Published on September 28, 2026
CISA Warns of Citrix NetScaler 0-Day RCE Vulnerabilities Exploited in Attacks
Severity
Critical
Detail
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) have added two Citrix NetScaler vulnerabilities, CVE-2026-88771 and CVE-2026-88772, to its Known Exploited Vulnerabilities (KEV) Catalog after confirming active exploitation in the wild. The vulnerabilities affect Citrix NetScaler ADC and NetScaler Gateway appliances and could allow unauthenticated attackers to compromise affected systems remotely.
The first vulnerability, CVE-2026-88771, is an improper input validation vulnerability that could allow a remote unauthenticated attacker to execute arbitrary commands on an affected NetScaler appliance. Given that NetScaler devices are commonly deployed as internet-facing infrastructure for remote access, application delivery, and VPN services, successful exploitation could provide attackers with a foothold within the target environment.
The second vulnerability, CVE-2026-88772, is an improper restriction of operations within the bounds of a memory buffer vulnerability. Successful exploitation may allow remote code execution or result in a denial-of-service (DoS) condition on vulnerable appliances.
CISA confirmed that both vulnerabilities are being actively exploited. However, details regarding the threat actors, targeted organizations, or associated campaigns have not been disclosed. Due to the active exploitation status and the critical role of NetScaler appliances within enterprise environments, organizations should prioritize remediation efforts and perform compromise assessments on affected systems.
| CVE ID | Summary | Severity |
| CVE-2026-88771 | An improper input validation vulnerability that could allow an unauthenticated remote attacker to execute arbitrary commands on affected Citrix NetScaler appliances. | 9.5 (Critical) |
| CVE-2026-88772 | A memory buffer vulnerability that could allow remote code execution or cause a denial-of-service condition on affected Citrix NetScaler appliances. | 9.5 (Critical) |
Affected Products
The vulnerabilities affect the following products:
- Citrix NetScaler ADC
- Citrix NetScaler Gateway
Recommendation
Organizations should implement the following measures immediately to reduce the risk of exploitation:
- Identify all internet-facing Citrix NetScaler ADC and NetScaler Gateway appliances within the environment.
- Apply Citrix vendor-recommended patches, updates, or mitigations as soon as they become available.
- Conduct forensic triage and compromise assessments on affected appliances, as exploitation has been observed in the wild.
- Review authentication logs, administrator account activity, configuration changes, and command execution history for signs of suspicious activity.
- Monitor for unusual outbound network connections and unauthorized modifications to appliance configurations.
- Restrict exposure of management interfaces to trusted administrative networks only.
- Follow CISA and Citrix guidance regarding remediation and incident response activities.
Source
https://cybersecuritynews.com/citrix-netscaler-0-day-rce-vulnerabilities-exploited/
https://www.cisa.gov/known-exploited-vulnerabilities-catalog
https://support.citrix.com/external/article/CTX697096/citrix-netscaler-adc-and-citrix-netscale.html
