Skip to main content

Citrix NetScaler Two Zero-Day Vulnerabilities Exploited Before Patches Existed (CVE-2026-88771 / CVE-2026-88772)

Scope: Citrix NetScaler ADC and NetScaler Gateway, Including Devices Already Running the August 2026 Authentication Bypass Fix

Severity: Red

Citrix confirmed on September 28, 2026 that two remote code execution vulnerabilities in NetScaler ADC and Gateway had been exploited as zero-days, meaning attacks were already happening before either flaw had a CVE identifier or a public advisory. CVE-2026-88771, rated 9.5, is caused by improper input validation and allows a completely unauthenticated attacker to run arbitrary commands. CVE-2026-88772, also rated 9.5, is a memory overflow that can lead to either remote code execution or a denial-of-service condition when DTLS is enabled on the device. Citrix stated that one of the flaws allowed attackers to place shellcode directly into memory, but has not disclosed how long the exploitation has been ongoing or who is behind it. Importantly, the affected version range includes appliances on builds 14.1-73.32 and 13.1-63.21, the exact versions that fixed the earlier authentication bypass flaw CVE-2026-19490 in August, meaning organizations that patched promptly back then are still exposed now and need this separate update. Reports from NetScaler administrators indicate some organizations were advised by their security teams over the weekend to shut affected devices down entirely rather than wait to patch. Organizations running NetScaler ADC or Gateway must apply Citrix's newly released fixed builds immediately, regardless of how recently the appliance was last updated.

The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.