# NetScaler ADC flaws exploited in the wild

Published: 2026-09-27 · Severity: severe · Sectors: technology, infrastructure
Canonical: https://vorant.io/reports/227722a3-62c7-5700-9dc9-bd97a1812d65/netscaler-adc-flaws-exploited-in-the-wild

> Citrix NetScaler ADC/Gateway have two actively exploited vulnerabilities (CVE-2026-88771, CVE-2026-88772) allowing remote code execution or DoS; patch immediately.

IPA (Japan's Information-technology Promotion Agency) issued an advisory covering eight vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway (formerly Citrix ADC/Gateway) appliances. Two of these, CVE-2026-88771 and CVE-2026-88772, are confirmed to be under active exploitation in the wild, with CISA reporting threat actors globally are actively abusing them. Successful exploitation can allow a remote unauthenticated attacker to execute arbitrary code or cause a denial-of-service condition. CVE-2026-88772 requires DTLS to be enabled, which is the default configuration for VPN virtual servers, broadening its practical exposure.

Affected versions span the 14.1 branch prior to 14.1-73.37, the 13.1 branch prior to 13.1-64.23, and corresponding FIPS/NDcPP builds. Citrix has released fixed versions for all affected branches and is providing Indicators of Compromise via NetScaler Console, along with guidance on checking whether a given deployment meets the vulnerable conditions.

Given the confirmed active exploitation, widespread deployment of NetScaler appliances as internet-facing VPN/ADC gateways, and the severity of potential impact (RCE/DoS), defenders should treat this as an urgent patching priority. Organizations should apply the vendor-supplied fixed builds immediately, review NetScaler Console for provided IOCs, and verify DTLS configuration status on VPN virtual servers as part of exposure assessment.

## Mentioned in this report

- Vulnerabilities: CVE-2026-88771 (KEV), CVE-2026-88772 (KEV), CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, CVE-2026-88778

Source reporting: https://www.ipa.go.jp/security/security-alert/2026/alert20260928.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/227722a3-62c7-5700-9dc9-bd97a1812d65/netscaler-adc-flaws-exploited-in-the-wild.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
