DEV Community

jeffrey
jeffrey

Posted on

Citrix NetScaler CVE-2026-88771 and CVE-2026-88772: two edge RCE flaws attacked before a fix existed

Citrix NetScaler CVE-2026-88771 and CVE-2026-88772: two edge RCE flaws attacked before a fix existed

Citrix published fixes for two NetScaler flaws on 2026-09-27 after watchTowr reported unpatched remote code execution bugs under active exploitation. Both flaws are rated 9.5 under CVSS v4.

The two vulnerabilities

CVE-2026-88771 is improper input validation that lets an unauthenticated attacker run arbitrary commands. Citrix states that it affects all NetScaler ADC and NetScaler Gateway deployments on the affected versions, with no additional feature required.
CVE-2026-88772 is a memory overflow that can lead to remote code execution or denial of service. It affects appliances with DTLS enabled. DTLS is on by default for VPN virtual servers, so a NetScaler Gateway is affected unless DTLS was explicitly turned off.

Timeline

watchTowr said on 2026-09-26 that it was responding to reports of unpatched NetScaler RCE issues and called the information credible. It later said the two flaws were found during forensic investigations. Citrix did not state whether its two flaws are the ones watchTowr described, but they match that account. Administrators on r/Citrix reported being told to shut down NetScalers immediately.
Citrix said exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated deployments had been observed. It did not say how widely the flaws were exploited, by whom, or since when. Both flaws were therefore used before any public fix existed.

Affected versions and fixes

Appliances on 14.1-73.32 and 13.1-63.21, the builds that fixed the August authentication bypass CVE-2026-19490, are inside the affected range and need the new update. Fixed releases are:

  • NetScaler ADC and NetScaler Gateway 14.1-73.37 and later
  • NetScaler ADC and NetScaler Gateway 13.1-64.23 and later 13.1 releases
  • NetScaler ADC 14.1-FIPS 14.1-73.37 and later 14.1-FIPS releases
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later releases The 13.1 fix arrived after that branch reached End of Maintenance on 2026-09-15.

What a defender should do

NetScaler ADC and Gateway sit at the edge, handling VPN, remote access, load balancing, and authentication. The bulletin lists no workaround and no indicators of compromise for the two exploited flaws. Because exploitation preceded disclosure, patching restores safety but does not show whether an attacker already established access. Teams should preserve authentication and VPN logs before applying changes, then hunt for anomalous command execution and outbound connections.

Exposure context

ZoomEye returned 239,277 matches for app="Citrix NetScaler" on 2026-09-30 (UTC). The figure counts assets that match the fingerprint, not confirmed vulnerable appliances, and the affected configuration still has to be verified per device.

References

  • Citrix NetScaler security bulletin covering the September 2026 releases.
  • watchTowr reports on unpatched NetScaler RCE activity.
  • The Hacker News coverage of the confirmed exploitation.

Top comments (0)