Exploitation of Zero-Day Vulnerabilities affecting Citrix NetScaler
CVE-2026-88771 & CVE-2026-88772 could allow an unauthenticated attacker to perform remote code execution
Summary
CVE-2026-88771 & CVE-2026-88772 could allow an unauthenticated attacker to perform remote code execution
Affected platforms
The following platforms are known to be affected:
The following platforms are also known to be affected:
Secure Private Access Hybrid deployments using NetScaler instances are also affected by the vulnerabilities.
Threat details
Exploitation of CVE-2026-88771 and CVE-2026-88772
Citrix has reported exploitation of vulnerabilities CVE-2026-88771 and CVE-2026-88772 in the wild and both have been added to the US Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) Catalog.
The NHS England National CSOC assesses further exploitation as almost certain.
VPNs and other edge devices are internet-facing by design and are highly attractive targets to attackers. Organisations are strongly encouraged to follow NCSC's vulnerability management guidance, including patching edge devices as soon as possible if a critical vulnerability is identified.
Introduction
Citrix has published a security advisory addressing eight vulnerabilities in NetScaler ADC and NetScaler Gateway, two of which are exploited as zero-days. Successful exploitation of CVE-2026-88771 could allow an unauthenticated attacker to perform remote code execution (RCE) and CVE-2026-88772 could allow an unauthenticated attacker to perform RCE or cause denial-of-service (DoS).
- CVE-2026-88771 - 'Improper Input Validation' vulnerability - CVSSv4 Base Score: 9.5
- CVE-2026-88772 - 'Improper Restriction of Operations within the Bounds of a Memory Buffer' vulnerability - CVSSv4 Base Score: 9.5
End of life (EoL) products likely still vulnerable
NetScaler ADC and NetScaler Gateway versions 12.1 and 13.0 are now End of Life (EoL) and are likely vulnerable. Organisations using EoL versions must upgrade to the latest release of supported versions as soon as possible.
Remediation advice
Affected organisations must review Citrix Advisory CTX697096 and follow the remediation steps detailed below.
Remediation steps
| Type | Step |
|---|---|
| Action |
Strongly Recommended: Perform a compromise assessment Organisations are strongly recommended to follow the steps listed in the "Indicators of Compromise" section of Citrix's supplementary blog post "Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778". Note: Organisations are strongly recommended to complete this step first; or collect all relevant artifacts to support the compromise assessment. Patching before conducting the compromise assessment or collecting relevant artifacts may delete critical evidence. If evidence of compromise is detected, organisations must immediately report this to the NHS England National Cyber Security Operations Centre (CSOC) by calling 0300 303 5222 or emailing [email protected]. https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/#Indicators_of_Compromise__811da4 |
| Patch |
Required: Update to a fixed version Fixed versions include:
Note: NetScaler releases 12.1 and 13.0 are end-of-life and do not receive security updates. Organisations running end-of-life versions must migrate to a supported release. https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096 |
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 28 September 2026 10:40 am