DarkReading

CVE-2026-88771 & CVE-2026-88772: NetScaler Flaws Exploited


Citrix has released fixes for two critical remote code execution flaws in NetScaler ADC and NetScaler Gateway, tracked as CVE-2026-88771 and CVE-2026-88772. On September 27, the company confirmed that attackers had already exploited both in the wild. The same update addresses six other vulnerabilities. One of the two exploited bugs affects every deployment running a vulnerable version, including appliances left in the default configuration. 

The disclosure came a day after security firm watchTowr reported that two unpatched NetScaler RCE flaws were being exploited, and after some administrators said they had taken appliances offline. Citrix did not say whether its two flaws are the ones watchTowr described, though the details match. 

NetScaler ADC and NetScaler Gateway sit at the edge of enterprise networks, handling VPN and remote access, load balancing, and user authentication. 

How CVE-2026-88771 and CVE-2026-88772 Work 

CVE-2026-88771, rated 9.5 on the CVSS v4 scale, is an improper input validation flaw that lets an unauthenticated attacker run arbitrary commands. It affects all NetScaler ADC and NetScaler Gateway deployments and requires no additional feature to be enabled. 

CVE-2026-88772, also rated 9.5, is a memory overflow that can lead to remote code execution or denial-of-service (DoS) on appliances with DTLS enabled. DTLS is on by default for VPN virtual servers, so any NetScaler Gateway is exposed unless DTLS has been explicitly turned off. 

“Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed,” Citrix said. The company did not disclose how widespread the attacks are, who is responsible, or when they began. 

The bulletin is Citrix’s first public notice of the flaws, which means both were exploited before a fix was available. It lists no workarounds and no indicators of compromise. 

Fixed NetScaler Versions 

Appliances running 14.1-73.32 and 13.1-63.21 fall within the affected range and need the new update. Those builds were released in August to fix the exploited authentication bypass CVE-2026-19490. 

Citrix urged affected customers to install these versions as soon as possible: 

  • NetScaler ADC and NetScaler Gateway 14.1-73.37 and later releases 
  • NetScaler ADC and NetScaler Gateway 13.1-64.23 and later releases of 13.1 
  • NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS 
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later releases of 13.1-FIPS and 13.1-NDcPP 

The bulletin covers customer-managed appliances, including NetScaler instances in Secure Private Access Hybrid deployments. Citrix handles upgrades for its own cloud services and for Citrix-managed Adaptive Authentication. The 13.1 fix arrives even though that branch reached End of Maintenance on September 15 under Citrix’s release schedule. 

Six Other Flaws 

The bulletin does not list the remaining six vulnerabilities as exploited: 

  • CVE-2026-88773 (9.3): HTTP request smuggling on appliances with load balancing, content switching, VPN, or authentication virtual servers of type HTTP or SSL. 
  • CVE-2026-88774 (7.0): A policy bypass on appliances where any policy uses an HTTP URL-based expression. 
  • CVE-2026-88775 (8.8): A memory overflow that can cause unpredictable behavior or DoS on appliances configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or as an authentication, authorization, and auditing (AAA) virtual server. 
  • CVE-2026-88776 (8.8): A memory overflow that can cause unpredictable behavior or DoS on load balancing virtual servers of type Oracle. 
  • CVE-2026-88777 (8.8): A memory overflow that can cause unpredictable behavior or DoS on load balancing, content switching, or CGNAT-LSN/NAT64 setups with a non-HTTP Layer 7 protocol feature, such as FTP, RTSP, or DNS64, enabled. 
  • CVE-2026-88778 (8.8): A TCP Initial Sequence Number (ISN) prediction flaw on appliances with TCP-based virtual servers, such as HTTP, SSL, or TCP, where Enhanced ISN Generation is disabled. Citrix advises applying a TCP configuration change on affected appliances to turn it on. 



Source link