CITRIX has issued emergency updates for eight vulnerabilities affecting customer-managed NetScaler ADC and NetScaler Gateway appliances, including two critical zero-days being exploited in the wild. CVE-2026-88771 and CVE-2026-88772 both have CVSS v4.0 scores of 9.5 and can independently enable remote code execution. CVE-2026-88771 is an unauthenticated input-validation flaw requiring no additional feature or special configuration.
CVE-2026-88772 is a memory-overflow vulnerability that can lead to remote code execution or denial of service when DTLS is enabled; Citrix says DTLS is enabled by default on VPN virtual servers. Citrix confirmed observed exploitation on unmitigated systems, while CISA said on 27 September 2026 that partner intelligence confirmed global exploitation and added both CVEs to its Known Exploited Vulnerabilities catalogue.
Affected supported branches include NetScaler ADC/Gateway 14.1 before 14.1-73.37, 13.1 before 13.1-64.23, 14.1-FIPS before 14.1-73.37 FIPS, and 13.1-FIPS/NDcPP before 13.1-37.279. Secure Private Access Hybrid deployments using customer-managed appliances are also affected. Organisations should verify exact running builds and upgrade to the applicable fixed release. CISA set a 30 September 2026 remediation deadline for covered federal agencies.
Because exploitation began before patches were available, updating alone may not identify earlier compromise. CISA and Citrix advise preserving relevant evidence where practical, reviewing logs and available Indicators of Compromise, and investigating exposed appliances. A clean Citrix scan does not prove that an appliance was not compromised.
Citrix has not publicly attributed the attacks to a specific threat actor, and the supplied report says no credible, independently verified fully weaponised public exploit was available as at 28 September 2026.