Citrix has released security updates for two critical vulnerabilities in customer-managed NetScaler ADC and NetScaler Gateway appliances after confirming that exploitation has been observed in the wild.

The flaws, tracked as CVE-2026-88771 and CVE-2026-88772, can both lead to remote code execution under their respective conditions. For organisations exposing NetScaler appliances to the internet, the practical priority is to identify affected systems, preserve evidence where compromise is suspected, and move to a fixed build as quickly as operationally possible.

Key takeaways

  • CVE-2026-88771 is an improper input-validation flaw that can allow an unauthenticated attacker to execute arbitrary commands.
  • CVE-2026-88771 affects NetScaler ADC and Gateway deployments without requiring an additional feature to be enabled.
  • CVE-2026-88772 is a memory-overflow vulnerability that can cause remote code execution or denial of service when DTLS is enabled.
  • Citrix says exploitation of both vulnerabilities has been observed on unmitigated deployments.
  • Administrators should upgrade to a fixed release rather than treating a configuration workaround as a substitute for the vendor update.

What is CVE-2026-88771?

Citrix describes CVE-2026-88771 as an improper input-validation vulnerability. An unauthenticated remote attacker can potentially execute arbitrary commands on a vulnerable appliance.

The exposure is unusually important because Citrix lists all NetScaler ADC and NetScaler Gateway deployments as meeting the vulnerability's precondition, including default configurations. Administrators therefore should not assume that an appliance is safe simply because optional VPN or application-delivery features have not been enabled.

What is CVE-2026-88772?

CVE-2026-88772 is a memory-overflow vulnerability that can lead to remote code execution or denial of service. Its precondition is different: DTLS must be enabled on NetScaler ADC or NetScaler Gateway.

Citrix notes that DTLS is enabled by default on VPN virtual servers. That makes the flaw particularly relevant to organisations using NetScaler Gateway for remote access. Administrators should review their configuration rather than relying on assumptions about whether DTLS is active.

Which NetScaler versions need updating?

Citrix's 27 September security bulletin lists supported releases before the following fixed builds as affected. Customers should install the relevant fixed build or a later supported release:

  • NetScaler ADC and NetScaler Gateway 14.1: 14.1-73.37 or later.
  • NetScaler ADC and NetScaler Gateway 13.1: 13.1-64.23 or later.
  • NetScaler ADC 14.1-FIPS: 14.1-73.37 FIPS or later.
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP: 13.1-37.279 or later.

Secure Private Access Hybrid deployments that use NetScaler instances are also covered by the bulletin. Citrix says its own managed cloud services and managed Adaptive Authentication are updated by Cloud Software Group.

Why the active exploitation matters

These are not vulnerabilities that administrators can safely leave for a routine maintenance cycle. Citrix explicitly says exploits of CVE-2026-88771 and CVE-2026-88772 have been observed on unmitigated deployments.

CISA has also added both vulnerabilities to its Known Exploited Vulnerabilities catalogue. That provides an additional signal that defenders should prioritise remediation based on real-world exploitation rather than severity scores alone.

What administrators should do now

1. Identify every affected appliance

Build an inventory of customer-managed NetScaler ADC and Gateway instances, including internet-facing systems, disaster-recovery appliances and instances used by hybrid services. Record the installed release and build before making changes.

2. Preserve evidence if compromise is possible

If an exposed appliance may have been targeted, preserve relevant forensic evidence before an upgrade or other changes overwrite useful artefacts. Follow your organisation's incident-response process and Citrix's compromise-assessment guidance.

3. Upgrade to a fixed build

Apply the appropriate fixed version listed in Citrix's bulletin. NetScaler Console users can use its CVE Detection and upgrade workflow to identify impacted instances and start remediation.

4. Check whether DTLS is enabled

This is particularly important for CVE-2026-88772. Citrix says NetScaler Gateway is vulnerable to this flaw when DTLS has not been explicitly disabled, while other virtual servers meet the precondition when configured for DTLS.

5. Treat patching and incident investigation as separate tasks

Installing a fixed build closes the known vulnerability, but it does not by itself establish that the appliance was never compromised. Where exposure and telemetry justify it, organisations should conduct a compromise assessment and review downstream authentication, credentials and internal access for suspicious activity.

There are more vulnerabilities in the same bulletin

Citrix's CTX697096 bulletin addresses eight CVEs in total, from CVE-2026-88771 through CVE-2026-88778. The two discussed here stand out because Citrix has observed exploitation of them and both can enable remote code execution, but administrators should review the complete bulletin for other issues that apply to their configuration.

Bottom line

Organisations running customer-managed NetScaler ADC or NetScaler Gateway should treat the 27 September update as an urgent security action. Confirm the installed build, preserve evidence where necessary, upgrade to the appropriate fixed release and assess exposed appliances for signs of earlier compromise.

Because the situation is developing, administrators should use Citrix's security bulletin and official NetScaler documentation as the authoritative source for supported builds and any subsequent guidance.