• 5 min read
Citrix’s two NetScaler zero-days have different exposure conditions
Citrix confirmed active exploitation of two NetScaler RCE flaws, but only one affects every deployment by default. Patches are available now.

Image: BleepingComputer
Citrix has confirmed that attackers are exploiting two critical NetScaler remote-code-execution vulnerabilities in the wild: CVE-2026-88771 and CVE-2026-88772. Both carry a 9.5 severity score, but their exposure conditions differ. Organizations operating NetScaler ADC or Gateway at the network edge should triage them accordingly.
CVE-2026-88771 is an improper-input-validation flaw that lets an unauthenticated attacker execute arbitrary commands. Citrix says it affects all NetScaler ADC and NetScaler Gateway deployments, including their default configuration, with no optional feature required. CVE-2026-88772 is a memory-overflow bug that can produce remote code execution or denial of service, but requires DTLS to be enabled.
Citrix says DTLS is enabled by default on VPN virtual servers, placing many remote-access deployments within its affected configuration. The company has published patches in security bulletin CTX697096 and confirmed observed exploitation against unmitigated appliances.
“Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed.”
The technical split matters for incident triage
The two CVEs should not be collapsed into a generic “NetScaler RCE” ticket. CVE-2026-88771 affects Internet-facing appliances without an administrator enabling a special feature or changing a default setting. Its stated impact is arbitrary command execution by an unauthenticated attacker.
CVE-2026-88772 requires urgent patching where DTLS is active. Its memory-overflow condition can result in code execution or denial of service, and the default presence of DTLS on VPN virtual servers means administrators should check their configurations rather than assume a feature-dependent flaw is irrelevant.
NetScaler appliances commonly provide remote access and application-delivery services to internal corporate systems. A compromised edge appliance can give an attacker an initial foothold without first taking over an employee endpoint. Citrix has not identified an actor, published indicators of compromise, or described the attack chain in the supplied information, so there is no basis to tie these incidents to a particular campaign.
Patched NetScaler builds
Citrix’s update covers four version branches of customer-managed NetScaler ADC and Gateway deployments. The version thresholds below are the relevant upgrade targets cited for the two exploited flaws.
| NetScaler deployment branch | Vulnerable before | Patched build |
|---|---|---|
| ADC and Gateway 14.1 | 14.1-73.37 | 14.1-73.37 |
| ADC and Gateway 13.1 | 13.1-64.23 | 13.1-64.23 |
| ADC FIPS 14.1 | 14.1-73.37 FIPS | 14.1-73.37 FIPS |
| ADC FIPS and NDcPP 13.1 | 13.1-37.279 | 13.1-37.279 |
Secure Private Access Hybrid deployments that use NetScaler instances are also affected and must move to Citrix’s recommended builds. Citrix says the same release fixes six additional NetScaler vulnerabilities, for eight vulnerabilities total, but the supplied reporting does not identify those six issues or give their severity ratings.
The bulletin applies to customer-managed NetScaler ADC and Gateway appliances. Cloud Software Group is handling upgrades for Citrix-managed cloud services and Citrix-managed Adaptive Authentication. Organizations using the managed services should not infer that every customer-operated appliance is covered; the company draws an explicit boundary between its managed infrastructure and customer-managed NetScaler deployments.
For organizations unable to update immediately, the available guidance is to reduce Internet exposure where operationally feasible until patching can be completed. That can have operational consequences for remote access and application delivery, but CVE-2026-88771's default exposure makes outage planning preferable to treating this as a normal maintenance-window update.
Warnings preceded public disclosure
Administrators began receiving private warnings before Citrix publicly named the vulnerabilities. A notice circulating online and attributed to the Dutch National Cyber Security Center said a European partner CERT had provided information about two flaws that could independently lead to remote code execution. The notice said one issue could allow attackers to place shellcode directly into memory, while technical analysis of the other was still underway.
The circulating notice also said Citrix found the vulnerabilities while investigating incidents in customer environments, identified exploitation at multiple customers worldwide, and filed a notification under the European Union’s Cyber Resilience Act. Those details were not publicly authenticated by the Dutch NCSC. When asked about the apparent notice, the agency declined to provide further information outside its constituency.
“As part of our role as the National CSIRT and sectoral CSIRT for designated organizations, the NCSC-NL monitors relevant developments and cyber threats affecting the Netherlands 24/7.”
The pre-disclosure warning reportedly urged organizations to prepare for potential downtime from NetScaler upgrades and apply safeguards where possible. Once fixed builds and CVE details are public, defenders can patch, but attackers can also focus reconnaissance and exploitation efforts on appliances that remain exposed.
A familiar edge-device patching problem
The critical question is whether an organization has inventoried the externally reachable systems that need a patch. In August 2026, attackers began exploiting a VMware vCenter flaw within five days of disclosure across 47 countries, as we reported in the vCenter exploitation campaign. That does not establish a connection to the NetScaler activity, but it illustrates how quickly a disclosed infrastructure vulnerability can move from advisory to widespread operational risk.
Citrix has made the split between the flaws clear. Teams can prioritize every exposed ADC and Gateway instance for CVE-2026-88771, then identify DTLS-enabled configurations—especially VPN virtual servers—for CVE-2026-88772. Neither condition changes the patch requirement for affected supported branches.
Citrix has confirmed exploitation, but the supplied information does not quantify victims, name targeted sectors, provide forensic indicators, or state when exploitation began. CVE-2026-88771 can be exploited on default NetScaler ADC and Gateway configurations by an unauthenticated attacker.
Frequently asked questions
Which Citrix NetScaler vulnerabilities are being exploited?+
Citrix confirmed active exploitation of CVE-2026-88771 and CVE-2026-88772, two critical NetScaler ADC and NetScaler Gateway flaws with 9.5 severity scores.
Does CVE-2026-88771 require DTLS to be enabled?+
No. Citrix says CVE-2026-88771 affects all NetScaler ADC and Gateway deployments, including default configurations, and does not require an additional feature.
Which NetScaler versions need to be updated?+
Citrix lists patched builds for 14.1, 13.1, 14.1 FIPS, and 13.1 FIPS/NDcPP branches. Secure Private Access Hybrid deployments using NetScaler instances also need recommended builds.
Editor-in-Chief
Sergey Kuznetsov is Head of Product at iXBT.com, one of the largest Russian-language technology media outlets, and the founder of itzine.ru. He has spent over a decade building and running tech newsrooms. At for(geeks) he sets editorial standards and reviews what ships.


