Citrix Confirms Two NetScaler RCE Zero-Days Exploited in Attacks

Network router infrastructure protected by firewall and access controls

Citrix has confirmed that two critical vulnerabilities in NetScaler ADC and NetScaler Gateway appliances were exploited before patches became available. The flaws, CVE-2026-88771 and CVE-2026-88772, can lead to remote code execution on exposed edge systems.

Both flaws affect perimeter infrastructure

Citrix describes CVE-2026-88771 as an improper-input-validation issue affecting customer-managed NetScaler deployments. CVE-2026-88772 is a memory-overflow condition associated with DTLS-enabled systems, including configurations where DTLS is enabled on VPN virtual servers. The vendor published fixed builds for supported 14.1 and 13.1 branches and related FIPS or NDcPP editions.

Because NetScaler appliances commonly broker remote access and application delivery, compromise can place an attacker at a sensitive network boundary. Patching the appliance closes the vulnerability but does not remove persistence that may have been established before remediation.

Response needs patching and compromise assessment

Administrators should inventory customer-managed appliances, compare installed builds with the bulletin and preserve relevant logs before making changes. Systems with suspected exploitation require incident-response review, credential rotation and inspection for unauthorized commands or configuration changes.

Organizations should also validate management-plane restrictions and reduce unnecessary internet exposure. SectechMedia tracks similar edge-device risks in its Cyber-Physical Security coverage.

Sources

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *