Nora
Blake

Citrix NetScaler CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild

Nora Blake

Sep 28, 2026

8 min read

Citrix NetScaler CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild

TL;DR

Citrix NetScaler CVE-2026-88771 and CVE-2026-88772 are critical NetScaler ADC and Gateway vulnerabilities under active exploitation.

  • CVE-2026-88771 can allow unauthenticated arbitrary command execution, while CVE-2026-88772 can cause RCE or denial of service when DTLS is enabled.
  • Both carry a CVSS v4.0 score of 9.5 and were added to CISA’s KEV Catalog.
  • Organizations should assess affected appliances for compromise, preserve relevant evidence, install Citrix’s fixed builds, and investigate endpoints if suspicious downstream activity appears.

Citrix has confirmed active exploitation of two critical vulnerabilities affecting NetScaler ADC and NetScaler Gateway. Citrix NetScaler CVE-2026-88771 and CVE-2026-88772 create separate paths to remote code execution on affected deployments. CVE-2026-88771 can allow unauthenticated arbitrary command execution, while CVE-2026-88772 can cause remote code execution (RCE) or denial of service when DTLS is enabled.

Both vulnerabilities carry a CVSS v4.0 score of 9.5. Citrix says exploits targeting unmitigated deployments have already been observed. CISA added both vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog on September 27, 2026.

CVE-2026-88771 and CVE-2026-88772 at a Glance

Vulnerability Attribute CVE-2026-88771  CVE-2026-88772 
Product  NetScaler ADC and NetScaler Gateway  NetScaler ADC and NetScaler Gateway 
Vulnerability type  Improper input validation  Memory overflow 
CWE  CWE-20  CWE-119 
CVSS  9.5, CVSS v4.0  9.5, CVSS v4.0 
Product/configuration prerequisite  No additional feature required  DTLS enabled 
Potential impact  Unauthenticated arbitrary command execution  RCE or denial of service 
Active exploitation  Confirmed  Confirmed 
CISA KEV  Added September 27, 2026  Added September 27, 2026 

Citrix lists affected standard releases as NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37 and 13.1 before 13.1-64.23. Separate fixed releases apply to FIPS and NDcPP deployments.

Why CVE-2026-88771 Exposes Every Vulnerable NetScaler Deployment

The two zero-days differ significantly in their exploitation prerequisites.

CVE-2026-88771 is an improper input validation vulnerability. Citrix says the flaw can allow an unauthenticated attacker to execute arbitrary commands on affected NetScaler ADC and Gateway appliances.

The vulnerability also does not depend on an optional NetScaler feature or unusual configuration. Citrix lists the precondition as all vulnerable NetScaler ADC and NetScaler Gateway deployments, including default configurations.

Administrators therefore cannot determine they are safe simply by checking whether a particular service is disabled.

Citrix’s public bulletin does not describe the complete exploit mechanism. It does not specify the attacker-controlled input, vulnerable processing component, resulting execution privileges, or commands observed during exploitation.

Therefore, arbitrary command execution should be treated as the vulnerability’s documented capability. It should not be expanded into claims about what attackers actually executed.

Why DTLS Determines Exposure to CVE-2026-88772

CVE-2026-88772 has a narrower attack condition.

Citrix describes it as a memory overflow vulnerability that can cause remote code execution or denial of service when DTLS is enabled on NetScaler ADC or Gateway.

The configuration detail matters for NetScaler Gateway deployments because DTLS is enabled by default on VPN virtual servers.

Administrators can inspect NetScaler configurations to determine whether this prerequisite exists. Citrix provides examples showing the difference.

A VPN virtual server without an explicit DTLS setting leaves DTLS enabled by default:

add vpn vserver vpn1 SSL 10.0.0.0 443 -Listenpolicy NONE

By contrast, explicitly configuring:

-dtls OFF

means the virtual server does not meet the DTLS prerequisite for CVE-2026-88772. Other virtual servers can also be exposed when configured with the DTLS type.

Important: Setting -dtls OFF removes the DTLS prerequisite for CVE-2026-88772, but it does not protect the appliance from CVE-2026-88771. Organizations running vulnerable NetScaler builds still need to install Citrix’s applicable fixed release.

Organizations still need to install Citrix’s applicable fixed release.

NetScaler Faces Another Actively Exploited Flaw in September

CVE-2026-19490 drew renewed attention when CISA added the NetScaler authentication bypass vulnerability to its Known Exploited Vulnerabilities Catalog on September 9, 2026, based on evidence of active exploitation.

CVE-2026-19490 and the two newer vulnerabilities involve different vulnerability classes and prerequisites. Current Citrix and CISA advisories do not establish a common campaign or threat-actor connection between them.

However, all three affect NetScaler ADC or Gateway infrastructure. The earlier CVE-2026-19490 NetScaler incident therefore provides useful context on actively exploited vulnerabilities affecting the same product family.

What Active Exploitation Does and Does Not Confirm

Citrix says exploitation of CVE-2026-88771 and CVE-2026-88772 against unmitigated NetScaler deployments has been observed. CISA separately describes both as critical zero-day vulnerabilities under active exploitation.

That confirms exploitation. However, it does not establish every action attackers took after exploiting the appliances.

The available primary advisories do not publicly confirm:

  • specific commands executed after exploitation
  • persistence mechanisms
  • credential theft
  • session theft
  • malware deployment
  • lateral movement
  • data exfiltration
  • attacker or campaign attribution

Organizations should therefore avoid assuming those outcomes occurred solely because the vulnerabilities can provide RCE.

At the same time, patching alone cannot determine whether exploitation happened before remediation.

Organizations should follow CISA’s KEV remediation guidance and Citrix’s incident-response guidance.

If compromise is suspected, Citrix recommends preserving relevant forensic evidence before isolation and remediation. The following evidence can support that investigation.

Preserve NetScaler Evidence Before Patching Where Possible

Incident responders should consider forensic preservation before modifying a suspected appliance.

For virtual NetScaler ADC VPX instances, Citrix recommends taking a snapshot of the potentially compromised instance. Administrators should also document the system time, timezone settings, and NTP configuration.

Teams should preserve:

  • local NetScaler logs
  • remote syslog records
  • NetScaler Console logs
  • relevant configuration information
  • available system and process information

Citrix also recommends generating a technical support bundle. The bundle can capture configuration, running processes, and other information that may support later analysis.

Evidence preservation is especially relevant when exploitation may have occurred before the organization installed the fix.

Which NetScaler Builds Fix CVE-2026-88771 and CVE-2026-88772?

Citrix urges affected customers to install the relevant updated NetScaler release as soon as possible.

Fixed builds include:

  • NetScaler ADC and NetScaler Gateway 14.1-73.37 and later
  • NetScaler ADC and NetScaler Gateway 13.1-64.23 and later
  • NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.279 and later

Organizations should match each deployed appliance to its appropriate release train rather than treating one build number as universal.

The fixes directly address the vulnerable NetScaler software. Endpoint patching does not remediate these appliance-side vulnerabilities.

How Hexnode Supports Downstream Endpoint Investigation

NetScaler remediation remains the first priority. Hexnode does not patch the vulnerable NetScaler appliance, and Hexnode XDR should not be positioned as detecting these specific CVEs.

Because NetScaler appliances can sit at the network edge, an investigation may need to extend beyond the appliance if responders find evidence of suspicious activity involving internal endpoints. In that case, endpoint telemetry can help teams investigate and contain related activity.

Investigate Endpoint Activity with Hexnode XDR

Hexnode XDR provides threat investigation and response capabilities across supported Windows and macOS endpoints. Security teams can use endpoint telemetry and threat-hunting capabilities when investigating suspicious activity associated with a broader incident.

If responders identify suspicious endpoint activity, documented response actions include:

  • Isolate Device: Restrict network connectivity on an affected endpoint while maintaining management through Hexnode XDR.
  • Kill Process: Terminate an identified malicious or suspicious process.
  • Quarantine File: Restrict a suspicious file and prevent its execution.
  • Deep Scan: Run a Deep Scan to verify remediation and assess device health and other vital parameters.

These XDR response actions can support endpoint investigation and containment when suspicious activity is identified.

They do not establish that NetScaler exploitation reached an endpoint. That conclusion requires evidence from the organization’s investigation.

Gate Resource Access Using Device Compliance

Organizations may also review access controls during the incident response process.

Hexnode UEM integrates with Microsoft Entra Conditional Access as a compliance partner. This integration lets Entra use compliance information reported by Hexnode when evaluating access to configured organizational resources.

Hexnode currently provides this Conditional Access compliance data for Android, iOS/iPadOS, and macOS devices. It does not currently provide compliance data for Windows through this integration.

Administrators can configure Conditional Access to require a device to be marked compliant before granting access to protected resources.

This capability can support access control during a broader response. However, device compliance does not determine whether a NetScaler appliance has been compromised.

Why-XDR-IS-stronger-thumbnail

Why XDR Is Stronger With UEM

Explore how UEM and XDR can work together to improve endpoint context, threat response, and incident containment.

Download the whitepaper

How to Respond to Citrix NetScaler CVE-2026-88771 and CVE-2026-88772

Organizations running affected NetScaler ADC or Gateway builds should identify vulnerable appliances, assess for compromise, preserve relevant forensic evidence, and install Citrix’s applicable fixed release. CVE-2026-88772 also requires administrators to review DTLS-enabled virtual servers.

  1. Inventory NetScaler deployments. Identify vulnerable ADC, Gateway, FIPS, NDcPP, and relevant hybrid deployments.
  2. Confirm CVE-2026-88771 exposure. Treat all vulnerable NetScaler ADC and Gateway deployments, including default configurations, as meeting Citrix’s product-configuration precondition.
  3. Check DTLS configurations for CVE-2026-88772. Review VPN virtual servers and other DTLS-enabled virtual servers.
  4. Preserve forensic evidence. Capture relevant snapshots, logs, system information, and configuration data before remediation where operationally possible.
  5. Assess for compromise. Follow current Citrix and CISA guidance rather than assuming patch installation proves the appliance was previously clean.
  6. Install the applicable fixed NetScaler build. Match the update to the organization’s specific NetScaler release train.
  7. Expand investigation when evidence warrants it. Review relevant identity, network, endpoint, and other telemetry for suspicious activity during the exposure window.
  8. Contain affected endpoints separately. If endpoint investigation identifies malicious activity, use the appropriate endpoint response controls.

This separation matters. NetScaler remediation closes the vulnerable appliance path. Endpoint investigation addresses evidence that suspicious activity may have extended beyond that appliance.

Conclusion

CVE-2026-88771 and CVE-2026-88772 put vulnerable NetScaler ADC and Gateway deployments under immediate remediation pressure because exploitation is already confirmed.

Organizations should preserve relevant evidence, assess exposed appliances for compromise, and install Citrix’s applicable fixed builds. If an investigation identifies suspicious activity beyond the appliance, teams can then extend their response to connected identity, network, and endpoint environments.

The latest disclosure also follows other actively exploited NetScaler vulnerabilities in 2026, reinforcing the need to maintain visibility and response plans for internet-facing NetScaler infrastructure.

Share

Nora Blake

I write at the intersection of technology, process, and people, focusing on explaining complex products with clarity. I break down tools, systems, and workflows without any noise, jargon, or the hype.