NetScaler ADC flaws exploited in the wild
Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.
Citrix NetScaler ADC/Gateway have two actively exploited vulnerabilities (CVE-2026-88771, CVE-2026-88772) allowing remote code execution or DoS; patch immediately.
IPA (Japan's Information-technology Promotion Agency) issued an advisory covering eight vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway (formerly Citrix ADC/Gateway) appliances. Two of these, CVE-2026-88771 and CVE-2026-88772, are confirmed to be under active exploitation in the wild, with CISA reporting threat actors globally are actively abusing them. Successful exploitation can allow a remote unauthenticated attacker to execute arbitrary code or cause a denial-of-service condition. CVE-2026-88772 requires DTLS to be enabled, which is the default configuration for VPN virtual servers, broadening its practical exposure.
Affected versions span the 14.1 branch prior to 14.1-73.37, the 13.1 branch prior to 13.1-64.23, and corresponding FIPS/NDcPP builds. Citrix has released fixed versions for all affected branches and is providing Indicators of Compromise via NetScaler Console, along with guidance on checking whether a given deployment meets the vulnerable conditions.
Given the confirmed active exploitation, widespread deployment of NetScaler appliances as internet-facing VPN/ADC gateways, and the severity of potential impact (RCE/DoS), defenders should treat this as an urgent patching priority. Organizations should apply the vendor-supplied fixed builds immediately, review NetScaler Console for provided IOCs, and verify DTLS configuration status on VPN virtual servers as part of exposure assessment.
Mentioned in this report
Source reporting: https://www.ipa.go.jp/security/security-alert/2026/alert20260928.html
What this brief leaves out
This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.
It sits in a corpus of 11,104 reports from 154 sources, 2,663 of them written in the last seven days, and it grows through the day.
A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.
Create a free account What it costs