Citrix has confirmed that two critical NetScaler remote code execution vulnerabilities, CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks and has released security updates to address them. The flaws are the same zero-days that cybersecurity researchers, IT providers, and national cybersecurity agencies began warning organizations about privately over the weekend. The company published security bulletin CTX697096 confirming the vulnerabilities and releasing patches for affected NetScaler ADC and NetScaler Gateway appliances.
NetScaler appliances are high-value targets because organizations commonly deploy them as internet-facing edge devices that provide remote access and application delivery services for internal corporate networks. Compromising one can give attackers an initial foothold at the perimeter of a victim's network and potentially a path to internal systems without first breaching an endpoint inside the organization.
CVE-2026-88771 is a remote code execution flaw caused by improper input validation that allows an unauthenticated attacker to execute arbitrary commands, with a severity score of 9.5. Citrix says it affects all NetScaler ADC and NetScaler Gateway deployments, including those using the default configuration, and requires no additional feature to be enabled. CVE-2026-88772 is a memory overflow vulnerability that can lead to remote code execution or a denial-of-service condition, also scored 9.5. It can be exploited when DTLS is enabled on a NetScaler ADC or NetScaler Gateway, and Citrix notes DTLS is enabled by default on VPN virtual servers.
Citrix stated in the bulletin that exploits of both flaws have been observed on unmitigated NetScaler deployments. Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to recommended builds. The bulletin applies only to customer-managed NetScaler ADC and NetScaler Gateway appliances, while Cloud Software Group is upgrading Citrix-managed cloud services and Citrix-managed Adaptive Authentication.
The issue first surfaced when Citrix administrators reported on Reddit that IT suppliers and security teams were privately contacting their organizations and advising them to shut down NetScaler appliances. One administrator said an IT supplier's security team advised immediate shutdown without providing details. Others said law enforcement, CERTs, and national cybersecurity agencies had also contacted organizations. Cybersecurity firm watchTowr later publicly warned it was reacting to credible rumors of multiple unpatched Citrix NetScaler RCE vulnerabilities being exploited in the wild after verifying the information with authoritative sources.
Before Citrix disclosed the flaws, the Dutch National Cyber Security Center reportedly sent a pre-notification to organizations in the Netherlands about two critical NetScaler zero-days. Copies shared online said the agency received information from a European partner CERT about two vulnerabilities that could independently lead to remote code execution. According to the notice, one allowed attackers to place shellcode directly into memory, while technical details of the second were still being researched. At the time, no CVE identifiers had been assigned and Citrix had not published an advisory. The notification said Citrix discovered the vulnerabilities while investigating incidents in customer environments and identified active exploitation. The bulletin also fixes six other NetScaler vulnerabilities, bringing the total to eight flaws addressed in this update.
More cybersecurity news from TechManNews.








