Critical Security Alert: Citrix NetScaler Zero-Day Exploits Exposed
Citrix has verified that two high-severity remote code execution flaws in NetScaler products are being actively exploited in cyberattacks. The vulnerabilities, designated as CVE-2026-88771 and CVE-2026-88772, were addressed through recent security updates released by the company.
Vulnerability Details
NetScaler devices serve as critical infrastructure components for many enterprises, often functioning as perimeter gateways for remote access and application delivery. Compromising these systems can provide adversaries with initial access to internal networks without requiring prior endpoint compromise.
CVE-2026-88771
CVE-2026-88771 stems from inadequate input validation, enabling unauthenticated attackers to execute arbitrary commands. This flaw affects all NetScaler ADC and Gateway deployments, regardless of configuration. The vulnerability carries a severity score of 9.5 on the CVSS scale.
CVE-2026-88772
CVE-2026-88772 is a memory overflow issue that can result in remote code execution or denial-of-service conditions. It is triggered when DTLS protocol is enabled on NetScaler ADC or Gateway devices, a setting that is default for VPN virtual servers. This vulnerability also has a severity rating of 9.5.
Pre-disclosure Warnings
Early indications of the incident emerged when IT administrators reported unsolicited communications from security teams advising immediate shutdowns of NetScaler appliances. One administrator described receiving a call from their IT provider’s security division that included no specific details but mandated urgent action.
Cybersecurity firm watchTowr publicly acknowledged the situation, stating it was responding to credible reports of unpatched NetScaler RCE vulnerabilities being used in attacks. The firm emphasized that while details remained limited, the information originated from reliable sources.
Affected Versions and Mitigation
Citrix confirmed that both flaws have been exploited in real-world attacks. The advisory specifies affected versions include:
- NetScaler ADC and Gateway 14.1 prior to 14.1-73.37
- NetScaler ADC and Gateway 13.1 prior to 13.1-64.23
- NetScaler ADC FIPS prior to 14.1-73.37
- NetScaler ADC FIPS and NDcPP prior to 13.1-37.279
Secure Private Access Hybrid deployments using NetScaler instances are also impacted.
Critical Vulnerabilities in Enterprise Infrastructure
The discovery highlights the ongoing challenges of securing widely deployed network infrastructure. The rapid response from Citrix and national agencies underscores the severity of the threats posed by these flaws. Enterprises must prioritize patch management and monitor for signs of compromise, given the potential for significant operational disruption.
Conclusion
The exploitation of these vulnerabilities serves as a reminder of the importance of proactive security measures and the risks associated with delayed patching. Administrators are urged to apply the latest patches for affected NetScaler ADC and Gateway appliances immediately.
