SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Citrix Sounds the Alarm: Two Critical NetScaler Zero-Days Actively Exploited

Citrix Sounds the Alarm: Two Critical NetScaler Zero-Days Actively Exploited

Citrix has released security updates for NetScaler ADC and NetScaler Gateway addressing CVE-2026-88771 and CVE-2026-88772, two critical remote code execution vulnerabilities. Exploits against unmitigated deployments have been observed. CVE-2026-88771 affects all deployments, including default configurations; CVE-2026-88772 applies when DTLS is enabled, including the default state on VPN virtual servers. This article covers impact, affected and fixed versions, how to confirm exposure, and recommended remediation.

Sep 28, 2026By Bapanapalli Prem Sai Siddhik

Summary

Citrix has published security updates for NetScaler ADC and NetScaler Gateway in bulletin CTX697096. Two critical issues CVE-2026-88771 and CVE-2026-88772 can lead to remote code execution. Exploits of both on unmitigated NetScaler deployments have been observed.

Citrix security bulletin also addresses CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778. Descriptions and preconditions for those issues are in that Citrix advisory.

Vulnerability Details

CVE ID CVSS Score Type
CVE-2026-88771 9.5 CWE-20: Improper Input Validation
CVE-2026-88772 9.5 CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer

Technical Information

Critical Zero-Day Unauthenticated No User Interaction Actively Exploited RCE

CVE-2026-88771 - Remote Code Execution due to Improper Input Validation

An unauthenticated attacker can execute arbitrary commands on the appliance through improper input validation.

Precondition: All NetScaler ADC and NetScaler Gateway deployments are affected(Default configuration / No additional feature required).

Instructions: All NetScaler ADC and NetScaler Gateway deployments are affected, including those deployed with the default configuration. No additional features or settings need to be enabled for the NetScaler deployment to be vulnerable.

Critical Zero-Day Unauthenticated No User Interaction Actively Exploited RCE DoS

CVE-2026-88772 - Memory Overflow Leading to Remote Code Execution or Denial of Service

A memory overflow condition can result in remote code execution or denial of service.

Precondition: DTLS configuration enabled on NetScaler ADC or NetScaler Gateway. DTLS is enabled by default on VPN virtual servers.

Instructions: Customers can determine whether their NetScaler deployment meets this precondition by inspecting the configuration for DTLS-enabled virtual servers. A NetScaler Gateway is vulnerable if DTLS is not explicitly disabled, and other virtual servers are vulnerable if they are configured with type DTLS.

Relevant configuration patterns to check:

  • add vpn vserver vpn1 SSL 10.0.0.0 443 -Listenpolicy NONE — DTLS is not explicitly disabled, so DTLS is enabled by default.
  • add vpn vserver vpn1 SSL 10.0.0.0 443 -dtls OFF -Listenpolicy NONE — DTLS is explicitly disabled; the precondition is not met.
  • add vpn vserver vs1 DTLS 10.11.1.1 443 — DTLS is enabled.
  • add lb vserver vd_dtls DTLS 10.146.111.74 443 -persistenceType NONE -cltTimeout 120 — DTLS is enabled.

Impact

  • CVE-2026-88771
    Remote command execution on NetScaler ADC and NetScaler Gateway, including default deployments. Compromise of an edge appliance can open a path into systems behind the device.
  • CVE-2026-88772
    Remote code execution or denial of service when DTLS is enabled, including cases where DTLS remains on by default for VPN virtual servers.

Affected and Fixed Versions

Supported version ranges listed as affected citrix advisory (including these two CVEs). Per-CVE exposure also depends on the preconditions above.

  • Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 before 14.1-73.37
  • Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 before 13.1-64.23
  • Citrix NetScaler ADC FIPS before 14.1-73.37 FIPS
  • Citrix NetScaler ADC FIPS and NDcPP before 13.1-37.279

Secure Private Access Hybrid deployments using NetScaler instances are also affected and should be upgraded to the recommended builds.

Fixed builds:

  • Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later releases
  • Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
  • Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
  • Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.279 and later releases of 13.1-FIPS and 13.1-NDcPP

Citrix Security bulletin applies only to customer-managed Citrix NetScaler ADC and Citrix NetScaler Gateway. Cloud Software Group upgrades Citrix-managed cloud services and Citrix-managed Adaptive Authentication.

MITRE ATT&CK Mapping

Technique ID Technique Name Tactic
T1190 Exploit Public-Facing Application Initial Access
T1498 Network Denial of Service Impact

Mitigation and Recommendations

Cloud Software Group strongly urges affected customers to install the relevant updated versions as soon as possible.

  • Upgrade customer-managed appliances to a fixed build listed above.
  • Upgrade NetScaler instances used in Secure Private Access Hybrid deployments to the recommended builds.
  • For CVE-2026-88772, confirm whether DTLS is enabled using the configuration patterns in Technical Information.

Instantly Fix Risks with Saner Patch Management

Saner patch management is a continuous, automated, and integrated solution that helps you quickly remediate risks, including critical network infrastructure updates. It supports Windows, Linux, macOS, and 550+ third-party applications.

You can stage patches in a safe testing environment before production deployment and roll back if needed.

Experience the fastest and most accurate patching software here.

Featured Posts

Open CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials
CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials

CVE Research

CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials

Sep 25, 2026

Open Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions
Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions

CVE Research

Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions

Two MikroTik RouterOS CVEs entered CISA KEV seven days after production fixes. Dated reporting places SSH-chain exploitation involving CVE-2026-86060 at least one calendar day before those releases; no comparable start date is established for CVE-2026-67277.

Sep 25, 2026

Open Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch
Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch

CVE Research

Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch

Four vulnerabilities added to CISA’s KEV catalog on September 9, 2026 show widely different timelines between public disclosure and formal exploitation-based prioritization, ranging from one day to 239 days.

Sep 24, 2026

Open TA412/APT31: Mapping Threat Actor Patterns to CVE Exploitation Chains

TA412/APT31: Mapping Threat Actor Patterns to CVE Exploitation Chains

CVE Research

TA412/APT31: Mapping Threat Actor Patterns to CVE Exploitation Chains

A chronological look at how a long-running China-nexus espionage cluster evolved from server-side exploitation to a chained Chrome/Windows zero-day kit — and what that shift signals.

Sep 24, 2026