
Please see our latest Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778. Citrix urges affected customers to install the relevant updated versions as soon as possible. https://bit.ly/3T4RXGY
Signal is active with 2 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
STABLE
If you run products in this scope, you should treat this CVE as relevant to your environment.

Please see our latest Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778. Citrix urges affected customers to install the relevant updated versions as soon as possible. https://bit.ly/3T4RXGY

⚠️ 𝗨𝗿𝗴𝗲𝗻𝘁: 𝗣𝗮𝘁𝗰𝗵 𝗡𝗲𝘁𝗦𝗰𝗮𝗹𝗲𝗿 𝗔𝗗𝗖/𝗚𝗮𝘁𝗲𝘄𝗮𝘆 𝗳𝗼𝗿 𝗔𝗰𝘁𝗶𝘃𝗲𝗹𝘆 𝗘𝘅𝗽𝗹𝗼𝗶𝘁𝗲𝗱 𝗩𝘂𝗹𝗻𝗲𝗿𝗮𝗯𝗶𝗹𝗶𝘁𝗶𝗲𝘀 Citrix has confirmed active exploitation of 𝗖𝗩𝗘-𝟮𝟬𝟮𝟲-𝟴𝟴𝟳𝟳𝟭 and 𝗖𝗩𝗘-𝟮𝟬𝟮𝟲-𝟴𝟴𝟳𝟳𝟮 on unpatched NetScaler deployments and strongly recommends that affected customers upgrade to the latest fixed versions immediately. https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/ To help security teams assess potential exposure, the KQL query below leverages 𝗠𝗶𝗰𝗿𝗼𝘀𝗼𝗳𝘁 𝗗𝗲𝗳𝗲𝗻𝗱𝗲𝗿 𝗳𝗼𝗿 𝗘𝗻𝗱𝗽𝗼𝗶𝗻𝘁 (𝗠𝗗𝗘) 𝗱𝗲𝘃𝗶𝗰𝗲 𝗱𝗶𝘀𝗰𝗼𝘃𝗲𝗿𝘆 𝘁𝗲𝗹𝗲𝗺𝗲𝘁𝗿𝘆 to identify NetScaler appliances within your environment, enabling faster validation and remediation actions. 🫡 https://github.com/SlimKQL/Detections.AI/blob/main/KQL/citrix-netscaler-check.kql #MicrosoftDefender #CitrixNetScaler #VulnerabilityManagement #ThreatHunting #ZeroDay

‼️ Citrix has released a security bulletin regarding zero-day attacks targeting Citrix NetScaler ADC and Citrix NetScaler Gateway. More info: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096 CVEs: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778

Citrix has released a security bulletin for 8 vulnerabilities in NetScaler ADC and NetScaler Gateway (CVE-2026-88771 through CVE-2026-88778). Censys currently observes ~37K internet-facing hosts serving ~285K NetScaler web endpoints worldwide. Review Citrix's guidance and remediate: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096 #CensysARC

Official comms and patches from Citrix are out! Exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments has been observed. https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/

We hope you’ve enjoyed this episode of “no way? vulns? in SECURITY appliances? there is no proof” watchTowr Platform clients have access to this info every day - preempting, validating, mitigating exposure to emerging threats. Speak.. soon… ;-) xoxo https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/

Citrix netscaler patches https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/

🚨 CITRIX NETSCALER — OFFICIAL PATCHES FOR TWO EXPLOITED RCE ZERO-DAYS (CVE-2026-88771 / CVE-2026-88772) Cloud Software Group (Citrix) published security bulletin CTX697096 covering eight NetScaler ADC / NetScaler Gateway flaws, including two critical remote code execution vulnerabilities that the vendor says have been exploited on unmitigated deployments. Lead issues (vendor CVSS v4 Base Score 9.5 each): • CVE-2026-88771 — Improper input validation → unauthenticated remote command execution. Affects ALL NetScaler ADC and NetScaler Gateway deployments, including default configuration (no extra features required). • CVE-2026-88772 — Memory overflow → remote code execution or denial of service when DTLS is enabled (DTLS is enabled by default on VPN virtual servers unless explicitly set to OFF). Fixed builds (install ASAP): • NetScaler ADC / Gateway 14.1-73.37 and later • NetScaler ADC / Gateway 13.1-64.23 and later (13.1) • NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later • NetScaler ADC 13.1-FIPS / 13.1-NDcPP 13.1.37.279 and later Also addressed in the same bulletin: CVE-2026-88773 through CVE-2026-88778 (HTTP request smuggling, policy bypass, additional memory overflows, TCP ISN prediction). ⚠️ Analyst Note: This is the official Citrix confirmation + patch set for the weekend’s unpatched NetScaler RCE warnings. Separate from the earlier auth-bypass CVE-2026-19490 (Aug builds 14.1-73.32 / 13.1-63.21 do NOT include these new fixes). Vendor wording: “Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed.” No public attribution, victim count, or full IOC package in the bulletin at publish time. Patching alone does not prove a previously exposed appliance was clean — treat internet-facing units as potentially compromised until forensics say otherwise. CISA had not listed CVE-2026-88771 / CVE-2026-88772 in KEV as of this post (catalog still 2026.09.25). Prefer the Citrix bulletin over secondary media. Official Citrix bulletin (CTX697096): https://support.citrix.com/external/article/CTX697096/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-and-cve-2026-88772.html #Citrix #NetScaler #ZeroDay #RCE #CVE202688771 #CVE202688772 #Vulnerability #CyberSecurity #ThreatIntel #DDW

Citrix NetScaler ADC/Gatewayのゼロデイ2件について公式情報が出た。CVE-2026-88771及びCVE-2026-88772はいずれもCVSSスコア9.5で、前者は無条件で刺さり、後者はDTLSが有効であることが条件(VPN仮想サーバでは既定で有効)。他6件も併せCVE-2026-88778までの8件が修正。 https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/

Official update: https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/?utm_id=cid2026-0806&utm_source=facebook&utm_medium=social%20media%20organic&utm_campaign=citrix%20organic&utm_content=1790523126

🚨 Citrix NetScaler ADC/Gateway: 8 kritik/yüksek güvenlik açığı için yama yayınlandı! 🔴 CVE-2026-88771 — CVSS 9.5 Unauthenticated RCE. Varsayılan yapılandırmalar dahil tüm NetScaler ADC/Gateway kurulumları etkileniyor. 🔴 CVE-2026-88772 — CVSS 9.5 Memory overflow -> RCE/DoS. DTLS etkin sistemler etkileniyor; VPN vServer'larda DTLS varsayılan olarak açık. 🟠 CVE-2026-88773 — CVSS 9.3 HTTP Request Smuggling. 🟠 CVE-2026-88774 — CVSS 7.0 Policy bypass. 🟠 CVE-2026-88775 — CVSS 8.8 Memory overflow -> DoS/öngörülemeyen davranış. 🟠 CVE-2026-88776 — CVSS 8.8 Memory overflow -> DoS. 🟠 CVE-2026-88777 — CVSS 8.8 Memory overflow -> DoS. 🟠 CVE-2026-88778 — CVSS 8.8 TCP Initial Sequence Number (ISN) prediction. ⚠️ CVE-2026-88771 ve CVE-2026-88772'nin aktif olarak istismar edildiği Citrix tarafından doğrulandı. Çözüm: 14.1-73.37+ veya 13.1-64.23+ sürümüne güncelleyin. FIPS/NDcPP sürümleri için ilgili güncel build'ler de uygulanmalı. Citrix güvenlik bülteni: https://support.citrix.com/external/article/CTX697096

🚨Citrixよりゼロデイに関連した公式パッチリリースあり(CVE-2026-88771~88778) CVE-2026-88771 / 88772(CVSS 9.5)がRCEに繋がるもので悪用を既に観測 88771は前提条件なし、88772はDTLS有効が条件(VPN vServerはデフォルトON) https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096 https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/ https://t.co/qYoYA2iwl6

The disclosure is now official. Citrix has assigned CVE-2026-88771 through CVE-2026-88778 and released security updates for affected NetScaler deployments. We’re tracking the vulnerabilities and exploit intelligence on ExploitGrid.

🚨 Patch your @NetScaler NOW. @citrix CTX697096: 8 new CVEs in NetScaler ADC & Gateway. Two are unauthenticated RCE and already exploited in the wild. 🧵 What you need to know 👇 #NetScaler #Citrix #PatchNow ——— 2/ The exploited two: 🔴 CVE-2026-88771 (CVSS 9.5) – RCE, affects every deployment incl. default config. No workaround. 🔴 CVE-2026-88772 (CVSS 9.5) – memory overflow → RCE via DTLS, which is ON by default on Gateway vServers. ——— 3/ Fixed builds: ✅ 14.1-73.37+ ✅ 13.1-64.23+ (64.24 if you use NS variables) ✅ 14.1-73.37 FIPS ✅ 13.1-37.279 FIPS/NDcPP ⚠️ Patched in August? You're NOT covered. ⚠️ 12.1/13.0 are EOL – no fix. ——— 4/ Before you upgrade: • On 13.1? Run "show ns variable". Any output → go to 13.1-64.24, not 64.23 (cyclic reboot risk) • SAML: unsigned assertions are no longer accepted. Make sure your IdP signs them, or logons break ——— 5/ After upgrading: • Enable Enhanced ISN Generation (CVE-2026-88778) • Assume breach – exploited before a patch existed • Save RAM + logs BEFORE reboot • Run the IoC scan in NetScaler Console (or ask Citrix Support) ——— 6/ Bulletin: https://support.citrix.com/external/article/CTX697096 Tech Zone guidance: https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/

@Technop54777070 https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/

Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778 https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096 KEV↓ Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway https://www.cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway 参考 Citrix confirms two NetScaler RCE zero-days exploited in attacks https://www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/ 『(直訳)Citrixは、NetScalerのリモートコード実行に関する2つの重大な脆弱性(CVE-2026-88771およびCVE-2026-88772として追跡されている)が攻撃に悪用されていることを確認し、これらの脆弱性を修正するためのセキュリティアップデートをリリースしたことを発表しました。』

JPMorgan Chase XOR Team🤔 Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778 https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096

Muuucha info de los 2 Zero-Days de Citrix NetScaler ADC y NetScaler Gateway (CVE-2026-88771 - CVE-2026-88778): https://blog.segu-info.com.ar/2026/09/explotacion-activa-de-dos-zero-day-rce.html Si tienes esos dispositivos, hoy no tienes nada más importante que hacer que PARCHEARLOS.

Neuigkeiten! Patches sind draußen: https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/

@twittaccount_ Schon entdeckt? https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/
4 of 4 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | citrix | netscaler_application_delivery_controller | - | - | - |
| App | citrix | netscaler_application_delivery_controller | - | - | - |
| App | citrix | netscaler_application_delivery_controller | - | - | - |
| App | citrix | netscaler_gateway | - | - | - |