Critical Citrix NetScaler Vulnerabilities Exploited in Attacks
Key Takeaways Citrix has issued urgent security updates for NetScaler ADC and Gateway products. Two critical remote code execution (RCE) vulnerabilities, CVE-2026-88771 and CVE-2026-88772, are...
Key Takeaways
- Citrix has issued urgent security updates for NetScaler ADC and Gateway products.
- Two critical remote code execution (RCE) vulnerabilities, CVE-2026-88771 and CVE-2026-88772, are actively being exploited in the wild.
- These flaws, rated 9.5 CVSS v4.0, allow unauthenticated attackers to execute arbitrary code on internet-facing devices.
- All NetScaler ADC and Gateway deployments are affected by CVE-2026-88771, including default configurations.
- Immediate patching is crucial, along with comprehensive post-patching security checks, as updates do not remove existing compromises.
Citrix Issues Emergency Patches as Critical NetScaler Zero-Days Under Active Exploitation
Citrix has released emergency security updates for its NetScaler ADC and NetScaler Gateway products, confirming that threat actors are actively exploiting two critical remote code execution (RCE) vulnerabilities against unpatched appliances. These severe flaws pose an immediate and significant risk to organizations utilizing these widely deployed network edge devices.
Table Of Content
The vulnerabilities, identified as CVE-2026-88771 and CVE-2026-88772, each carry a CVSS v4.0 severity score of 9.5. They enable remote, unauthenticated attackers to execute arbitrary code, making internet-facing gateways particularly vulnerable. Given that these appliances sit at the network perimeter and handle trusted traffic, a successful exploit can provide attackers with a critical foothold for lateral movement within a network and potential credential theft.
This confirmation validates earlier warnings, including reports from watchTowr, which had identified two previously undisclosed NetScaler RCE zero-days during forensic investigations. At the time of those initial reports, Citrix had not yet provided CVE identifiers, affected build numbers, indicators of compromise (IoCs), or patches, leaving some organizations to consider isolating exposed appliances while awaiting official guidance.
Deep Dive into the Exploited Vulnerabilities
CVE-2026-88771 stems from improper input validation, which can lead to arbitrary command execution. This vulnerability is particularly concerning due to its broad exposure: every NetScaler ADC and NetScaler Gateway deployment is affected, including default configurations, without requiring any specific optional features to be enabled.
CVE-2026-88772 is a memory-overflow flaw. When DTLS (Datagram Transport Layer Security) is enabled, this vulnerability can lead to remote code execution or denial of service. DTLS is enabled by default on VPN virtual servers, increasing the attack surface for many deployments.
Additional Vulnerabilities Addressed
Beyond the two actively exploited flaws, the recent security bulletin addresses six other vulnerabilities:
- CVE-2026-88773, rated 9.3 (Critical), involves HTTP request smuggling in deployments using HTTP configurations, potentially leading to conflicting interpretations of HTTP requests.
- CVE-2026-88774, scored 7.0 (High), is a policy bypass vulnerability related to improper HTTP URL-based expressions. This could allow non-normalized URLs to circumvent Web Application Firewall (WAF) rules or other security policies.
- Three memory-overflow flaws—CVE-2026-88775, CVE-2026-88776, and CVE-2026-88777—are all rated 8.8 (High). These affect Gateway or AAA virtual servers, Oracle load-balancing virtual servers, and LB/CS or CGNAT-LSN/NAT64 devices utilizing non-HTTP Layer 7 features, respectively.
- CVE-2026-88778, also rated 8.8 (High), allows for TCP initial sequence number prediction when Enhanced ISN Generation is disabled on relevant TCP configurations, potentially enabling TCP connection manipulation or related network attacks.
Patching and Mitigation Details
Administrators are urged to upgrade their NetScaler ADC and Gateway installations immediately to versions 14.1-73.37 or later, or 13.1-64.23 or later. Specialized builds for FIPS and NDcPP deployments, specifically 14.1-73.37 FIPS and 13.1-37.279, are also available. Since CVE-2026-88771 impacts default installations, relying solely on configuration changes for exposure reduction is insufficient; patching is absolutely essential.
While patching is paramount, organizations should still review their configurations for DTLS, HTTP or SSL virtual servers, Gateway and AAA services, Oracle load balancing, non-HTTP Layer 7 protocols, and instances where Enhanced ISN Generation is disabled.
Citrix provides generic indicators of compromise (IoCs) through NetScaler Console’s Security Advisory workflow. This feature requires telemetry and is accessible via the Console service and on-premises Console with Cloud Connect, starting with version 14.1-73.36.
Citrix cautions that these checks may not identify all attacker techniques and could miss certain compromises. Organizations detecting suspicious activity should preserve evidence and engage qualified forensic responders. Forwarding logs to an external SIEM and employing File Integrity Monitoring can help detect unauthorized changes.
A specific issue has been noted where a deployment running 13.1-64.23 might enter a reboot loop during an upgrade if NetScaler variables are configured. If show ns variable returns variables, Citrix advises planning for an upgrade to 13.1-64.24 instead. Additionally, the Console may temporarily mislabel 13.1-64.23 as vulnerable.
Given the confirmed active exploitation, defenders must treat this update as an incident-response priority rather than routine patch management. Installing the update closes the vulnerabilities, but it does not remove any persistence mechanisms or other artifacts left by attackers who may have already compromised an appliance prior to remediation.
What You Should Do
- Immediately Patch: Upgrade all NetScaler ADC and NetScaler Gateway instances to the latest secure versions: 14.1-73.37 or later, or 13.1-64.23 or later. For FIPS and NDcPP deployments, use 14.1-73.37 FIPS and 13.1-37.279.
- Verify Patch Application: After patching, confirm that the new build is correctly running on every node.
- Scan for Compromise: Utilize available IoCs and conduct thorough scans to detect any signs of pre-existing compromise.
- Review Activity Logs: Scrutinize authentication logs and network activity for any unusual or unauthorized access attempts.
- Investigate Anomalies: Look for unexpected files, rogue processes, unauthorized configuration changes, or suspicious outbound network connections on affected appliances.
- Enable Telemetry and IoC Checks: Leverage NetScaler Console’s Security Advisory workflow with telemetry enabled to monitor for generic indicators of compromise.
- Enhance Monitoring: Ensure logs are forwarded to an external SIEM and implement File Integrity Monitoring (FIM) to detect unauthorized modifications.
- Plan for Reboot Loop: If running 13.1-64.23 and
show ns variablereturns variables, plan to upgrade to 13.1-64.24 to avoid potential reboot loops. - Engage Forensic Experts: If any suspicious activity or compromise is detected, preserve all evidence and engage qualified forensic incident response teams.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.