Citrix has released emergency security updates for NetScaler ADC and NetScaler Gateway after confirming that attackers are exploiting two critical remote code execution vulnerabilities against unmitigated appliances.
The flaws, CVE-2026-88771 and CVE-2026-88772, each carry a CVSS v4.0 score of 9.5 and can let remote, unauthenticated adversaries execute code, placing internet-facing gateways at immediate risk.
Because these appliances operate at the network edge and manage trusted traffic, a successful exploitation can create a strong foothold for lateral movement and credential theft.
The confirmation validates warnings covered yesterday by Cyber Security News, when watchTowr reported two previously undisclosed NetScaler RCE zero-days found during forensic investigations.
At that time, Citrix had not released CVE identifiers, affected builds, indicators of compromise, or patches, forcing some organizations to consider isolating exposed appliances while awaiting authoritative guidance.
NetScaler 0-Day RCE Exploited
CVE-2026-88771 results from improper input validation and can permit arbitrary command execution. Its exposure is unusually broad: every NetScaler ADC and NetScaler Gateway deployment is affected, including default configurations, with no optional feature required.
CVE-2026-88772 is a memory-overflow flaw capable of causing RCE or denial of service when DTLS is enabled; DTLS is enabled by default on VPN virtual servers.
The bulletin addresses six additional vulnerabilities. CVE-2026-88773, rated 9.3, enables HTTP request smuggling in deployments using HTTP configurations.
CVE-2026-88774, scored 7.0, involves policy bypass through improper HTTP URL-based expressions, potentially allowing non-normalized URLs to evade WAF or security rules.
Three 8.8-rated memory-overflow flaws—CVE-2026-88775, CVE-2026-88776 and CVE-2026-88777—affect Gateway or AAA virtual servers, Oracle load-balancing virtual servers, and LB/CS or CGNAT-LSN/NAT64 devices using non-HTTP Layer 7 features, respectively.
CVE-2026-88778, also rated 8.8, permits TCP initial sequence number prediction when Enhanced ISN Generation is disabled on relevant TCP configurations.
Administrators should upgrade immediately to NetScaler ADC and Gateway 14.1-73.37 or later, or 13.1-64.23 or later. Fixed specialized builds are 14.1-73.37 FIPS and 13.1-37.279 for FIPS and NDcPP deployments.
Because CVE-2026-88771 affects default installations, configuration-based exposure reduction cannot replace patching. Teams should still inspect configurations for DTLS, HTTP or SSL virtual servers, Gateway and AAA services, Oracle load balancing, non-HTTP Layer 7 protocols, and disabled Enhanced ISN Generation.
| CVE ID | Vulnerability | Technical impact | Required configuration | CVSS v4.0 | Exploited |
|---|---|---|---|---|---|
| CVE-2026-88771 | Improper input validation | Unauthenticated attackers can execute arbitrary commands remotely | All deployments, including default configurations; no additional feature required | 9.5 Critical | Yes |
| CVE-2026-88772 | Memory overflow | Remote code execution or denial of service | DTLS enabled; DTLS is enabled by default on VPN virtual servers | 9.5 Critical | Yes |
| CVE-2026-88773 | HTTP request smuggling | Enables conflicting HTTP request interpretation, potentially affecting downstream systems | HTTP configuration enabled, including applicable HTTP or SSL virtual servers | 9.3 Critical | Not reported |
| CVE-2026-88774 | HTTP URL policy bypass | Non-normalized URLs may bypass WAF policies or other URL-based security rules | Policy configured with an HTTP URL-based expression | 7.0 High | Not reported |
| CVE-2026-88775 | Memory overflow | Unpredictable behavior, memory corruption or denial of service | Gateway services, including SSL VPN, ICA Proxy, CVPN and RDP Proxy, or an AAA virtual server | 8.8 High | Not reported |
| CVE-2026-88776 | Memory overflow | Unpredictable behavior, memory corruption or denial of service | Load-balancing virtual server configured with the Oracle protocol | 8.8 High | Not reported |
| CVE-2026-88777 | Memory overflow | Unpredictable behavior, memory corruption or denial of service | LB/CS or CGNAT-LSN/NAT64 deployment using a non-HTTP Layer 7 protocol feature | 8.8 High | Not reported |
| CVE-2026-88778 | Predictable TCP initial sequence numbers | May enable TCP connection prediction, manipulation or related network attacks | Relevant TCP virtual server configured and Enhanced ISN Generation disabled | 8.8 High | Not reported |
Citrix is providing generic indicators of compromise through NetScaler Console’s Security Advisory workflow. The capability requires telemetry and is available through the Console service and on-premises Console with Cloud Connect, beginning with version 14.1-73.36.
Citrix cautions that these checks cannot cover every attacker technique and may miss compromises; organizations finding suspicious activity should preserve evidence and engage qualified forensic responders. Logs should be forwarded to an external SIEM, while File Integrity Monitoring can help identify unauthorized changes.
A deployment running 13.1-64.23 may enter a reboot loop during upgrade when NetScaler variables are configured. Administrators can run show ns variable; if variables are returned, Citrix advises planning for 13.1-64.24. The Console may also temporarily mislabel 13.1-64.23 as vulnerable.
Given confirmed exploitation, defenders should treat the update as an incident-response priority, not routine patch management. Patch every node, verify the running build, scan for compromise, review authentication and network activity, and investigate unexpected files, processes, configuration changes or outbound connections.
Updating closes the vulnerabilities, but it does not remove persistence or other artifacts left by attackers who exploited an appliance before remediation.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

