CITRIX disclosed eight vulnerabilities affecting NetScaler ADC and NetScaler Gateway on 27 September 2026, including two critical remote-code-execution flaws: CVE-2026-88771 and CVE-2026-88772. Both have a CVSSv4 score of 9.5 and were confirmed by the US Cybersecurity and Infrastructure Security Agency (CISA) as actively exploited zero-days before disclosure. CVE-2026-88771 is an input-validation flaw exploitable against vulnerable appliances in their default configuration, with low attack complexity.
CVE-2026-88772 is a memory-corruption vulnerability requiring DTLS to be enabled, and has high attack complexity. CISA said exploitation is occurring globally and added both vulnerabilities to its Known Exploited Vulnerabilities catalogue on 27 September.
The remaining six flaws are CVE-2026-88773, an HTTP request-smuggling vulnerability rated 9.3; CVE-2026-88774, a policy-bypass flaw rated 7.0; CVE-2026-88775, CVE-2026-88776 and CVE-2026-88777, memory-overflow vulnerabilities each rated 8.8; and CVE-2026-88778, involving predictable TCP initial sequence numbers and rated 8.8. Exploitation has not been confirmed for these six vulnerabilities.
Citrix updates addressing all eight issues include NetScaler ADC and Gateway 14.1-73.37 and later, 13.1-64.23 and later, and the specified FIPS and NDcPP releases. Rapid7 recommends emergency patching and investigation of affected appliances for compromise indicators.