Citrix has confirmed that two new NetScaler ADC and NetScaler Gateway vulnerabilities — CVE-2026-88771 and CVE-2026-88772 — are being actively exploited in the wild, and CISA added both to its Known Exploited Vulnerabilities catalog on September 27 after receiving partner threat-intelligence reports of global exploitation. This is the fourth major NetScaler pre-auth incident of 2026, following the CitrixBleed-lineage bugs (CVE-2026-3055, CVE-2026-8451, CVE-2026-19490) and the SAML heap overflow (CVE-2026-8452) disclosed earlier this year — and it’s arguably the worst of the run, because CVE-2026-88771 doesn’t require any optional feature to be enabled at all.

What’s vulnerable

Both flaws carry a CVSS v4 score of 9.5 and are documented in Citrix’s security bulletin CTX697096, which covers eight related CVEs (CVE-2026-88771 through CVE-2026-88778); only the first two are confirmed under active exploitation.

  • CVE-2026-88771 — Improper input validation that lets a remote, unauthenticated attacker execute arbitrary commands on the appliance. Citrix states this affects every NetScaler ADC and Gateway deployment, including default configurations, with no optional feature required to be at risk. That’s a materially worse exposure profile than the SAML/AAA-gated bugs from earlier this year — there’s no “don’t use this feature” workaround, since the vulnerable code path is reachable regardless of configuration.
  • CVE-2026-88772 — A memory overflow that leads to remote code execution or denial of service, exploitable when DTLS (the UDP-based TLS variant used for VPN transport) is enabled. NetScaler turns DTLS on by default for VPN virtual servers, so most Gateway/SSL VPN deployments are exposed without any explicit opt-in.

Affected: NetScaler ADC and Gateway versions prior to 14.1-73.37 and 13.1-64.23, NetScaler ADC 14.1 FIPS prior to 14.1-73.37, and 13.1-FIPS/13.1-NDcPP prior to 13.1.37.279.

Why this matters

NetScaler appliances are internet-facing by design — they terminate SSL VPN, ICA proxy, and application-delivery traffic at the network edge. A pre-auth RCE against that class of device hands an attacker a foothold at the perimeter without first needing to compromise an endpoint or steal a credential, and from there a path into whatever internal network the appliance fronts. That’s the same exposure pattern that turned the original CitrixBleed into a mass-exploitation event, and CISA’s global-exploitation language suggests this round is following the same trajectory.

CVE-2026-88771 is the more urgent of the two precisely because it has no configuration escape hatch — every NetScaler ADC/Gateway instance, regardless of how conservatively it’s configured, presents the vulnerable code path.

Mitigation

  • Patch immediately to a fixed build: NetScaler ADC/Gateway 14.1-73.37 or later, or 13.1-64.23 or later (FIPS/NDcPP: 13.1.37.279). See Citrix bulletin CTX697096.
  • There is no meaningful configuration-based mitigation for CVE-2026-88771 — patching is the only real fix. For CVE-2026-88772, disabling DTLS on VPN virtual servers removes the exploitable path as a stopgap, at the cost of falling back to TCP-based DTLS negotiation overhead for VPN clients.
  • Restrict management-plane and Gateway/VPN endpoint exposure to trusted networks wherever business requirements allow, as a defense-in-depth measure independent of patch status.
  • Treat any appliance that was internet-facing and unpatched during the exploitation window as potentially compromised: check for unexpected files under web-accessible paths, unfamiliar child processes spawned by nsppe/aaad, and outbound connections initiated from the appliance itself — the same indicators seen in the CVE-2026-8452 exploitation wave.
  • Rotate credentials and certificates presented through any appliance showing signs of compromise; NetScaler-targeting campaigns have consistently paired initial RCE with session-token or credential theft for follow-on access.
  • Federal civilian agencies are bound by CISA’s KEV remediation deadline; every other organization running internet-facing NetScaler should treat that same timeline as the de facto industry SLA given confirmed active exploitation.

References: Citrix security bulletin CTX697096, and the CISA KEV catalog addition and advisory dated September 27, 2026.