Citrix Confirms Active Exploitation of Critical NetScaler Vulnerabilities

Citrix warned of active exploitation of two critical vulnerabilities in customer-managed NetScaler ADC and NetScaler Gateway devices. Both flaws have a CVSS v4 score of 9.5.

Citrix NetScaler vulnerabilities identified as CVE-2026-88771 and CVE-2026-88772 are, according to the vendor, being actively exploited against unpatched customer-managed NetScaler ADC and NetScaler Gateway deployments. Citrix disclosed them on September 27 in bulletin CTX697096, which describes eight platform vulnerabilities in total.

Both flaws have a CVSS v4 score of 9.5. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added them to its Known Exploited Vulnerabilities (KEV) catalog and said it has reports and partner intelligence regarding active global exploitation.

Citrix NetScaler vulnerabilities could lead to RCE or DoS

The first flaw, CVE-2026-88771, is unauthenticated remote code execution (RCE). It affects all NetScaler ADC and NetScaler Gateway deployments, including the default configuration. Based on the available description, exploiting it therefore does not require additional configuration or authentication.

CVE-2026-88772 is a memory overflow flaw that could lead to remote code execution or denial of service (DoS). It requires the DTLS protocol to be enabled. DTLS is enabled by default on a VPN vServer, which is particularly relevant to organizations using NetScaler for remote access.

NetScaler ADC and Gateway are often used at the edge of an enterprise network, for example to publish services and provide remote access. Unauthenticated command execution on such a device could give an attacker control over an important network infrastructure component.

Patched releases are available

Citrix lists fixes in versions 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, and 13.1-37.279 FIPS/NDcPP, or in newer applicable releases. Organizations with customer-managed devices should immediately verify the version in use and deploy the vendor’s update.

Internet-accessible devices should be prioritized. In light of the confirmed exploitation, CISA recommends checking for possible compromise before updating. If compromise is suspected, the organization should preserve forensic data and investigate the environment.

  • Verify whether the organization operates customer-managed NetScaler ADC or NetScaler Gateway.
  • Check the version and update to the patched release specified by the vendor or a newer applicable release.
  • For internet-accessible devices, check for signs of compromise and, if compromise is suspected, preserve data for forensic analysis.

The vendor is handling cloud services separately

The bulletin concerns customer-managed devices. According to Cloud Software Group, Citrix-managed cloud services and Citrix-managed Adaptive Authentication are updated by the vendor itself. Organizations should therefore distinguish between operating the device themselves and using a vendor-managed service.

The identities of the attackers, the number of affected organizations, specific victims, and the extent of successful compromises have not been publicly confirmed. It is also unknown whether the attackers are using the same exploit or combining both vulnerabilities against specific targets.

Further information may emerge in the form of indicators of compromise and technical exploit details from Citrix, CISA, or national CERT teams. Confirmed incident reports and any attribution of the campaigns to specific actors will also be important.

Sources

Verified and updated: September 28, 2026 06:20

Sharing