Skip to main content

Exploitation of Zero-Day Vulnerabilities affecting Citrix NetScaler

CVE-2026-88771 & CVE-2026-88772 could allow an unauthenticated attacker to perform remote code execution

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

CVE-2026-88771 & CVE-2026-88772 could allow an unauthenticated attacker to perform remote code execution


The following platforms are also known to be affected:

Secure Private Access Hybrid deployments using NetScaler instances are also affected by the vulnerabilities.

Threat details

Exploitation of CVE-2026-88771 and CVE-2026-88772

Citrix has reported exploitation of vulnerabilities CVE-2026-88771 and CVE-2026-88772 in the wild and both have been added to the US Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) Catalog.

The NHS England National CSOC assesses further exploitation as almost certain.

VPNs and other edge devices are internet-facing by design and are highly attractive targets to attackers. Organisations are strongly encouraged to follow NCSC's vulnerability management guidance, including patching edge devices as soon as possible if a critical vulnerability is identified.


Introduction

Citrix has published a security advisory addressing eight vulnerabilities in NetScaler ADC and NetScaler Gateway, two of which are exploited as zero-days. Successful exploitation of CVE-2026-88771 could allow an unauthenticated attacker to perform remote code execution (RCE) and CVE-2026-88772 could allow an unauthenticated attacker to perform RCE or cause denial-of-service (DoS).

  • CVE-2026-88771 - 'Improper Input Validation' vulnerability - CVSSv4 Base Score: 9.5
  • CVE-2026-88772 - 'Improper Restriction of Operations within the Bounds of a Memory Buffer' vulnerability - CVSSv4 Base Score: 9.5

End of life (EoL) products likely still vulnerable

NetScaler ADC and NetScaler Gateway versions 12.1 and 13.0 are now End of Life (EoL) and are likely vulnerable. Organisations using EoL versions must upgrade to the latest release of supported versions as soon as possible.


Remediation advice

Affected organisations must review Citrix Advisory CTX697096 and follow the remediation steps detailed below.


Remediation steps

Type Step
Action

Strongly Recommended: Perform a compromise assessment

Organisations are strongly recommended to follow the steps listed in the "Indicators of Compromise" section of Citrix's supplementary blog post "Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778".

Note: Organisations are strongly recommended to complete this step first; or collect all relevant artifacts to support the compromise assessment. Patching before conducting the compromise assessment or collecting relevant artifacts may delete critical evidence.

If evidence of compromise is detected, organisations must immediately report this to the NHS England National Cyber Security Operations Centre (CSOC) by calling 0300 303 5222 or emailing [email protected]. 


https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/#Indicators_of_Compromise__811da4
Patch

Required: Update to a fixed version

Fixed versions include:

  • NetScaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later releases
  • NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
  • NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.279 and later releases of 13.1-FIPS and 13.1-NDcPP

Note: NetScaler releases 12.1 and 13.0 are end-of-life and do not receive security updates. Organisations running end-of-life versions must migrate to a supported release.


https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096


Last edited: 28 September 2026 10:40 am