Citrix NetScaler — Active Zero-Day Exploitation in ADC and Gateway (CVE-2026-88771 and CVE-2026-88772)
Publication date: September 28, 2026
Category: Zero Days (realtime trigger)
Introduction
Security researchers have issued a critical warning following the detection of active in-the-wild zero-day exploitation campaigns targeting Citrix NetScaler ADC and Citrix NetScaler Gateway devices. The flaws, designated as CVE-2026-88771 and CVE-2026-88772, allow unauthenticated threat actors to compromise the integrity and availability of exposed systems through remote code execution (RCE). According to Cortex Xpanse telemetry data, over 50,000 exposed instances worldwide have been identified as potentially vulnerable, prompting urgent advisories and patch recommendations from security authorities and the vendor.
What is Citrix NetScaler ADC and Gateway? (General Analysis)
Citrix NetScaler ADC (Application Delivery Controller) and NetScaler Gateway are enterprise network infrastructure solutions built to optimize web application delivery, manage high-performance load balancing, and provide secure remote access (VPN) to corporate resources. Because these systems are typically deployed at the perimeter of corporate networks, they act as the first line of defense and initial entry point for external traffic.
Direct exposure of these devices to the internet makes any critical vulnerability an attractive attack vector for malicious actors, as successful compromise provides an immediate foothold into sensitive internal enterprise networks.
Official metrics recorded in the National Vulnerability Database (NVD) for both flaws underscore their extreme severity:
- CVE-2026-88771: Improper input validation vulnerability.
- CVSS v4.0 Vector (Confirmed):
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H(Score: 9.5 - Critical). - CWE Classification (Confirmed):
CWE-20(Improper Input Validation).
- CVSS v4.0 Vector (Confirmed):
- CVE-2026-88772: Memory overflow vulnerability in network configurations.
- CVSS v4.0 Vector (Confirmed):
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H(Score: 9.5 - Critical). - CWE Classification (Confirmed):
CWE-119(Improper Restriction of Operations within the Bounds of a Memory Buffer).
- CVSS v4.0 Vector (Confirmed):
How Does It Work? (Technical Analysis)
Technical breakdown of the vulnerabilities highlights core flaws in input processing and memory management within the NetScaler architecture:
- Initial infection flow and exploit entry:
- CVE-2026-88771: Stemming from flawed input validation within NetScaler ADC and Gateway interface components, an unauthenticated remote attacker can submit specially crafted requests across the network. The system processes these inputs insecurely, enabling arbitrary command execution on the underlying operating system.
- CVE-2026-88772: Linked to a memory overflow flaw specifically affecting the Datagram Transport Layer Security (DTLS) configuration on NetScaler systems. By manipulating malicious DTLS frames, an attacker can trigger memory corruption leading to remote code execution or a denial of service (DoS) state on the target service.
- Persistence and code execution: Once the perimeter is breached via either vector, the attacker obtains elevated privileges on the appliance, facilitating the installation of discreet persistence mechanisms, modification of routing tables, or lateral movement into internal corporate networks.
- Evasion and C2 communication: Operating directly on proprietary edge devices allows command execution to blend stealthily into legitimate underlying operating system processes, complicating detection by traditional endpoint monitoring tools unless kernel logs and network telemetry are deeply scrutinized.
Affected Systems / Environments
The vulnerabilities impact multiple firmware versions across both NetScaler ADC and NetScaler Gateway deployments. The following table summarizes the CVE details:
| CVE | Category (CWE) | Impact | CVSS | Vector (summary) |
|---|---|---|---|---|
| CVE-2026-88771 | CWE-20 (Improper Input Validation) | Command Execution / RCE | 9.5 (Critical) | AV:N/AC:L/AT:P/PR:N/UI:N |
| CVE-2026-88772 | CWE-119 (Memory Buffer Overflow) | RCE / Denial of Service (DoS) | 9.5 (Critical) | AV:N/AC:H/AT:N/PR:N/UI:N |
Affected Software Versions:
- NetScaler ADC: Before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP.
- NetScaler Gateway: Before 14.1-73.37 and before 13.1-64.23.
Mitigation and Detection
Remediation
Defensive teams should prioritize the following corrective actions:
- Firmware Update: Immediately apply official patches provided by Citrix in their security advisory, upgrading systems to secure versions (14.1-73.37, 13.1-64.23, or later).
- Perimeter Isolation: If patching cannot be performed immediately, isolate vulnerable systems from direct public internet access using strict network segmentation rules.
- Evidence Preservation: Prior to applying patches or modifications, capture VPX instance snapshots, technical support bundles, packet engine core dumps, and centralize logs to remote syslog servers.
Detection
Defensive teams (Blue Teams) must conduct proactive threat hunting to spot anomalies:
- Audit system logs for signs of suspicious or unauthorized administrative sessions.
- Monitor network traffic for unexpected outbound connections originating from NetScaler appliances.
- Search for unexplained gaps or drops in logging continuity.
Intelligence Advisory: Applying software patches remediates the underlying vulnerability, but it will not automatically remove access or persistence mechanisms established by threat actors within the internal network prior to remediation.
Wrapping Up
The detection of zero-day exploitation campaigns targeting Citrix NetScaler ADC and Gateway highlights the ongoing focus of attackers on enterprise perimeter infrastructure. With a critical CVSS v4.0 score of 9.5 and inclusion in CISA’s KEV catalog, organizations with exposed devices face imminent operational risk. Combining rapid firmware updates with rigorous forensic auditing remains essential to mitigating the impact of these sophisticated threats.
References
- Citrix Systems. (2026). Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777 and CVE-2026-88778. https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096
- Cybersecurity and Infrastructure Security Agency (CISA). (2026). Known Exploited Vulnerabilities Catalog (CVE-2026-88771). https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-88771
- Cybersecurity and Infrastructure Security Agency (CISA). (2026). Known Exploited Vulnerabilities Catalog (CVE-2026-88772). https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-88772
- Unit 42 (Palo Alto Networks). (2026). Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild. https://unit42.paloaltonetworks.com/?p=187874