Citrix: Citrix NetScaler Hit by Two Critical RCE Flaws Already Under Attack

Citrix: Citrix NetScaler Hit by Two Critical RCE Flaws Already Under Attack

Citrix Patches Two Actively Exploited Critical RCE Flaws in NetScaler ADC and Gateway

Citrix has released emergency fixes for two critical remote code execution (RCE) vulnerabilities CVE-2026-88771 and CVE-2026-88772 affecting NetScaler ADC and NetScaler Gateway, both of which were confirmed to be exploited in the wild as of September 27. The update also addresses six additional flaws, though none are reported as actively targeted.

The vulnerabilities impact enterprise deployments handling VPN, remote access, load balancing, and authentication, leaving unpatched systems exposed to arbitrary command execution and denial-of-service (DoS) attacks. CVE-2026-88771 (CVSS 9.5) stems from improper input validation, allowing unauthenticated attackers to execute commands without requiring additional configurations. CVE-2026-88772 (CVSS 9.5) is a memory overflow flaw affecting appliances with DTLS enabled, which is active by default for VPN virtual servers.

Citrix’s disclosure followed reports from security firm watchTowr, which identified exploitation of unpatched NetScaler RCE flaws, though the company did not confirm whether these were the same vulnerabilities. Administrators had already taken some appliances offline in response to the threats. Citrix provided no details on the scale, origin, or timeline of the attacks, nor did it offer workarounds or indicators of compromise.

Affected Versions and Fixes
The vulnerabilities impact NetScaler ADC and Gateway versions 14.1-73.32 and 13.1-63.21, with patches available in:

  • 14.1-73.37 and later
  • 13.1-64.23 and later (despite the 13.1 branch reaching End of Maintenance on September 15)
  • FIPS and NDcPP-specific releases for secure environments

The update also resolves six other vulnerabilities, including HTTP request smuggling (CVE-2026-88773, CVSS 9.3), policy bypasses, and memory overflows in various configurations. Citrix emphasized that customer-managed appliances must be updated manually, while cloud and managed services are handled internally.

Source: https://thecyberexpress.com/citrix-netscaler-cve-2026-88771-cve-2026-88772/

Citrix TPRM report: https://www.rankiteo.com/company/citrix

"id": "cit1790684635",
"linkid": "citrix",
"type": "Vulnerability",
"date": "9/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': 'Enterprise deployments using '
                                              'NetScaler ADC and Gateway',
                        'industry': 'Software, Networking, Cybersecurity',
                        'name': 'Citrix',
                        'type': 'Technology Company'}],
 'attack_vector': 'Improper input validation, Memory overflow (DTLS enabled)',
 'date_detected': '2026-09-27',
 'date_publicly_disclosed': '2026-09-27',
 'description': 'Citrix has released emergency fixes for two critical remote '
                'code execution (RCE) vulnerabilities CVE-2026-88771 and '
                'CVE-2026-88772 affecting NetScaler ADC and NetScaler Gateway, '
                'both of which were confirmed to be exploited in the wild as '
                'of September 27. The vulnerabilities impact enterprise '
                'deployments handling VPN, remote access, load balancing, and '
                'authentication, leaving unpatched systems exposed to '
                'arbitrary command execution and denial-of-service (DoS) '
                'attacks.',
 'impact': {'operational_impact': 'Arbitrary command execution, '
                                  'Denial-of-Service (DoS) attacks',
            'systems_affected': 'NetScaler ADC and NetScaler Gateway'},
 'investigation_status': 'Ongoing',
 'post_incident_analysis': {'corrective_actions': 'Patches released, manual '
                                                  'updates required for '
                                                  'customer-managed appliances',
                            'root_causes': 'Improper input validation '
                                           '(CVE-2026-88771), Memory overflow '
                                           'in DTLS (CVE-2026-88772)'},
 'recommendations': 'Update to patched versions (14.1-73.37+, 13.1-64.23+) '
                    'immediately. Disable DTLS if not required.',
 'references': [{'source': 'Citrix Security Bulletin'},
                {'source': 'watchTowr'}],
 'response': {'containment_measures': 'Administrators took some appliances '
                                      'offline',
              'remediation_measures': 'Patches released for affected versions',
              'third_party_assistance': 'watchTowr (security firm)'},
 'title': 'Citrix Patches Two Actively Exploited Critical RCE Flaws in '
          'NetScaler ADC and Gateway',
 'type': 'Remote Code Execution (RCE)',
 'vulnerability_exploited': ['CVE-2026-88771', 'CVE-2026-88772']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.