Citrix has released security updates for two critical vulnerabilities in NetScaler ADC and NetScaler Gateway that it says have been exploited against unpatched devices. The flaws could allow remote attackers to execute commands or code on exposed appliances, which are commonly used for VPN access, authentication, and application delivery.
The company identified the issues as CVE-2026-88771 and CVE-2026-88772, each assigned a CVSS v4 score of 9.5. Citrix said it has observed exploitation on deployments that have not applied mitigations or updates, but did not disclose the responsible actors, the scale of activity, or when attacks began.
Exposure conditions
- CVE-2026-88771 is an input-validation issue that can permit unauthenticated command execution. Citrix said affected versions are vulnerable regardless of configuration.
- CVE-2026-88772 is a memory-overflow vulnerability that may result in remote code execution or a denial of service. It affects appliances with DTLS enabled, a setting that is enabled by default for many VPN virtual-server deployments.
The advisory follows reports from security researchers that they had encountered evidence of two previously undisclosed NetScaler remote-code-execution vulnerabilities during incident response work. Citrix did not explicitly confirm whether those reports referred to the same CVEs, though the descriptions align with the vendor's notice.
Recommended action
Citrix urged customers running affected customer-managed instances to update immediately. Fixed releases include NetScaler ADC and Gateway 14.1-73.37 and later, 13.1-64.23 and later 13.1 releases, plus corresponding updated FIPS and NDcPP builds. The company manages updates for its own cloud services and Citrix-managed Adaptive Authentication offerings.
The bulletin also addresses six additional flaws, including an HTTP request-smuggling issue and several memory-safety vulnerabilities. These were not listed as under active exploitation.
Organizations should treat patching as only one part of incident response where compromise is suspected. Citrix recommends preserving relevant logs and system evidence, isolating potentially affected appliances, rotating credentials and secrets held by the device, revoking exposed certificates and keys, and ensuring management interfaces are not publicly reachable. Administrators should also review authentication activity and network logs for indications that access may have been obtained before updates were installed.
