DEV Community

Mark0
Mark0

Posted on

Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation

Citrix has confirmed that two critical vulnerabilities in NetScaler ADC and NetScaler Gateway (CVE-2026-88771 and CVE-2026-88772) have been exploited in the wild prior to the release of official patches. Both flaws carry a CVSS v4 score of 9.5 and allow for unauthenticated remote code execution (RCE). While CVE-2026-88771 impacts all deployments due to improper input validation, CVE-2026-88772 involves a memory overflow affecting systems with DTLS enabled, which is a default configuration for most VPN servers.

In addition to the critical RCE fixes, Citrix addressed six other vulnerabilities covering HTTP request smuggling, policy bypasses, and TCP sequence prediction issues. Security researchers had observed active exploitation and forensic evidence of these flaws before the public disclosure. Organizations are urged to upgrade to the latest firmware versions immediately and perform comprehensive forensic checks, as applying the patch does not remediate existing compromises gained by attackers before the update.


Read Full Article

Top comments (0)