Citrix released security updates addressing two critical NetScaler vulnerabilities actively exploited in attacks, prompting urgent patching requirements for organizations using NetScaler ADC and NetScaler Gateway appliances. Tracked as CVE-2026-88771 and CVE-2026-88772, both flaws carry a CVSS v4 severity score of 9.5 and enable remote code execution on vulnerable systems. The vendor's security bulletin confirms active exploitation in the wild, changing the operational environment for administrators who previously relied on private warnings and emergency shutdown advice circulating over the weekend.
Two Critical Attack Vectors Threatening NetScaler Deployments
The two vulnerabilities provide distinct paths for attackers to achieve remote code execution. CVE-2026-88771 stems from improper input validation that permits unauthenticated arbitrary command execution. This flaw affects NetScaler deployments in their default configuration without needing any additional features enabled. CVE-2026-88772 involves a memory overflow that triggers remote code execution or a denial of service when DTLS is enabled. Because DTLS is enabled by default on VPN virtual servers, administrators cannot rely on disabling the protocol to secure their appliances, as the first vulnerability remains entirely independent of DTLS configurations.
Prior to Citrix issuing official patches, security firms and national agencies tracked early indicators. Tenable traced public discussions back to September 25, followed by warnings from watchTowr and security researcher Kevin Beaumont referencing a restricted pre-notification attributed to the Dutch National Cyber Security Centre. Sweden’s CERT-SE subsequently issued an alert confirming active exploitation of both flaws and directing system operators to verify build versions.
Patch Boundaries and Specific Fixed Releases
Sweden’s CERT-SE outlined exact version thresholds required to remediate the vulnerabilities across different NetScaler branches. For standard NetScaler ADC and Gateway 14.1 deployments, the fixed release boundary is version 14.1-73.37. For the 13.1 branch, the update requires build 13.1-64.23. Specialized editions maintain separate thresholds, with FIPS and NDcPP variants requiring build 14.1-73.37 FIPS and build 13.1-37.279 respectively. Citrix confirmed that these patches apply to customer-managed appliances, including NetScaler instances deployed in Secure Private Access Hybrid environments, while Citrix-managed cloud services are updated by the provider.

Beyond the two remote code execution flaws, Citrix’s advisory covers a total of eight vulnerabilities, requiring security teams to perform a comprehensive configuration review rather than applying a narrow fix. Organizations must also investigate systems for prior intrusion indicators. Citrix provides generic indicators through NetScaler Console, though the vendor cautions that indicator checks can miss actual compromises and recommends experienced forensic investigators.
Upgrade Caveats and Operational Risks
Deploying the security updates requires careful preparation to prevent secondary operational outages. Citrix flagged a potential reboot loop during upgrades to build 13.1-64.23 on systems with configured variables. The vendor directs affected customers to target build 13.1-64.24 instead, advising administrators to run the command show ns variable to identify whether variables are present before initiating the upgrade. Additionally, the updates enforce signed SAML assertions, requiring organizations to verify that their identity providers properly issue signed assertions to maintain remote access functionality after the patch is applied.