Citrix has released security updates for two critical NetScaler vulnerabilities after confirming that attackers exploited both flaws before patches were available.
The company’s security bulletin covers CVE-2026-88771 and CVE-2026-88772, each rated 9.5 out of 10. Citrix says exploitation was observed on unmitigated NetScaler deployments.
One flaw affects default deployments
CVE-2026-88771 is an improper-input-validation flaw that can let an unauthenticated attacker execute arbitrary commands. BleepingComputer reports that it affects NetScaler ADC and Gateway deployments without requiring an optional feature to be enabled.
CVE-2026-88772 is a memory-overflow vulnerability that can lead to remote code execution or denial of service when DTLS is enabled. Citrix notes that DTLS is enabled by default on VPN virtual servers.
The affected releases include NetScaler ADC and Gateway 14.1 before 14.1-73.37 and 13.1 before 13.1-64.23, along with specified FIPS and NDcPP builds. Secure Private Access Hybrid deployments that use NetScaler instances also need the fixed versions.
Private warnings preceded the public patches
Administrators began reporting that suppliers, incident responders and national cybersecurity agencies were privately advising organizations to shut down appliances. BleepingComputer says Citrix discovered the vulnerabilities while investigating incidents in customer environments, prompting advance warnings so teams could prepare for disruptive upgrades.
NetScaler appliances often sit at the edge of corporate networks and provide remote access, which makes a compromise a potential path into internal systems. Citrix says its bulletin applies to customer-managed appliances. Cloud Software Group is updating Citrix-managed cloud services and Adaptive Authentication itself.
Organizations should install the fixed builds as soon as possible and reduce internet exposure where an immediate upgrade is not possible. Applying the patch addresses the vulnerability; teams that may have been exposed before patching still need to investigate for signs of compromise.