Citrix patches two actively exploited NetScaler zero-day RCE flaws

Citrix has confirmed that two critical NetScaler remote code execution zero-days, CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks and has released security updates. The vulnerabilities affect NetScaler ADC and NetScaler Gateway appliances, which are often exposed to the internet as edge devices. CVE-2026-88771 stems from improper input validation and allows unauthenticated attackers to run arbitrary commands, with a severity score of 9.5.
Citrix has issued fixes for CVE-2026-88771 and CVE-2026-88772 after confirming both were used in real attacks. The first stems from faulty input handling and lets an unauthenticated actor run commands; the second is a memory overflow that can cause code execution or service disruption. Both carry a 9.5 severity rating.
The flaws affect NetScaler ADC and Gateway, including default setups. DTLS-enabled deployments, default on VPN virtual servers, are exposed to the second bug. Patched builds cover 14.1 and 13.1 branches, FIPS/NDcPP variants, and Secure Private Access Hybrid instances. Citrix-managed cloud services are being upgraded separately; the bulletin also addresses six other flaws.
Organizations relying on internet-facing NetScaler appliances may face heightened risk because these devices often guard remote access and application delivery. A successful compromise could expose internal systems, disrupt services, or require urgent patching and incident response. Administrators, remote workers, and customers of affected organizations may feel indirect effects through outages or data exposure. The confirmed exploitation underscores how edge-device flaws can create broad, cross-sector security concerns.