# Citrix NetScaler flaws exploited for RCE

Published: 2026-09-23 · Severity: severe · Sectors: technology, government-national
Canonical: https://vorant.io/reports/cec5ee4e-b233-5b5f-a3ba-bd4ecfbda367/citrix-netscaler-flaws-exploited-for-rce

> Two actively exploited NetScaler ADC/Gateway vulnerabilities allow unauthenticated remote code execution; patch immediately.

CIS/MS-ISAC has issued an advisory covering eight vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway, the most severe of which enable unauthenticated remote code execution. CVE-2026-88771 is an unauthenticated RCE affecting all NetScaler ADC/Gateway deployments by default, requiring no additional configuration. CVE-2026-88772 is a memory overflow vulnerability leading to RCE or DoS on deployments with DTLS enabled (the default on VPN virtual servers). Both are confirmed as actively exploited in the wild. The remaining six vulnerabilities include HTTP request smuggling, policy bypass, multiple memory overflow/DoS conditions affecting Gateway, Load Balancing (Oracle-type), and CGNAT-LSN/NAT64 deployments, and a TCP ISN prediction issue.

Affected versions span NetScaler ADC/Gateway 14.1 prior to 14.1-73.37, 13.1 prior to 13.1-64.23, and corresponding FIPS/NDcPP builds. Given the widespread default exposure of CVE-2026-88771 and confirmed in-the-wild exploitation, this represents a high-urgency patching priority for organizations running internet-facing NetScaler appliances, which are commonly used for VPN/SSO access and application delivery. Defenders should prioritize immediate patching to the fixed versions, review exposure of DTLS-enabled VPN virtual servers, and apply network segmentation and vulnerability scanning as compensating controls while patches are validated.

No threat actor attribution, malware families, or specific IOCs were provided in this advisory. The advisory maps to MITRE ATT&CK's Exploit Public-Facing Application technique under Initial Access, consistent with prior NetScaler exploitation patterns seen in the wild against edge/remote-access infrastructure.

## Mentioned in this report

- Vulnerabilities: CVE-2026-88771 (KEV), CVE-2026-88772 (KEV), CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, CVE-2026-88778

Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-netscaler-adc-and-netscaler-gateway-could-allow-for-remote-code-execution_2026-103

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/cec5ee4e-b233-5b5f-a3ba-bd4ecfbda367/citrix-netscaler-flaws-exploited-for-rce.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
