CITRIX has confirmed that two zero-day vulnerabilities in NetScaler ADC and NetScaler Gateway appliances have been exploited in the wild. CVE-2026-88771 and CVE-2026-88772 were reportedly used against internet-facing devices before patches were available, according to Citrix, watchTowr and Kevin Beaumont. The warning first emerged on 25 September 2026 after advice linked to an NCSC-NL pre-notification was shared on Reddit, followed by public researcher warnings the next day. The affected products sit at the network edge, handling VPN access, authentication and application traffic.
Both vulnerabilities have a CVSS v4.0 score of 9.5. CVE-2026-88771 allows an unauthenticated attacker to execute arbitrary commands through improper input validation and affects all NetScaler ADC and Gateway deployments, including default configurations. CVE-2026-88772 is a memory-overflow flaw that can enable remote code execution or denial of service when DTLS is enabled; Citrix says DTLS is enabled by default on VPN virtual servers.
Citrix’s bulletin covers eight vulnerabilities, CVE-2026-88771 through CVE-2026-88778, and says all NetScaler ADC and Gateway products are affected by at least one issue.
Citrix urges customers to upgrade immediately to fixed builds, including 14.1-73.37 or later, 13.1-64.23 or later, or the specified FIPS and NDcPP releases. Because exploitation began before fixes were available, upgrading alone does not establish that a device is uncompromised. Organisations should review exposed appliances, preserve forensic evidence and investigate for unexpected processes, crash dumps and newly created web-directory files. Citrix warns that its generic indicators of compromise may have limited forensic value.