Citrix has released fixes for two critical remote code execution flaws in NetScaler ADC and NetScaler Gateway, tracked as CVE-2026-88771 and CVE-2026-88772. On September 27, the company confirmed that attackers had already exploited both in the wild. The same update addresses six other vulnerabilities. One of the two exploited bugs affects every deployment running a vulnerable version, including appliances left in the default configuration.
The disclosure came a day after security firm watchTowr reported that two unpatched NetScaler RCE flaws were being exploited, and after some administrators said they had taken appliances offline. Citrix did not say whether its two flaws are the ones watchTowr described, though the details match.
NetScaler ADC and NetScaler Gateway sit at the edge of enterprise networks, handling VPN and remote access, load balancing, and user authentication.
CVE-2026-88771, rated 9.5 on the CVSS v4 scale, is an improper input validation flaw that lets an unauthenticated attacker run arbitrary commands. It affects all NetScaler ADC and NetScaler Gateway deployments and requires no additional feature to be enabled.
CVE-2026-88772, also rated 9.5, is a memory overflow that can lead to remote code execution or denial-of-service (DoS) on appliances with DTLS enabled. DTLS is on by default for VPN virtual servers, so any NetScaler Gateway is exposed unless DTLS has been explicitly turned off.
“Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed,” Citrix said. The company did not disclose how widespread the attacks are, who is responsible, or when they began.
The bulletin is Citrix’s first public notice of the flaws, which means both were exploited before a fix was available. It lists no workarounds and no indicators of compromise.
Appliances running 14.1-73.32 and 13.1-63.21 fall within the affected range and need the new update. Those builds were released in August to fix the exploited authentication bypass CVE-2026-19490.
Citrix urged affected customers to install these versions as soon as possible:
The bulletin covers customer-managed appliances, including NetScaler instances in Secure Private Access Hybrid deployments. Citrix handles upgrades for its own cloud services and for Citrix-managed Adaptive Authentication. The 13.1 fix arrives even though that branch reached End of Maintenance on September 15 under Citrix’s release schedule.
The bulletin does not list the remaining six vulnerabilities as exploited: