Citrix Confirms Exploitation of Two Critical NetScaler RCE Flaws, CVE-2026-88771 and CVE-2026-88772, as CISA Adds Both to KEV Catalog
Citrix confirmed exploitation of two critical NetScaler ADC and Gateway flaws, both CVSS v4 9.5, and shipped fixes; CISA added both to its KEV catalog as of September 27, 2026.
Overview
Citrix has confirmed that two critical remote-code-execution vulnerabilities in NetScaler ADC and NetScaler Gateway have been exploited in the wild, according to The Hacker News. Citrix confirmed this on September 27 and released fixes for both, along with six other flaws. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added both to its Known Exploited Vulnerabilities catalog as of September 27, 2026.
What We Know
- CVE-2026-88771 carries a CVSS v4 score of 9.5. It is an improper input validation flaw that lets an unauthenticated attacker run arbitrary commands, and it affects all NetScaler ADC and NetScaler Gateway deployments with no extra feature required, per The Hacker News.
- CVE-2026-88772 also scores 9.5 on CVSS v4. It is a memory overflow that can lead to remote code execution or denial-of-service on appliances with DTLS enabled. The same report says DTLS is on by default for VPN virtual servers, so a NetScaler Gateway is affected unless DTLS has been explicitly turned off.
- Citrix said, in the words quoted by The Hacker News, “Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed.” According to The Hacker News, Citrix did not say how widely the flaws have been exploited, by whom, or since when.
- CISA said: “CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally,” as reported by The Hacker News. Federal Civilian Executive Branch agencies were given until September 30, 2026, to apply the fixes.
- Appliances on builds 14.1-73.32 and 13.1-63.21, the versions that fixed the exploited authentication bypass CVE-2026-19490 in August, fall inside the affected range, according to The Hacker News.
Fixed Versions
Per The Hacker News, the fixed releases are:
- NetScaler ADC and NetScaler Gateway 14.1-73.37 and later releases
- NetScaler ADC and NetScaler Gateway 13.1-64.23 and later releases of 13.1
- NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
- NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later releases of 13.1-FIPS and 13.1-NDcPP
The same report lists six additional flaws fixed in the update, CVE-2026-88773 through CVE-2026-88778, with CVSS v4 scores ranging from 7.0 to 9.3. They include an HTTP request smuggling flaw (CVE-2026-88773, 9.3) and a TCP Initial Sequence Number prediction flaw (CVE-2026-88778, 8.8).
Technical Details and Exposure
The Hacker News reports that watchTowr Labs, on September 28, 2026, said CVE-2026-88771 is rooted in a Perl script named “ns_monuploadd_err.pl” that processes NetScaler crash and error information. According to that report, the script constructs a shell command using input an attacker can influence, resulting in remote code execution as root, and the flaw can be triggered by a pre-authentication request to the “/nf/auth/doAuthentication.do” endpoint.
Palo Alto Networks’ Unit 42 wrote in its threat brief: “As of Sept. 27, 2026, Palo Alto Networks Cortex Xpanse has identified 50,277 exposed instances that could potentially be vulnerable to these CVEs based on our telemetry.”
The Hacker News, citing GreyNoise, reports that the earliest known exploitation attempt against its sensor occurred on September 24, and that the attempt was unsuccessful.
Advance Warnings
The Hacker News reports that watchTowr’s first post on X on September 26 said it was reacting to rumors of several unpatched NetScaler RCE vulnerabilities in the wild, writing “While details are scarce, the information is credible.” The report adds that Citrix did not say whether its two flaws are the ones watchTowr described, but that they match that account.
The same report says an administrator posting on r/Citrix on September 26 wrote that their IT supplier’s security team had advised shutting NetScalers down immediately, and that others in the thread said their organizations had done the same. Where the suppliers’ warning came from has not been established, according to the report.
Guidance for Administrators
According to The Hacker News, Citrix has made generic indicators of compromise available through NetScaler Console. If compromise is suspected, the recommended steps include preserving evidence of the NetScaler ADC VPX instance and rotating all local account passwords and Key Encryption Keys. Citrix’s existing guidance, quoted by The Hacker News, states: “The NetScaler Management Services should never be exposed to the public internet.”
What We Don’t Know
- How many appliances have actually been compromised, who is behind the exploitation, and when it began. Citrix has not said, per The Hacker News.
- Whether the flaws Citrix patched are the same ones watchTowr described on September 26; the report says only that they match that account.
Context
NetScaler has drawn attention before. The Machine Herald previously reported on reconnaissance activity against an earlier critical NetScaler flaw, CVE-2026-3055, in March. In the present case, Citrix itself reports that exploitation has been observed.