Citrix Confirms Active Exploitation of Critical NetScaler Vulnerabilities
Citrix warned of active exploitation of two critical vulnerabilities in customer-managed NetScaler ADC and NetScaler Gateway devices. Both flaws have a CVSS v4 score of 9.5.

Citrix NetScaler vulnerabilities identified as CVE-2026-88771 and CVE-2026-88772 are, according to the vendor, being actively exploited against unpatched customer-managed NetScaler ADC and NetScaler Gateway deployments. Citrix disclosed them on September 27 in bulletin CTX697096, which describes eight platform vulnerabilities in total.
Both flaws have a CVSS v4 score of 9.5. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added them to its Known Exploited Vulnerabilities (KEV) catalog and said it has reports and partner intelligence regarding active global exploitation.
Citrix NetScaler vulnerabilities could lead to RCE or DoS
The first flaw, CVE-2026-88771, is unauthenticated remote code execution (RCE). It affects all NetScaler ADC and NetScaler Gateway deployments, including the default configuration. Based on the available description, exploiting it therefore does not require additional configuration or authentication.
CVE-2026-88772 is a memory overflow flaw that could lead to remote code execution or denial of service (DoS). It requires the DTLS protocol to be enabled. DTLS is enabled by default on a VPN vServer, which is particularly relevant to organizations using NetScaler for remote access.
NetScaler ADC and Gateway are often used at the edge of an enterprise network, for example to publish services and provide remote access. Unauthenticated command execution on such a device could give an attacker control over an important network infrastructure component.
Patched releases are available
Citrix lists fixes in versions 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, and 13.1-37.279 FIPS/NDcPP, or in newer applicable releases. Organizations with customer-managed devices should immediately verify the version in use and deploy the vendor’s update.
Internet-accessible devices should be prioritized. In light of the confirmed exploitation, CISA recommends checking for possible compromise before updating. If compromise is suspected, the organization should preserve forensic data and investigate the environment.
- Verify whether the organization operates customer-managed NetScaler ADC or NetScaler Gateway.
- Check the version and update to the patched release specified by the vendor or a newer applicable release.
- For internet-accessible devices, check for signs of compromise and, if compromise is suspected, preserve data for forensic analysis.
The vendor is handling cloud services separately
The bulletin concerns customer-managed devices. According to Cloud Software Group, Citrix-managed cloud services and Citrix-managed Adaptive Authentication are updated by the vendor itself. Organizations should therefore distinguish between operating the device themselves and using a vendor-managed service.
The identities of the attackers, the number of affected organizations, specific victims, and the extent of successful compromises have not been publicly confirmed. It is also unknown whether the attackers are using the same exploit or combining both vulnerabilities against specific targets.
Further information may emerge in the form of indicators of compromise and technical exploit details from Citrix, CISA, or national CERT teams. Confirmed incident reports and any attribution of the campaigns to specific actors will also be important.
Sources
- Citrix / Cloud Software Group – CTX697096 – The vendor confirms observed exploitation of CVE-2026-88771 and CVE-2026-88772, describes the vulnerability conditions, and lists patched versions.
- CISA – Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway – CISA confirms that both flaws were added to KEV and reports active global exploitation.
- CERT-EU – Security Advisory 2026-014 – Independently summarizes the scope of affected versions, the critical nature of both RCE flaws, and recommends immediate updating and compromise checks.
Verified and updated: September 28, 2026 06:20



