation and Detection
Remediation
- Prioritized Patching: Administrators must immediately upgrade affected NetScaler ADC and NetScaler Gateway appliances to the vendor-patched builds (versions 14.1-73.37, 13.1-64.23, or subsequent revisions).
- Temporary Exposure Reduction: In scenarios where immediate patching is unfeasible due to operational constraints, organizations should heavily restrict Internet exposure or isolate management and VPN services until remediation can be completed.
Detection
Defensive teams and Security Operations Centers (SOCs) should thoroughly audit access logs and perimeter traffic for anomalies:
- Monitor for abnormal connection attempts involving the DTLS protocol or HTTP/Gateway requests containing highly unusual input parameters or command escape sequences.
- Review unexpected child processes spawned by NetScaler system daemons or management services.
Threat Intelligence Warning: The active exploitation of CVE-2026-88771 and CVE-2026-88772 in production environments highlights that attackers prioritize edge appliances as initial access vectors. Organizations must not underestimate memory persistence risks and should validate appliance integrity concurrently with patch deployment.
Wrapping Up
Citrix’s confirmation of two critical remote code execution vulnerabilities exploited as zero-days emphasizes the high stakes surrounding perimeter attack surfaces. With CVSS v4.0 scores of 9.5 and inclusion in CISA’s KEV catalog, unpatched NetScaler ADC and NetScaler Gateway appliances represent primary targets for initial access and lateral movement. Immediate upgrading to patched versions and the restriction of Internet exposure are essential steps to safeguard enterprise infrastructure.
References
- Citrix Systems. (2026). Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, and other vulnerabilities (CTX697096). Vendor Advisory
- Cybersecurity and Infrastructure Security Agency (CISA). (2026). Known Exploited Vulnerabilities Catalog - CVE-2026-88771. US Government Resource
- Cybersecurity and Infrastructure Security Agency (CISA). (2026). Known Exploited Vulnerabilities Catalog - CVE-2026-88772. US Government Resource
- BleepingComputer. (2026). Citrix confirms two NetScaler RCE zero-days exploited in attacks. News Article