Security advisories

Citrix NetScaler ADC and NetScaler Gateway Zero-Day Vulnerabilities (CVE-2026-88771 & CVE-2026-88772)

September 28, 2026

4 MINS READ

THE THREAT

On September 27th, 2026, Citrix disclosed eight vulnerabilities impacting its Citrix NetScaler ADC and NetScaler Gateway products; two of which are zero-days. The first zero-day vulnerability is CVE-2026-88771 (CVSS: 9.8), which involves improper input validation within the impacted products that can lead to unauthenticated Remote Code Execution (RCE). The other zero-day flaw, CVE-2026-88772 (CVSS: 8.1), is a memory overflow vulnerability, when DTLS configuration is enabled (DTLS is enabled by default on VPN virtual servers) that can lead to RCE or Denial of Service (DoS).

Citrix has confirmed that exploitation of CVE-2026-88771 and CVE-2026-88772 has been observed on "unmitigated NetScaler deployments". As exploitation is ongoing, organizations utilizing vulnerable Citrix NetScaler ADC and NetScaler Gateway versions should apply relevant updates immediately.

What We're Doing About It

What You Should Do About It

Additional Information

On September 26th, watchTowr Labs reported on rumors that "multiple unpatched Citrix NetScaler RCE vulnerabilities were circulating in the wild", later confirming that these reports involved two RCE zero-days that were "discovered during forensics". The following day, Citrix published their advisory addressing the zero-days, confirming their exploitation in the wild. CVE-2026-88772 requires the precondition of DTLS being enabled, a setting that is enabled by default on VPN virtual servers. CVE-2026-88771 requires no preconditions, and all deployments are impacted.

The advisory also addressed six other flaws, including CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778. There are currently no reports indicating that these flaws are being exploited.

Citrix did not provide any further details on the nature of attacks leveraging the flaws. Citrix is sharing IoCs through NetScaler Console to aid customers in performing a "faster initial assessment" of impact. Citrix notes that customers who do not use NetScaler Console should contact Citrix Support to request access to the applicable IoCs. On September 27th, CISA added both CVE-2026-88771 and CVE-88772 to its Known Exploited Vulnerabilities (KEV) catalog, with a deadline of September 30th for federal agencies to apply relevant patches.

On September 28th, watchTowr Labs published technical details on CVE-2026-88771, providing insight into exploitation. eSentire's TRU has observed unverified reports of Proof-of-Concept (PoC) exploit code for CVE-2026-88772 being publicly available. PoC exploit code lowers the barrier for threat actors of all skill levels to make use of within attacks, often being considered an early warning sign of widespread exploitation. Given the history of Citrix NetScaler ADC and NetScaler Gateway vulnerabilities being leveraged within attacks, eSentire's Threat Intelligence team assesses with high confidence that widespread exploitation of both CVE-2026-88771 and CVE-2026-88772 will be seen in the near term. As such, organizations should ensure that relevant patches are applied as soon as possible.

Fixed Versions:

References:

[1] https://support.citrix.com/external/article/CTX697096/citrix-netscaler-adc-and-citrix-netscale.html
[2] https://nvd.nist.gov/vuln/detail/cve-2026-88771
[3] https://nvd.nist.gov/vuln/detail/cve-2026-88772
[4] https://docs.netscaler.com/en-us/citrix-adc/current-release/system/tcp-configurations.html#enhanced-isn-generation
[5] https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/
[6] https://x.com/watchtowrcyber/status/2103891689857228803
[7] https://x.com/watchtowrcyber/status/2103972792043479307
[8] https://nvd.nist.gov/vuln/detail/cve-2026-88773
[9] https://nvd.nist.gov/vuln/detail/cve-2026-88774
[10] https://nvd.nist.gov/vuln/detail/cve-2026-88775
[11] https://nvd.nist.gov/vuln/detail/cve-2026-88776
[12] https://nvd.nist.gov/vuln/detail/cve-2026-88777
[13] https://nvd.nist.gov/vuln/detail/cve-2026-88778
[14] https://www.cisa.gov/news-events/alerts/2026/09/27/cisa-adds-two-known-exploited-vulnerabilities-catalog
[15] https://labs.watchtowr.com/oh-look-the-foot-gun-went-off-again-citrix-netscaler-preauth-command-injection-cve-2026-88771/
[16] https://www.esentire.com/blog/six-days-ahead-how-esentire-detected-netscaler-exploitation-before-the-industry-caught-up

Back to Security Advisories

Speak With A Security Expert Now

TALK TO AN EXPERT
View Most Recent Advisories