Citrix Sounds the Alarm: Two Critical NetScaler Zero-Days Actively Exploited
Citrix has released security updates for NetScaler ADC and NetScaler Gateway addressing CVE-2026-88771 and CVE-2026-88772, two critical remote code execution vulnerabilities. Exploits against unmitigated deployments have been observed. CVE-2026-88771 affects all deployments, including default configurations; CVE-2026-88772 applies when DTLS is enabled, including the default state on VPN virtual servers. This article covers impact, affected and fixed versions, how to confirm exposure, and recommended remediation.
Summary
Citrix has published security updates for NetScaler ADC and NetScaler Gateway in bulletin CTX697096. Two critical issues CVE-2026-88771 and CVE-2026-88772 can lead to remote code execution. Exploits of both on unmitigated NetScaler deployments have been observed.
Citrix security bulletin also addresses CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778. Descriptions and preconditions for those issues are in that Citrix advisory.
Vulnerability Details
| CVE ID | CVSS Score | Type |
|---|---|---|
| CVE-2026-88771 | 9.5 | CWE-20: Improper Input Validation |
| CVE-2026-88772 | 9.5 | CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer |
Technical Information
CVE-2026-88771 - Remote Code Execution due to Improper Input Validation
An unauthenticated attacker can execute arbitrary commands on the appliance through improper input validation.
Precondition: All NetScaler ADC and NetScaler Gateway deployments are affected(Default configuration / No additional feature required).
Instructions: All NetScaler ADC and NetScaler Gateway deployments are affected, including those deployed with the default configuration. No additional features or settings need to be enabled for the NetScaler deployment to be vulnerable.
CVE-2026-88772 - Memory Overflow Leading to Remote Code Execution or Denial of Service
A memory overflow condition can result in remote code execution or denial of service.
Precondition: DTLS configuration enabled on NetScaler ADC or NetScaler Gateway. DTLS is enabled by default on VPN virtual servers.
Instructions: Customers can determine whether their NetScaler deployment meets this precondition by inspecting the configuration for DTLS-enabled virtual servers. A NetScaler Gateway is vulnerable if DTLS is not explicitly disabled, and other virtual servers are vulnerable if they are configured with type DTLS.
Relevant configuration patterns to check:
add vpn vserver vpn1 SSL 10.0.0.0 443 -Listenpolicy NONE— DTLS is not explicitly disabled, so DTLS is enabled by default.add vpn vserver vpn1 SSL 10.0.0.0 443 -dtls OFF -Listenpolicy NONE— DTLS is explicitly disabled; the precondition is not met.add vpn vserver vs1 DTLS 10.11.1.1 443— DTLS is enabled.add lb vserver vd_dtls DTLS 10.146.111.74 443 -persistenceType NONE -cltTimeout 120— DTLS is enabled.
Impact
-
CVE-2026-88771Remote command execution on NetScaler ADC and NetScaler Gateway, including default deployments. Compromise of an edge appliance can open a path into systems behind the device.
-
CVE-2026-88772Remote code execution or denial of service when DTLS is enabled, including cases where DTLS remains on by default for VPN virtual servers.
Affected and Fixed Versions
Supported version ranges listed as affected citrix advisory (including these two CVEs). Per-CVE exposure also depends on the preconditions above.
- Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 before 14.1-73.37
- Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 before 13.1-64.23
- Citrix NetScaler ADC FIPS before 14.1-73.37 FIPS
- Citrix NetScaler ADC FIPS and NDcPP before 13.1-37.279
Secure Private Access Hybrid deployments using NetScaler instances are also affected and should be upgraded to the recommended builds.
Fixed builds:
- Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later releases
- Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
- Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
- Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.279 and later releases of 13.1-FIPS and 13.1-NDcPP
Citrix Security bulletin applies only to customer-managed Citrix NetScaler ADC and Citrix NetScaler Gateway. Cloud Software Group upgrades Citrix-managed cloud services and Citrix-managed Adaptive Authentication.
MITRE ATT&CK Mapping
| Technique ID | Technique Name | Tactic |
|---|---|---|
| T1190 | Exploit Public-Facing Application | Initial Access |
| T1498 | Network Denial of Service | Impact |
Mitigation and Recommendations
Cloud Software Group strongly urges affected customers to install the relevant updated versions as soon as possible.
- Upgrade customer-managed appliances to a fixed build listed above.
- Upgrade NetScaler instances used in Secure Private Access Hybrid deployments to the recommended builds.
- For CVE-2026-88772, confirm whether DTLS is enabled using the configuration patterns in Technical Information.
Instantly Fix Risks with Saner Patch Management
Saner patch management is a continuous, automated, and integrated solution that helps you quickly remediate risks, including critical network infrastructure updates. It supports Windows, Linux, macOS, and 550+ third-party applications.
You can stage patches in a safe testing environment before production deployment and roll back if needed.
Experience the fastest and most accurate patching software here.



