Citrix confirmed the exploitation of two zero-day vulnerabilities in NetScaler ADC and NetScaler Gateway appliances after special warnings were sent to organizations and security teams over the weekend. The company issued security bulletin CTX697096 and updates addressing the two vulnerabilities, in addition to six other vulnerabilities, bringing the total number of flaws addressed in the update to eight.
Two vulnerabilities with a severity rating of 9.5
The first vulnerability, CVE-2026-88771, has a severity rating of 9.5 and results from improper input validation. An unauthenticated attacker can exploit it to execute arbitrary commands remotely. Citrix says the vulnerability affects all NetScaler ADC and NetScaler Gateway deployments, including default configurations, and does not require an additional feature to be enabled.
CVE-2026-88772 is a memory overflow vulnerability with a severity rating of 9.5 that could lead to remote command execution or denial of service. Exploiting it requires DTLS to be enabled on the appliance, noting that DTLS is enabled by default on VPN virtual servers.
Affected versions
The affected versions include NetScaler ADC and NetScaler Gateway 14.1 before version 14.1-73.37, and version 13.1 before 13.1-64.23. The list also includes NetScaler ADC FIPS before 14.1-73.37 FIPS, and NetScaler ADC FIPS and NDcPP before 13.1-37.279. Secure Private Access Hybrid deployments that use NetScaler instances are also affected and must be upgraded to the recommended versions.
The advisory applies to NetScaler ADC and NetScaler Gateway appliances managed by customers. Cloud services managed by Citrix, including Citrix-managed Adaptive Authentication, will be upgraded by Cloud Software Group.
What does the official confirmation change?
NetScaler appliances often serve as internet-exposed access points for providing remote access and delivering applications to internal networks. Therefore, compromising them could give an attacker a foothold at the network perimeter without first needing to compromise an internal endpoint. Citrix confirms that exploitation of the two vulnerabilities was observed in deployments where mitigation or remediation measures had not been taken.
Vendors, security teams, and national agencies had asked some organizations to shut down NetScaler appliances, while watchTowr warned that credible information about the exploitation of unpatched remote code execution vulnerabilities was circulating. A notice attributed to the National Cyber Security Centre in the Netherlands also reported that exploitation had been observed among several Citrix customers worldwide, without specifying the extent of the attacks.
What administrators should review
Organizations should upgrade affected NetScaler appliances to the patched versions as soon as possible. If the update cannot be implemented immediately, the article recommends reducing internet exposure wherever operational requirements permit until the patches are installed. Timing remains important because NetScaler upgrades may cause operational outages, while the publication of technical details and updates may increase exploitation attempts.