CITRIX has released updates for eight vulnerabilities in NetScaler ADC and NetScaler Gateway, including two critical zero-days that it says have been exploited in the wild. The flaws have CVSS scores between 7 and 9.5. CVE-2026-88771 is an unauthenticated remote-code-execution vulnerability caused by improper input validation, affecting all deployments with the default configuration.
CVE-2026-88772 is a memory-overflow flaw that can allow remote code execution or denial of service on deployments with DTLS enabled, which Citrix says is the default on VPN virtual servers.
Citrix confirmed on 27 September that exploitation of both vulnerabilities had been observed on unpatched systems and urged customers to install the relevant updates immediately. Another critical issue, CVE-2026-88773, is an HTTP request-smuggling vulnerability with a CVSS score of 9.3 when HTTP configuration is enabled. The remaining flaws, CVE-2026-88774 through CVE-2026-88778, involve policy bypass, memory overflows and TCP initial sequence number prediction, with CVSS scores from 7 to 8.8.
Australia’s ACSC issued a critical alert on 28 September, while CISA directed US federal agencies to patch by 30 September. The bulletin applies to customer-managed NetScaler products; Citrix-managed cloud services are being updated by Cloud Software Group.