VORANT. Threat Intelligence Research Sign in Create a free account

Citrix NetScaler flaws exploited for RCE

severe vulnerability technologygovernment-national

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

Two actively exploited NetScaler ADC/Gateway vulnerabilities allow unauthenticated remote code execution; patch immediately.

CIS/MS-ISAC has issued an advisory covering eight vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway, the most severe of which enable unauthenticated remote code execution. CVE-2026-88771 is an unauthenticated RCE affecting all NetScaler ADC/Gateway deployments by default, requiring no additional configuration. CVE-2026-88772 is a memory overflow vulnerability leading to RCE or DoS on deployments with DTLS enabled (the default on VPN virtual servers). Both are confirmed as actively exploited in the wild. The remaining six vulnerabilities include HTTP request smuggling, policy bypass, multiple memory overflow/DoS conditions affecting Gateway, Load Balancing (Oracle-type), and CGNAT-LSN/NAT64 deployments, and a TCP ISN prediction issue.

Affected versions span NetScaler ADC/Gateway 14.1 prior to 14.1-73.37, 13.1 prior to 13.1-64.23, and corresponding FIPS/NDcPP builds. Given the widespread default exposure of CVE-2026-88771 and confirmed in-the-wild exploitation, this represents a high-urgency patching priority for organizations running internet-facing NetScaler appliances, which are commonly used for VPN/SSO access and application delivery. Defenders should prioritize immediate patching to the fixed versions, review exposure of DTLS-enabled VPN virtual servers, and apply network segmentation and vulnerability scanning as compensating controls while patches are validated.

No threat actor attribution, malware families, or specific IOCs were provided in this advisory. The advisory maps to MITRE ATT&CK's Exploit Public-Facing Application technique under Initial Access, consistent with prior NetScaler exploitation patterns seen in the wild against edge/remote-access infrastructure.

Mentioned in this report

Vulnerabilities CVE-2026-88771KEVCVE-2026-88772KEVCVE-2026-88773CVE-2026-88774CVE-2026-88775CVE-2026-88776CVE-2026-88777CVE-2026-88778

Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-netscaler-adc-and-netscaler-gateway-could-allow-for-remote-code-execution_2026-103

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 11,174 reports from 151 sources, 2,685 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs