CVE-2026-88771(citrix / netscaler_application_delivery_controller)

LOWCVSS 9.8 · CRITICALCISA KEV

Signal is active with 74 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.

0.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-09-30. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • netscaler_application_delivery_controller
  • netscaler_gateway

Threat summary

  • 158 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 84 mentions (2026-09-27); latest day: 74
  • 158 total mentions across 2 days

Affected systems

Vendors
Products
netscaler_application_delivery_controllernetscaler_gateway

Deep dive

Activity timeline158 mentions / 2d
021426384Mentions · 2026-09-27: 84Mentions · 2026-09-28: 7409-2709-28
Referenced assets98 URLs
By indicator
Full discourse20 posts
  • The Hacker News@TheHackersNews

    ‼️ BREAKING: Citrix confirms two NetScaler flaws have been exploited and has released fixes. CVE-2026-88771 and CVE-2026-88772 were observed exploited on unmitigated deployments. The new advisory covers eight CVEs affecting NetScaler ADC and Gateway. New Details → https://thehackernews.com/2026/09/warning-two-unpatched-citrix-netscaler.html

    98773297358.7K
    2.4M followersView on X
  • Citrix@citrix

    Please see our latest Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778. Citrix urges affected customers to install the relevant updated versions as soon as possible. https://bit.ly/3T4RXGY

    9120252108079.1K
    197.2K followersView on X
  • Steven Lim@0x534c

    ⚠️ 𝗨𝗿𝗴𝗲𝗻𝘁: 𝗣𝗮𝘁𝗰𝗵 𝗡𝗲𝘁𝗦𝗰𝗮𝗹𝗲𝗿 𝗔𝗗𝗖/𝗚𝗮𝘁𝗲𝘄𝗮𝘆 𝗳𝗼𝗿 𝗔𝗰𝘁𝗶𝘃𝗲𝗹𝘆 𝗘𝘅𝗽𝗹𝗼𝗶𝘁𝗲𝗱 𝗩𝘂𝗹𝗻𝗲𝗿𝗮𝗯𝗶𝗹𝗶𝘁𝗶𝗲𝘀 ​ Citrix has confirmed active exploitation of 𝗖𝗩𝗘-𝟮𝟬𝟮𝟲-𝟴𝟴𝟳𝟳𝟭 and 𝗖𝗩𝗘-𝟮𝟬𝟮𝟲-𝟴𝟴𝟳𝟳𝟮 on unpatched NetScaler deployments and strongly recommends that affected customers upgrade to the latest fixed versions immediately. https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/​ To help security teams assess potential exposure, the KQL query below leverages 𝗠𝗶𝗰𝗿𝗼𝘀𝗼𝗳𝘁 𝗗𝗲𝗳𝗲𝗻𝗱𝗲𝗿 𝗳𝗼𝗿 𝗘𝗻𝗱𝗽𝗼𝗶𝗻𝘁 (𝗠𝗗𝗘) 𝗱𝗲𝘃𝗶𝗰𝗲 𝗱𝗶𝘀𝗰𝗼𝘃𝗲𝗿𝘆 𝘁𝗲𝗹𝗲𝗺𝗲𝘁𝗿𝘆 to identify NetScaler appliances within your environment, enabling faster validation and remediation actions. 🫡 https://github.com/SlimKQL/Detections.AI/blob/main/KQL/citrix-netscaler-check.kql ​ #MicrosoftDefender #CitrixNetScaler #VulnerabilityManagement #ThreatHunting #ZeroDay

    212069406.1K
    7.7K followersView on X
  • Dark Web Informer@DarkWebInformer

    ‼️ Citrix has released a security bulletin regarding zero-day attacks targeting Citrix NetScaler ADC and Citrix NetScaler Gateway. More info: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096 CVEs: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778

    3170641911.2K
    240.3K followersView on X
  • KevTheHermit@KevTheHermit

    Spent a few hours with @craigsblackie and a healthy dose of @claudeai reviewing the recent Citrix Vulns; took a while but between us and the agents we managed to replicate what we think is the RCE CVE-2026-88771 https://t.co/aq63vzgrxG

    314065205.0K
    4.2K followersView on X
  • The Hacker News@TheHackersNews

    ⚠️ CISA says attackers are actively exploiting two critical Citrix NetScaler flaws globally. CVE-2026-88771 can allow unauthenticated command execution. CVE-2026-88772 can enable RCE when DTLS is enabled. Citrix has fixes and IoCs. Read: https://thehackernews.com/2026/09/cisa-says-attackers-are-exploiting-two.html

    5212601319.6K
    2.4M followersView on X
  • Censys@censysio

    Citrix has released a security bulletin for 8 vulnerabilities in NetScaler ADC and NetScaler Gateway (CVE-2026-88771 through CVE-2026-88778). Censys currently observes ~37K internet-facing hosts serving ~285K NetScaler web endpoints worldwide. Review Citrix's guidance and remediate: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096 #CensysARC

    317149227.1K
    12.6K followersView on X
  • watchTowr@watchtowrcyber

    CVE-2026-88771 - the loaded Citrix footgun went off again, and the screaming noise is back in our ear. You knew it was coming - enjoy the latest watchTowr Labs blogpost. https://labs.watchtowr.com/oh-look-the-foot-gun-went-off-again-citrix-netscaler-preauth-command-injection-cve-2026-88771/

    220246152.0K
    13.6K followersView on X
  • Bert-Jan 🛡️@BertJanCyber

    Official comms and patches from Citrix are out! Exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments has been observed. https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/

    117144155.0K
    4.6K followersView on X
  • watchTowr@watchtowrcyber

    We hope you’ve enjoyed this episode of “no way? vulns? in SECURITY appliances? there is no proof” watchTowr Platform clients have access to this info every day - preempting, validating, mitigating exposure to emerging threats. Speak.. soon… ;-) xoxo https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/

    21104464.0K
    13.6K followersView on X
  • ExploitGrid@exploitgrid

    🚨 Citrix has confirmed active exploitation of two NetScaler RCE flaws. CVE-2026-88771 | CVSS 9.5 CVE-2026-88772 | CVSS 9.5 8 vulnerabilities disclosed. Patches are now available. 🔎 CVE-2026-88771: https://exploitgrid.net/vulnerabilities/CVE-2026-88771 CVE-2026-88772: https://exploitgrid.net/vulnerabilities/CVE-2026-88772

    13141103.5K
    127 followersView on X
  • ᴅᴀɴɪᴇʟ ᴍɪᴇssʟᴇʀ 🛡️@DanielMiessler

    Citrix confirmed two new NetScaler zero-days, CVE-2026-88771 and CVE-2026-88772, both CVSS 9.5 and exploited before patches were available. https://securityaffairs.com/199873/security/citrix-confirmed-two-new-netscaler-flaws-exploited-as-zero-day.html

    2512544.3K
    159.8K followersView on X
  • EZ@IAMERICAbooted

    CVE-2026-88771: All NetScaler ADC and NetScaler Gateway deployments are affected - Unauthenticated Remote Code Execution - already exploited in the wild

    1402643.4K
    3.3K followersView on X
  • mRr3b00t@UK_Daniel_Card

    Citrix netscaler patches https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/

    0801942.9K
    125.8K followersView on X
  • BleepingComputer@BleepinComputer

    Citrix has confirmed that two critical NetScaler remote code execution vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks. They have now released security updates. Our article is updated, and the Citrix advisory is here: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096

    11201324.4K
    258.7K followersView on X
  • The Hacker News@TheHackersNews

    The broader update includes flaws that can lead to remote code execution, denial of service, HTTP request smuggling, policy bypass, and TCP initial sequence number prediction under specific conditions. Only CVE-2026-88771 and CVE-2026-88772 are confirmed exploited. https://t.co/taRQw0NXT9

    1402027.2K
    2.4M followersView on X
  • Dark Web Intelligence@DailyDarkWeb

    🚨 CITRIX NETSCALER — OFFICIAL PATCHES FOR TWO EXPLOITED RCE ZERO-DAYS (CVE-2026-88771 / CVE-2026-88772) Cloud Software Group (Citrix) published security bulletin CTX697096 covering eight NetScaler ADC / NetScaler Gateway flaws, including two critical remote code execution vulnerabilities that the vendor says have been exploited on unmitigated deployments. Lead issues (vendor CVSS v4 Base Score 9.5 each): • CVE-2026-88771 — Improper input validation → unauthenticated remote command execution. Affects ALL NetScaler ADC and NetScaler Gateway deployments, including default configuration (no extra features required). • CVE-2026-88772 — Memory overflow → remote code execution or denial of service when DTLS is enabled (DTLS is enabled by default on VPN virtual servers unless explicitly set to OFF). Fixed builds (install ASAP): • NetScaler ADC / Gateway 14.1-73.37 and later • NetScaler ADC / Gateway 13.1-64.23 and later (13.1) • NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later • NetScaler ADC 13.1-FIPS / 13.1-NDcPP 13.1.37.279 and later Also addressed in the same bulletin: CVE-2026-88773 through CVE-2026-88778 (HTTP request smuggling, policy bypass, additional memory overflows, TCP ISN prediction). ⚠️ Analyst Note: This is the official Citrix confirmation + patch set for the weekend’s unpatched NetScaler RCE warnings. Separate from the earlier auth-bypass CVE-2026-19490 (Aug builds 14.1-73.32 / 13.1-63.21 do NOT include these new fixes). Vendor wording: “Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed.” No public attribution, victim count, or full IOC package in the bulletin at publish time. Patching alone does not prove a previously exposed appliance was clean — treat internet-facing units as potentially compromised until forensics say otherwise. CISA had not listed CVE-2026-88771 / CVE-2026-88772 in KEV as of this post (catalog still 2026.09.25). Prefer the Citrix bulletin over secondary media. Official Citrix bulletin (CTX697096): https://support.citrix.com/external/article/CTX697096/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-and-cve-2026-88772.html #Citrix #NetScaler #ZeroDay #RCE #CVE202688771 #CVE202688772 #Vulnerability #CyberSecurity #ThreatIntel #DDW

    0102135.8K
    205.1K followersView on X
  • Manuel Winkel@Deyda84

    Citrix confirms exploitation of CVE-2026-88771 and CVE-2026-88772. My updated NetScaler checklist covers all eight CVEs and includes a read-only triage script. A clean scan does not prove an appliance is uncompromised. https://www.deyda.net/index.php/de/2026/08/28/netscaler-cve-checkliste-updates-sicherheitspruefung-und-incident-response/ #DeydaConsulting #NetScaler #Citrix

    1401361.4K
    1.4K followersView on X
  • Cristian Borghello@SeguInfo

    Utilizas Citrix NetScaler ADC y NetScaler Gateway? FELIZ DOMINGO! Expotación activa de CVE-2026-88771 y CVE-2026-88772 permite RCE en el dispositivo. PARCHEA! https://blog.segu-info.com.ar/2026/09/explotacion-activa-de-dos-zero-day-rce.html

    0411712.1K
    38.3K followersView on X
  • FOFA@fofabot

    ⚠️⚠️ CVE-2026-88771 (CVSS 9.5) + CVE-2026-88772 (CVSS 9.5): Citrix NetScaler ADC/Gateway zero-day RCE — now actively exploited in the wild 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJOZXRTY2FsZXItQUFBIg== 🎯42.7K+ Results are found on http://en.fofa.info in the past year. FOFA Query: app="NetScaler-AAA" 🔖Refer: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096 #OSINT #FOFA #CyberSecurity #Vulnerability

    1601051.4K
    14.8K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appcitrixnetscaler_application_delivery_controller---
Appcitrixnetscaler_application_delivery_controller---
Appcitrixnetscaler_application_delivery_controller---
Appcitrixnetscaler_gateway---

Explore more