
NetScaler appliances are an important part of many enterprise networks, providing VPN and remote access, load balancing and other application delivery services.
Agnidipta Sarkar, chief evangelist at ColorTokens, said, “RCE on these NetScaler deployments means an unauthenticated remote attacker can run arbitrary commands on the appliance itself, typically with high privileges. If that succeeds, attackers install persistent backdoors/webshells, modify configurations, disable logging, create rogue virtual servers, or brick/DOS the device.” They could also pivot into the internal network and reach Active Directory or other crown jewels, he added.
Citrix is tracking the two exploited vulnerabilities as CVE-2026-88771 and CVE-2026-88772. It has released fixes in NetScaler ADC and Gateway 14.1-73.37 and later, 13.1-64.23 and later, with corresponding FIPS and NDcPP builds also available.
