Desktop virtualisation vendor Citrix has confirmed alerts appearing over the weekend saying its Netscaler Application Deliver Controller (ADC) and Gateway devices are under active attacks by threat actors, and has issued urgent updates for the vulnerabilities.
The most serious vulnerability is tracked as CVE-2026-88771 and is rated as 9.5 out of 10.0 possible.
It allows for remote code execution (RCE) that allows attackers to run arbitrary commands with no configuration preconditions required.
Another 9.5 vulnerability (CVE-2026-88772) affects devices with datagram transport layer security (DTLS) enabled and is a memory overflow bug that allows for RCE or denial of service (DoS).
DTLS is enabled on Citrix Netscaler Gateways by default.
A further six zero-days, rated 7.0 to 9.3 were also disclosed by Citrix.
Along with cyber defence agencies in the European Union, Citrix has confirmed the above two vulnerabilities are actively exploited currently.
Affected versions include:
- Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 BEFORE 14.1-73.37
- Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 BEFORE 13.1-64.23
- Citrix NetScaler ADC FIPS BEFORE 14.1-73.37 FIPS
- Citrix NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.279
The United States Cybersecurity and Infrastructure Security Agency (CISA) has added the flaws to its Known Exploited Vulnerabilities (KEV) catalogue of must-fix items for US government entities.
As of writing, the extent of the exploitation is not known, with administrators sharing information about the incident on the Reddit online forum.
In guidance released Monday morning, the Australian Signals Directorate (ASD) recommended “that organisations operating vulnerable Citrix products, review details of the vulnerabilities released by the vendor and install the security update.”
“Organisations should consider internal security assessments and business plans, in determining how to effectively prioritise the implementation of this security update,” ASD wrote.
“In addition to applying the security update, organisations should review the pre-condition requirements for each of the CVEs to understand where they may have been vulnerable to exploitation.”
It added that organisations should review “device logging for any suspicious activity, which is consistent with the kinds of attacks enabled by each of the CVE’s where the pre-conditions for exploitation have been met.”

