Citrix disclosed two critical vulnerabilities in NetScaler ADC and NetScaler Gateway that are already being exploited in the wild. CVE-2026-88771 allows unauthenticated attackers to run commands on an affected appliance, while CVE-2026-88772 can lead to remote code execution or denial of service when DTLS is turned on. Both received a CVSS v4.0 score of 9.5, and CISA added them to its Known Exploited Vulnerabilities catalog. Because NetScaler appliances sit at the front door of many networks, handling remote access and critical app traffic, simply patching isn't enough, you need to verify whether attackers accessed internal systems before the patch was applied.
According to Bitsight Threat Intelligence
Bitsight Threat Intelligence assigned both flaws a Dynamic Vulnerability Exploit (DVE) score of 10.0 out of 10. DVE is Bitsight's proprietary score that helps security teams prioritize flaws based on how likely they are to be exploited over the next 90 days. In this case, active exploitation is already confirmed by Citrix.
Attribute | CVE-2026-88771 | CVE-2026-88772 |
|---|---|---|
| What is the flaw? | Improper input validation | Memory overflow |
| What could happen? | An unauthenticated attacker could execute arbitrary commands | Remote code execution or denial of service |
| What configuration is required? | No additional feature is required; default configurations are affected | DTLS must be enabled; it is enabled by default on VPN virtual servers |
| CVSS v4.0 score | 9.5 | 9.5 |
| Bitsight DVE score | 10.0 | 10.0 |
| Exploitation status | Confirmed by Citrix; listed by CISA and EUVD as a KEV | Confirmed by Citrix; listed by CISA and EUVD as a KEV |
Citrix released updates for NetScaler ADC and Gateway 14.1-73.37 and 13.1-64.23, alongside fixed FIPS and NDcPP builds. Check the official security bulletin for the full list of affected versions and corresponding updates.
Why this matters
Disabling DTLS mitigates CVE-2026-88772, but it does nothing to protect against CVE-2026-88771, which affects default configurations out of the box. Teams must address both flaws. Because attackers actively targeted these vulnerabilities before patches were available, updating software is only half the battle. CISA warns that updating can wipe forensic evidence. If you suspect an intrusion, preserve logs and device state before making changes, then patch as quickly as possible.