CVE-2026-88771 and CVE-2026-88772: Two Critical Citrix NetScaler Flaws Under Active Exploitation

mse major security alert blog
emma-stevens-bio-portrait
Written by Emma Stevens
Senior Threat Intelligence Advisor

Citrix disclosed two critical vulnerabilities in NetScaler ADC and NetScaler Gateway that are already being exploited in the wild. CVE-2026-88771 allows unauthenticated attackers to run commands on an affected appliance, while CVE-2026-88772 can lead to remote code execution or denial of service when DTLS is turned on. Both received a CVSS v4.0 score of 9.5, and CISA added them to its Known Exploited Vulnerabilities catalog. Because NetScaler appliances sit at the front door of many networks, handling remote access and critical app traffic, simply patching isn't enough, you need to verify whether attackers accessed internal systems before the patch was applied.

According to Bitsight Threat Intelligence

Bitsight Threat Intelligence assigned both flaws a Dynamic Vulnerability Exploit (DVE) score of 10.0 out of 10. DVE is Bitsight's proprietary score that helps security teams prioritize flaws based on how likely they are to be exploited over the next 90 days. In this case, active exploitation is already confirmed by Citrix.

Attribute

CVE-2026-88771

CVE-2026-88772

What is the flaw?Improper input validationMemory overflow
What could happen?An unauthenticated attacker could execute arbitrary commandsRemote code execution or denial of service
What configuration is required?No additional feature is required; default configurations are affectedDTLS must be enabled; it is enabled by default on VPN virtual servers
CVSS v4.0 score9.59.5
Bitsight DVE score10.010.0
Exploitation statusConfirmed by Citrix; listed by CISA and EUVD as a KEVConfirmed by Citrix; listed by CISA and EUVD as a KEV

Citrix released updates for NetScaler ADC and Gateway 14.1-73.37 and 13.1-64.23, alongside fixed FIPS and NDcPP builds. Check the official security bulletin for the full list of affected versions and corresponding updates.

Why this matters

Disabling DTLS mitigates CVE-2026-88772, but it does nothing to protect against CVE-2026-88771, which affects default configurations out of the box. Teams must address both flaws. Because attackers actively targeted these vulnerabilities before patches were available, updating software is only half the battle. CISA warns that updating can wipe forensic evidence. If you suspect an intrusion, preserve logs and device state before making changes, then patch as quickly as possible.

CVE-2026-88771 and CVE-2026-88772 impact to organizations

Successful exploitation could give attackers control over the appliance or disrupt service. From there, attackers can use a compromised NetScaler handling remote access or core apps to pivot to connected networks, harvest credentials, or breach internal databases. While these risks are severe, the exact scope of public attacks remains unconfirmed.

Risk also extends to third-party vendors. If a key vendor runs an affected NetScaler managing your access or applications, you should confirm that they patched their systems and checked for prior signs of compromise.

Recommendations

  1. Locate and update affected appliances. Cross-reference customer-managed NetScaler ADC and Gateway instances (including hybrid deployments) against Citrix's advisory. Since Citrix disclosed eight total vulnerabilities in this release, review the full bulletin when planning updates.

  2. Preserve forensic evidence before rebooting. Save appliance logs and check external sources (firewall, DNS, authentication logs) before rebooting or rebuilding. Balance forensic preservation carefully so it does not unduly delay urgent patching.

  3. Investigate beyond automated checks. Citrix provides generic indicator-of-compromise checks in NetScaler Console (or via Support), but warns these checks may miss sophisticated intrusions. Bring in experienced incident responders if you notice suspicious activity.

  4. Engage critical vendors. Ask third-party vendors operating NetScaler appliances which software builds they use, when they patched, and whether they investigated historical activity. If compromise occurred, ask how they assessed potential impacts on your connection.

Threat landscape & context

Citrix confirmed active exploitation of these two vulnerabilities on unmitigated devices, and CISA reported worldwide targeting. Public data is still too limited to confirm which industries or how many organizations have been impacted overall.

How Bitsight TI and TPRM support you

Threat monitoring: Bitsight Threat Intelligence helps teams follow exploitation activity and attacker interest as the situation develops.

Vulnerability prioritization: DVE adds a view of exploitation likelihood alongside severity, helping teams decide what needs attention first.

First- and third-party exposure: Bitsight can help organizations identify relevant external exposure and prioritize outreach to vendors that may operate affected technology.

Supply chain monitoring: Bitsight Beacon provides validated alerts and supporting evidence to help security teams assess emerging threats across critical vendors.

Conclusion

These vulnerabilities require immediate remediation. Active exploitation is happening, and default NetScaler setups are vulnerable to CVE-2026-88771. Identify exposed appliances, apply the official updates, and verify that attackers haven't already gained a foothold. Finally, reach out to critical vendors running NetScaler on your behalf to ensure they've done the same.

Bitsight cta background color
2026 gartner magic quadrant cover

Bitsight Recognized as a Visionary in 2026 Gartner® Magic Quadrant™ for Cyber Threat Intelligence Technologies

Get the report and see why Bitsight was named a Visionary.

 

Download

Bitsight cta background color