The short version
- Citrix has confirmed exploitation of two critical NetScaler ADC and Gateway vulnerabilities that can allow remote code execution.
- CVE-2026-88771 can be exploited without authentication on affected deployments while CVE-2026-88772 is tied to DTLS-enabled configurations.
- Citrix has released fixed builds and advises customers to update affected appliances and investigate for signs of compromise.
Two flaws sit at the network edge
The latest NetScaler security incident matters because the vulnerable products often sit directly on the boundary between enterprise networks and the internet. NetScaler ADC and NetScaler Gateway handle application delivery, remote access, VPN traffic and authentication. A successful compromise can therefore put an attacker close to systems that control access to much larger environments.
Citrix has confirmed exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated deployments. Both vulnerabilities carry a CVSS v4 score of 9.5. The first is an improper input validation issue that can allow an unauthenticated attacker to execute arbitrary commands. The second is a memory overflow condition that can lead to remote code execution or denial of service when the relevant DTLS configuration is enabled.
The vendor’s security bulletin CTX697096 lists the affected versions and the fixed builds. Citrix has released NetScaler 14.1-73.37 and 13.1-64.23 along with corresponding FIPS updates. The company has also listed additional vulnerabilities in the same bulletin that were fixed but were not identified as exploited.
A patch closes the vulnerability. It does not prove that an appliance was never accessed before the patch was installed.
Why patching is only the first step
The exploitation history changes the response process. When a remote access appliance has been exposed to an active zero-day, defenders have to consider the possibility that an attacker obtained persistence or credentials before the security update became available.
Citrix’s response guidance calls for evidence preservation, network isolation where compromise is suspected, credential rotation and review of secrets stored on the appliance. Administrators also need to examine logs and supporting systems because a successful attack may use the NetScaler as an entry point rather than as the final target.
CVE-2026-88771 is especially broad because the vulnerable condition does not require an optional feature to be enabled. CVE-2026-88772 has a different precondition involving DTLS. VPN virtual servers commonly have DTLS enabled by default, which makes configuration review important even when an organization has not deliberately enabled the feature for a particular security workflow.
The incident also demonstrates why internet-facing infrastructure needs a shorter remediation path than ordinary enterprise software. A firewall appliance, VPN gateway or application delivery controller can expose authentication and administrative functions to remote users. The security boundary is therefore concentrated in a small number of devices that can have an outsized effect on the rest of the network.
Security teams should treat the NetScaler advisory as both a patching event and a potential incident-response event. The relevant question is not only whether the appliance is now running a fixed version. Teams also need to establish whether suspicious activity occurred before remediation and whether credentials or certificates connected to the appliance require replacement.