Citrix has disclosed two critical remote-code-execution vulnerabilities in NetScaler ADC and NetScaler Gateway that were exploited before public disclosure. The flaws, CVE-2026-88771 and CVE-2026-88772, each carry a CVSS v4 score of 9.5; CISA says exploitation is occurring globally and added both to its Known Exploited Vulnerabilities catalog.
CVE-2026-88771 is especially urgent because it affects vulnerable default deployments and has low attack complexity. CVE-2026-88772 is a memory-corruption issue that requires DTLS to be enabled. Citrix released fixes for supported 14.1 and 13.1 releases, including 14.1-73.37 and 13.1-64.23.
What to do now
- Apply Citrix’s emergency updates outside the normal patch cycle.
- Investigate exposed appliances for signs of compromise, not merely patch status.
- Prioritize internet-facing ADC and Gateway instances and validate the deployed build after updating.
The combination of confirmed exploitation, appliance exposure, and unauthenticated command execution makes this an incident-response priority.
Source: Rapid7 analysis; CISA alert.
