Citrix NetScaler Zero-Days Are Being Exploited — Two RCE Bugs Hit the VPN Gateway
- The Mess: Citrix confirmed that two critical NetScaler vulnerabilities were exploited in attacks before patches were available. CVE-2026-88771 and CVE-2026-88772 can lead to remote code execution, with both rated CVSS 9.5.
- The Damage: A compromised NetScaler can become an attacker-controlled gateway into infrastructure that handles remote access, application delivery and VPN traffic.
- The Fix: Upgrade affected NetScaler ADC and Gateway appliances to the fixed builds immediately and investigate them for signs of compromise.
Citrix NetScaler is not some forgotten internal application.
It often sits directly on the edge of the network.
That makes a remotely exploitable vulnerability in the platform particularly nasty.
This time there are two of them.
Citrix disclosed eight vulnerabilities in NetScaler ADC and NetScaler Gateway, but CVE-2026-88771 and CVE-2026-88772 are the ones that matter most because Citrix confirmed exploitation on unmitigated appliances.
CVE-2026-88771: no special configuration required
The first vulnerability is a remote code execution flaw caused by improper input validation.
The important part is the precondition:
None.
Citrix says all affected NetScaler ADC and NetScaler Gateway deployments are vulnerable, including installations using the default configuration.
No additional feature needs to be enabled.
No exotic configuration is required.
An unauthenticated attacker can send malicious input and execute arbitrary commands on the appliance.
The vulnerability carries a CVSS 4.0 score of 9.5.
That makes CVE-2026-88771 particularly uncomfortable for organizations running internet-facing NetScaler systems.
There is no authentication barrier to rely on.
CVE-2026-88772: the DTLS problem
The second vulnerability is different.
CVE-2026-88772 is a memory overflow that can result in remote code execution or denial of service.
It carries another CVSS 9.5 score.
This one requires DTLS to be enabled.
The problem?
Citrix says DTLS is enabled by default on a VPN vServer unless it has been explicitly disabled.
So an administrator cannot simply assume that the second vulnerability is irrelevant because nobody intentionally enabled some unusual feature.
The configuration needs to be checked.
Citrix provides specific configuration patterns for determining whether the appliance meets the vulnerability precondition.
Eight vulnerabilities, not two
The emergency Citrix bulletin covers eight CVEs in total:
- CVE-2026-88771 — Remote Code Execution — CVSS 9.5
- CVE-2026-88772 — RCE / DoS — CVSS 9.5
- CVE-2026-88773 — HTTP Request Smuggling — CVSS 9.3
- CVE-2026-88774 — Feature policy bypass — CVSS 7.0
- CVE-2026-88775 — Memory overflow / DoS — CVSS 8.8
- CVE-2026-88776 — Memory overflow / DoS — CVSS 8.8
- CVE-2026-88777 — Memory overflow / DoS — CVSS 8.8
- CVE-2026-88778 — TCP ISN prediction — CVSS 8.8
So patching only the two zero-days isn’t enough.
The fixed releases address the complete bulletin.
Check the build number
Citrix lists these vulnerable ranges:
NetScaler ADC / Gateway 14.1
Affected before:
14.1-73.37
NetScaler ADC / Gateway 13.1
Affected before:
13.1-64.23
For FIPS and NDcPP editions, Citrix specifies separate fixed builds, including:
14.1-73.37 FIPS
and
13.1.37.279
respectively.
If the appliance is running an older build, don’t assume that a previous NetScaler security update covered these vulnerabilities.
It didn’t.
Citrix explicitly recommends upgrading affected customer-managed appliances to the fixed releases as soon as possible.
Patching isn’t enough
This is the part administrators should not skip.
Citrix says exploitation of CVE-2026-88771 and CVE-2026-88772 has already been observed.
That means upgrading an appliance does not answer the question:
Was it already compromised?
It only answers:
Is the appliance protected against this vulnerability going forward?
Those are different questions.
Security teams should therefore investigate internet-facing NetScaler appliances that were running vulnerable builds during the exploitation window.
Palo Alto Networks Unit 42 reported possible zero-day activity against NetScaler devices and observed attackers using the vulnerabilities to deploy web shells and establish persistence.
That makes post-patch investigation particularly important.
VPN gateways are attractive targets
NetScaler Gateway frequently handles remote access.
That means attackers don’t have to compromise an ordinary workstation first.
The gateway itself can become the initial foothold.
Once an edge appliance is compromised, defenders have a much harder problem: they need to determine whether the attacker only executed code on the appliance or used it to move deeper into the environment.
That is why these vulnerabilities should be treated as potential incident-response events, not just another entry in a vulnerability scanner.
What administrators should do
If you operate NetScaler ADC or NetScaler Gateway:
- Identify every customer-managed appliance.
- Check the exact running build.
- Upgrade to the appropriate fixed release.
- Check whether DTLS is enabled on VPN vServers.
- Review available logs and Citrix indicators of compromise.
- Investigate suspicious processes, files and outbound connections.
- Review authentication and VPN activity around potentially compromised systems.
- Treat unexplained activity on a vulnerable appliance as a possible compromise.
- Preserve forensic evidence before rebuilding the appliance if compromise is suspected.
Citrix’s bulletin also contains configuration checks for the individual CVEs, including the DTLS conditions relevant to CVE-2026-88772.
The ugly part
The usual security-appliance argument is:
“It’s behind the firewall.”
That doesn’t help much when the appliance is deliberately exposed to the internet because it needs to provide remote access.
NetScaler is supposed to accept hostile traffic.
The attacker only needs the exposed service.
And with CVE-2026-88771, Citrix says no additional feature is required for exploitation.
That’s about as direct as an attack surface gets.
Bugstoday opinion: Two CVSS 9.5 RCE vulnerabilities would already be enough to trigger an emergency maintenance window. Confirmed exploitation makes the decision easier: patch the NetScaler, then investigate it as though someone may already have been inside.
Technical Sources
- Citrix — CTX697096: NetScaler ADC and NetScaler Gateway Security Bulletin
- Citrix — NetScaler Security Updates for CVE-2026-88771 through CVE-2026-88778
- CVE.org — CVE-2026-88771
- CVE.org — CVE-2026-88772
- CISA — Known Exploited Vulnerabilities Catalog
- Palo Alto Networks Unit 42 — Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772




