CVE-2026-88772(citrix / netscaler_application_delivery_controller)

LOWCVSS 8.1 · HIGHCISA KEV

Signal is active with 58 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service

0.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-09-30. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weakness type (CWE)
CWE-119

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • netscaler_application_delivery_controller
  • netscaler_gateway

Threat summary

  • 109 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked at 58 mentions on most recent observed day (2026-09-28)
  • 109 total mentions across 2 days

Affected systems

Vendors
Products
netscaler_application_delivery_controllernetscaler_gateway

Deep dive

Activity timeline109 mentions / 2d
015294458Mentions · 2026-09-27: 51Mentions · 2026-09-28: 5809-2709-28
Referenced assets75 URLs
By indicator
Full discourse20 posts
  • The Hacker News@TheHackersNews

    ‼️ BREAKING: Citrix confirms two NetScaler flaws have been exploited and has released fixes. CVE-2026-88771 and CVE-2026-88772 were observed exploited on unmitigated deployments. The new advisory covers eight CVEs affecting NetScaler ADC and Gateway. New Details → https://thehackernews.com/2026/09/warning-two-unpatched-citrix-netscaler.html

    98773297358.7K
    2.4M followersView on X
  • Dark Web Informer@DarkWebInformer

    ‼️ Citrix has released a security bulletin regarding zero-day attacks targeting Citrix NetScaler ADC and Citrix NetScaler Gateway. More info: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096 CVEs: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778

    3170641911.2K
    240.3K followersView on X
  • The Hacker News@TheHackersNews

    ⚠️ CISA says attackers are actively exploiting two critical Citrix NetScaler flaws globally. CVE-2026-88771 can allow unauthenticated command execution. CVE-2026-88772 can enable RCE when DTLS is enabled. Citrix has fixes and IoCs. Read: https://thehackernews.com/2026/09/cisa-says-attackers-are-exploiting-two.html

    5212601319.6K
    2.4M followersView on X
  • Rıdvan Yağlı@ridvanyagli

    🔴 Citrix NetScaler'da CVSS 9.5 kritik DTLS açığı: CVE-2026-88772 için @murrezsec tarafından PoC yayınlandı. NetScaler ADC ve NetScaler Gateway'de DTLS işleme mekanizmasındaki memory overflow açığı, uzaktan RCE veya DoS saldırılarına yol açabiliyor. ⚠️ Citrix, CVE-2026-88772'nin aktif olarak sömürüldüğünü bildiriyor. Bu PoC; NetScaler Gateway/ADC fingerprinting, build sürümü kontrolü, UDP/443 DTLS kontrolü ve benign DTLS ClientHello probe içeriyor. Memory overflow'u tetikleyen weaponized paket PoC'de bulunmuyor. Düzeltilen sürümler: • NetScaler 14.1 -> 14.1-73.37+ • NetScaler 13.1 -> 13.1-64.23+ ⚠️ Önceki 14.1-73.32 ve 13.1-63.21 sürümleri bu açığı gidermiyor. PoC: https://github.com/murrez/CVE-2026-88772

    311233293.4K
    2.4K followersView on X
  • Bert-Jan 🛡️@BertJanCyber

    Official comms and patches from Citrix are out! Exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments has been observed. https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/

    117144155.0K
    4.6K followersView on X
  • ExploitGrid@exploitgrid

    🚨 Citrix has confirmed active exploitation of two NetScaler RCE flaws. CVE-2026-88771 | CVSS 9.5 CVE-2026-88772 | CVSS 9.5 8 vulnerabilities disclosed. Patches are now available. 🔎 CVE-2026-88771: https://exploitgrid.net/vulnerabilities/CVE-2026-88771 CVE-2026-88772: https://exploitgrid.net/vulnerabilities/CVE-2026-88772

    13141103.5K
    127 followersView on X
  • ᴅᴀɴɪᴇʟ ᴍɪᴇssʟᴇʀ 🛡️@DanielMiessler

    Citrix confirmed two new NetScaler zero-days, CVE-2026-88771 and CVE-2026-88772, both CVSS 9.5 and exploited before patches were available. https://securityaffairs.com/199873/security/citrix-confirmed-two-new-netscaler-flaws-exploited-as-zero-day.html

    2512544.3K
    159.8K followersView on X
  • BleepingComputer@BleepinComputer

    Citrix has confirmed that two critical NetScaler remote code execution vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks. They have now released security updates. Our article is updated, and the Citrix advisory is here: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096

    11201324.4K
    258.7K followersView on X
  • The Hacker News@TheHackersNews

    The broader update includes flaws that can lead to remote code execution, denial of service, HTTP request smuggling, policy bypass, and TCP initial sequence number prediction under specific conditions. Only CVE-2026-88771 and CVE-2026-88772 are confirmed exploited. https://t.co/taRQw0NXT9

    1402027.2K
    2.4M followersView on X
  • Dark Web Intelligence@DailyDarkWeb

    🚨 CITRIX NETSCALER — OFFICIAL PATCHES FOR TWO EXPLOITED RCE ZERO-DAYS (CVE-2026-88771 / CVE-2026-88772) Cloud Software Group (Citrix) published security bulletin CTX697096 covering eight NetScaler ADC / NetScaler Gateway flaws, including two critical remote code execution vulnerabilities that the vendor says have been exploited on unmitigated deployments. Lead issues (vendor CVSS v4 Base Score 9.5 each): • CVE-2026-88771 — Improper input validation → unauthenticated remote command execution. Affects ALL NetScaler ADC and NetScaler Gateway deployments, including default configuration (no extra features required). • CVE-2026-88772 — Memory overflow → remote code execution or denial of service when DTLS is enabled (DTLS is enabled by default on VPN virtual servers unless explicitly set to OFF). Fixed builds (install ASAP): • NetScaler ADC / Gateway 14.1-73.37 and later • NetScaler ADC / Gateway 13.1-64.23 and later (13.1) • NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later • NetScaler ADC 13.1-FIPS / 13.1-NDcPP 13.1.37.279 and later Also addressed in the same bulletin: CVE-2026-88773 through CVE-2026-88778 (HTTP request smuggling, policy bypass, additional memory overflows, TCP ISN prediction). ⚠️ Analyst Note: This is the official Citrix confirmation + patch set for the weekend’s unpatched NetScaler RCE warnings. Separate from the earlier auth-bypass CVE-2026-19490 (Aug builds 14.1-73.32 / 13.1-63.21 do NOT include these new fixes). Vendor wording: “Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed.” No public attribution, victim count, or full IOC package in the bulletin at publish time. Patching alone does not prove a previously exposed appliance was clean — treat internet-facing units as potentially compromised until forensics say otherwise. CISA had not listed CVE-2026-88771 / CVE-2026-88772 in KEV as of this post (catalog still 2026.09.25). Prefer the Citrix bulletin over secondary media. Official Citrix bulletin (CTX697096): https://support.citrix.com/external/article/CTX697096/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-and-cve-2026-88772.html #Citrix #NetScaler #ZeroDay #RCE #CVE202688771 #CVE202688772 #Vulnerability #CyberSecurity #ThreatIntel #DDW

    0102135.8K
    205.1K followersView on X
  • Manuel Winkel@Deyda84

    Citrix confirms exploitation of CVE-2026-88771 and CVE-2026-88772. My updated NetScaler checklist covers all eight CVEs and includes a read-only triage script. A clean scan does not prove an appliance is uncompromised. https://www.deyda.net/index.php/de/2026/08/28/netscaler-cve-checkliste-updates-sicherheitspruefung-und-incident-response/ #DeydaConsulting #NetScaler #Citrix

    1401361.4K
    1.4K followersView on X
  • Cristian Borghello@SeguInfo

    Utilizas Citrix NetScaler ADC y NetScaler Gateway? FELIZ DOMINGO! Expotación activa de CVE-2026-88771 y CVE-2026-88772 permite RCE en el dispositivo. PARCHEA! https://blog.segu-info.com.ar/2026/09/explotacion-activa-de-dos-zero-day-rce.html

    0411712.1K
    38.3K followersView on X
  • FOFA@fofabot

    ⚠️⚠️ CVE-2026-88771 (CVSS 9.5) + CVE-2026-88772 (CVSS 9.5): Citrix NetScaler ADC/Gateway zero-day RCE — now actively exploited in the wild 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJOZXRTY2FsZXItQUFBIg== 🎯42.7K+ Results are found on http://en.fofa.info in the past year. FOFA Query: app="NetScaler-AAA" 🔖Refer: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096 #OSINT #FOFA #CyberSecurity #Vulnerability

    1601051.4K
    14.8K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi

    ‼️ تحذير عاجل اذا تستخدم Citrix NetScaler تواصل مع مزود الخدمة وحدث لاخر نسخه لوجود ثغرتين Zero-Day تستغل حالياً CVE-2026-88771 CVE-2026-88772 المصدر https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096&articleURL=Citrix_NetScaler_ADC_and_Citrix_NetScaler_Gateway_Security_Bulletin_for_CVE_2026_88771_CVE_2026_88772_CVE_2026_88773_CVE_2026_88774_CVE_2026_88775_CVE_2026_88776_CVE_2026_88777_and_CVE_2026_88778 https://t.co/SvnP19FnFv

    1011353.9K
    50.2K followersView on X
  • Dark Web Intelligence@DailyDarkWeb

    🚨 CISA ADDS TWO KNOWN EXPLOITED VULNERABILITIES — CITRIX NETSCALER CVE-2026-88771 / CVE-2026-88772 CISA has added two critical Citrix NetScaler zero-days to the Known Exploited Vulnerabilities catalog and issued a dedicated Alert confirming active global exploitation. • CVE-2026-88771 — Citrix NetScaler improper input validation (unauthenticated remote command execution) • CVE-2026-88772 — Citrix NetScaler memory buffer restriction flaw (RCE / denial of service) • Both independently enable remote code execution; federal BOD due date 2026-09-30 • CISA: threat actors are actively exploiting these vulnerabilities globally • Vendor bulletin CTX697096 covers eight NetScaler ADC / Gateway CVEs (88771–88778); fixed builds include 14.1-73.37+ and 13.1-64.23+ ⚠️ Analyst Note: This is the CISA KEV / Alert escalation for the Citrix NetScaler RCE story already covered via official CTX697096 patches earlier today — not a rehash of the vendor bulletin. CISA also urges checking for compromise before patching where possible (updates can destroy forensic evidence) and points to Citrix IoC guidance via NetScaler Console. Preserve evidence if compromise is suspected, then patch urgently. CISA KEV alert: https://www.cisa.gov/news-events/alerts/2026/09/27/cisa-adds-two-known-exploited-vulnerabilities-catalog CISA Citrix zero-day Alert: https://www.cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway Citrix bulletin CTX697096: https://support.citrix.com/external/article/CTX697096/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-and-cve-2026-88772.html CISA KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog #DDW #DarkWeb #CISA #KEV #Citrix #NetScaler #ThreatIntelligence #CyberSecurity

    340725.3K
    205.1K followersView on X
  • Ryx@PadhiyarRushi

    Citrix confirmed two NetScaler RCEs are being exploited. Public DTLS PoC dropped with the bulletin!! CVE-2026-88771 (CVSS 9.5): unauth command execution on every affected ADC/Gateway. No extra feature required. CVE-2026-88772 (CVSS 9.5): DTLS memory overflow → RCE or DoS. DTLS is on by default on VPN vServers unless -dtls OFF. Fingerprint + probe script is public. Fixed: 14.1-73.37 / 13.1-64.23. August builds 14.1-73.32 and 13.1-63.21 do not cover this. https://www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/ #Cybersecurity #AI #AISecurity #MCP #Claude #GPT #Infosec #Trending #NetworkSecurity #KEV #RCE

    10081572
    929 followersView on X
  • mürrez@murrezsec

    🚨 CVE-2026-88772 — Citrix NetScaler ADC/Gateway DTLS memory overflow (UDP/443) → RCE/DoS. Active exploitation reported (CTX697096). Patch: 14.1-73.37+ / 13.1-64.23+. 📖 https://pocbit.org/pocs/cve-2026-88772 #CVE #Citrix #NetScaler #CyberSecurity #VPN #InfoSec

    12061425
    620 followersView on X
  • CERT-FR@CERT_FR

    ⚠️ Alerte CERT-FR ⚠️ Les vulnérabilités CVE-2026-88771 et CVE-2026-88772 sont activement exploitées et permettent une RCE pré-authentification sur Citrix NetScaler ADC et Gateway. https://www.cert.ssi.gouv.fr/alerte/CERTFR-2026-ALE-011/

    040412.8K
    58.2K followersView on X
  • Rıdvan Yağlı@ridvanyagli

    🚨 Citrix NetScaler ADC/Gateway: 8 kritik/yüksek güvenlik açığı için yama yayınlandı! 🔴 CVE-2026-88771 — CVSS 9.5 Unauthenticated RCE. Varsayılan yapılandırmalar dahil tüm NetScaler ADC/Gateway kurulumları etkileniyor. 🔴 CVE-2026-88772 — CVSS 9.5 Memory overflow -> RCE/DoS. DTLS etkin sistemler etkileniyor; VPN vServer'larda DTLS varsayılan olarak açık. 🟠 CVE-2026-88773 — CVSS 9.3 HTTP Request Smuggling. 🟠 CVE-2026-88774 — CVSS 7.0 Policy bypass. 🟠 CVE-2026-88775 — CVSS 8.8 Memory overflow -> DoS/öngörülemeyen davranış. 🟠 CVE-2026-88776 — CVSS 8.8 Memory overflow -> DoS. 🟠 CVE-2026-88777 — CVSS 8.8 Memory overflow -> DoS. 🟠 CVE-2026-88778 — CVSS 8.8 TCP Initial Sequence Number (ISN) prediction. ⚠️ CVE-2026-88771 ve CVE-2026-88772'nin aktif olarak istismar edildiği Citrix tarafından doğrulandı. Çözüm: 14.1-73.37+ veya 13.1-64.23+ sürümüne güncelleyin. FIPS/NDcPP sürümleri için ilgili güncel build'ler de uygulanmalı. Citrix güvenlik bülteni: https://support.citrix.com/external/article/CTX697096

    010801.1K
    2.4K followersView on X
  • FastFoodRembrandt.onion@solminingpunk

    #UPDATE @citrix Confirmed Two New NetScaler Flaws Exploited as Zero-Day Citrix confirmed active exploitation of CVE-2026-88771 (CVSS score of 9.5) and CVE-2026-88772 (CVSS score of 9.5) on unpatched systems and urged customers to install the relevant updates as soon as possible

    02060740
    6.4K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appcitrixnetscaler_application_delivery_controller---
Appcitrixnetscaler_application_delivery_controller---
Appcitrixnetscaler_application_delivery_controller---
Appcitrixnetscaler_gateway---

Explore more