The short version
- Citrix confirmed active exploitation of two NetScaler ADC and NetScaler Gateway vulnerabilities.
- CVE-2026-88771 and CVE-2026-88772 were rated 9.5 out of 10 in the cited security reporting.
- The first flaw is described as an unauthenticated remote-code-execution vulnerability caused by improper input validation.
Citrix confirmed active exploitation of two NetScaler ADC and NetScaler Gateway vulnerabilities. Citrix has confirmed active exploitation of two NetScaler ADC and NetScaler Gateway vulnerabilities, CVE-2026-88771 and CVE-2026-88772. The reported severity is high, with both vulnerabilities rated 9.5 out of 10 in the cited security reporting.
NetScaler’s security advisory documents the affected platform the security response and the recommended updates.
Why the NetScaler disclosure changes the response
Citrix issued security updates for the vulnerabilities and urged customers to install the fixes.
The first vulnerability is described as an unauthenticated remote-code-execution issue caused by improper input validation. The second involves a memory-overflow condition that can lead to remote code execution or denial of service under affected configurations.
Security agencies also warned operators because NetScaler systems often sit at the network edge and can provide a valuable path into enterprise environments.
- Citrix has confirmed active exploitation of two NetScaler ADC and NetScaler Gateway vulnerabilities, CVE-2026-88771 and CVE-2026-88772.
- CVE-2026-88771 and CVE-2026-88772 were rated 9.5 out of 10 in the cited security reporting.
Citrix confirmed active exploitation of two vulnerabilities affecting NetScaler ADC and NetScaler Gateway. The affected products sit at the edge of enterprise networks, which makes exploitation especially significant for organizations using them as externally reachable infrastructure.
The active-exploitation detail changes the priority for organizations running affected appliances. Internet-facing infrastructure is exposed differently from an isolated internal system, and security teams need to establish whether vulnerable versions are present before assessing the likely impact.
Citrix has issued security updates and urged customers to install the fixes. Patching is only the first step for organizations that suspect exploitation. They also need to review relevant logs, investigate unusual activity and determine whether credentials or connected systems require additional attention.
The incident is another reminder that edge infrastructure remains a high-value target. Appliances that sit between users and internal applications can provide an attractive route into an environment, which is why vulnerability management on network-facing systems has to include both rapid patching and post-patch verification.