Citrix NetScaler CVE-2026-88771 and CVE-2026-88772: Exploited RCE Flaws, Fixed Builds and Response Guide


Citrix published fixes on September 27, 2026 for two critical NetScaler ADC and NetScaler Gateway vulnerabilities that were already being exploited on unmitigated systems. CVE-2026-88771 and CVE-2026-88772 are both rated 9.5 under CVSS v4.0 and can lead to remote code execution.

Customers running affected builds should move to 14.1-73.37 or later or 13.1-64.23 or later. NetScaler ADC FIPS deployments require 14.1-73.37 FIPS or later, while 13.1 FIPS and NDcPP deployments require 13.1-37.279 or later. Citrix-managed cloud services and Citrix-managed Adaptive Authentication have already received the necessary updates.

The first flaw has the broader exposure. Citrix says CVE-2026-88771 affects all NetScaler ADC and NetScaler Gateway deployments on vulnerable versions, including the default configuration, with no additional feature required. CVE-2026-88772 applies when DTLS is enabled; Citrix notes that DTLS is enabled by default on VPN virtual servers.

The two exploited vulnerabilities

CVE CVSS v4 Impact Required condition Fixed builds
CVE-2026-88771 9.5 Unauthenticated arbitrary command execution All affected ADC/Gateway deployments 14.1-73.37+, 13.1-64.23+; corresponding FIPS/NDcPP builds
CVE-2026-88772 9.5 Remote code execution or denial of service DTLS enabled; enabled by default on VPN vServer Same fixed build floors

CVE-2026-88771 is an improper-input-validation vulnerability. Citrix's CVSS vector lists network reachability, low attack complexity, no privileges and no user interaction, with an additional attack precondition. The vendor says exploitation can allow an unauthenticated attacker to execute arbitrary commands.

CVE-2026-88772 is a memory-overflow vulnerability. Its CVSS vector lists network reachability, high attack complexity, no privileges and no user interaction. Successful exploitation can produce remote code execution or denial of service when the DTLS condition is present.

Citrix's September 27 bulletin states that exploitation of both vulnerabilities has been observed on unmitigated NetScaler deployments and urges affected customers to install the updated versions as soon as possible. Because exploitation preceded the public fixes, operators should treat previously exposed vulnerable appliances as an incident-response question as well as a patch-management task.

Affected and fixed versions

Citrix lists these supported release families as affected:

  • NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37.
  • NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23.
  • NetScaler ADC FIPS 14.1 before 14.1-73.37 FIPS.
  • NetScaler ADC FIPS and NDcPP 13.1 before 13.1-37.279.
  • Secure Private Access Hybrid deployments using affected NetScaler instances also require the relevant NetScaler update.

Citrix's bulletin applies to customer-managed NetScaler ADC and Gateway systems. Cloud Software Group says it has updated Citrix-managed cloud services and Citrix-managed Adaptive Authentication.

Why CVE-2026-88771 deserves immediate priority

The deployment condition makes CVE-2026-88771 particularly consequential. The vendor lists the precondition as all NetScaler ADC and NetScaler Gateway deployments, including default configurations. Administrators therefore cannot use the absence of an optional feature such as VPN, AAA or DTLS as an exclusion test for this CVE.

CVE-2026-88772 has a narrower configuration boundary, but that boundary still includes common remote-access deployments because DTLS is enabled by default on VPN virtual servers.

CERT-SE independently issued an alert on September 27 recommending rapid application of the vendor updates and examination of affected systems for signs of compromise or anomalous behavior.

Response checklist for NetScaler operators

1. Identify every customer-managed appliance

Inventory NetScaler ADC, NetScaler Gateway and Secure Private Access Hybrid deployments. Record the exact installed build and whether each system is internet-facing or otherwise reachable from untrusted networks.

2. Upgrade past the fixed build floor

Install the appropriate fixed release for each branch. A system remains in the affected range when it is below the build listed by Citrix, even if it received an earlier 2026 NetScaler security update.

3. Determine DTLS exposure separately

For CVE-2026-88772, verify whether DTLS is enabled. VPN virtual servers have DTLS enabled by default according to the Citrix bulletin. This configuration check is additional context for triage; CVE-2026-88771 applies across affected deployments regardless of that setting.

4. Preserve and review evidence from the pre-patch period

Active exploitation occurred before public remediation was available. Preserve relevant NetScaler logs, configuration records and surrounding network/security telemetry before normal retention cycles remove them. Review for anomalous administrative activity, unexpected processes or files, configuration changes and unusual outbound connections during the vulnerable exposure window.

5. Escalate credible compromise indicators

A successful upgrade closes the known software exposure going forward. It cannot establish whether an appliance was compromised earlier. If investigation identifies credible compromise, follow the organization's incident-response process and assess credentials, sessions, certificates, secrets and downstream systems accessible through the appliance.

Six additional vulnerabilities shipped in the same bulletin

Citrix's CTX697096 bulletin covers eight CVEs in total. Beyond the two exploited 9.5-rated flaws, it lists CVE-2026-88773 through CVE-2026-88778 with deployment-specific preconditions affecting functions including HTTP configurations, URL-based policy expressions, Gateway/AAA virtual servers and other networking features.

Operators should use the full Citrix bulletin when assessing an appliance. Moving to the vendor's current fixed build addresses the affected release range described in the bulletin.

Bottom line

Customer-managed NetScaler ADC and Gateway systems below the September 27 fixed builds need urgent attention. CVE-2026-88771 reaches all affected deployments and permits unauthenticated arbitrary command execution; CVE-2026-88772 can produce RCE or denial of service where DTLS is enabled. Citrix has confirmed observed exploitation of both flaws on unmitigated deployments.

The appropriate operational sequence is to inventory affected systems, preserve useful telemetry, install the fixed build, and investigate previously exposed appliances for evidence of compromise. The pre-disclosure exploitation history makes retrospective review material even after patching succeeds.

Sources