Skip to finding
§
High
Edge — RCE
Confirmed
CVE-2026-88771

Two exploited NetScaler zero-days give unauthenticated network callers code execution on the appliance.

One arbitrary-command path is present in default deployments; the other is a memory overflow behind DTLS, which is enabled by default on VPN virtual servers.

Affects

NetScaler ADC and NetScaler Gateway, customer-managed application-delivery and remote-access appliances.

What it enables

Unauthenticated code execution on a customer-managed NetScaler appliance

Reach a customer-managed NetScaler ADC or Gateway virtual service over the network without credentials.→↓For CVE-2026-88771, send input to the vulnerable path present in every deployment, including the default configuration; alternatively, reach a DTLS-enabled service for CVE-2026-88772.→↓Improper input validation permits arbitrary commands, or the DTLS memory overflow yields remote code execution.→↓Execute code in the appliance service context; Citrix says exploitation of both flaws has been observed on unmitigated deployments.
Why this matters

These are pre-authentication paths through default or normally enabled services, and exploitation was observed before unmitigated customers had closed them.

Detail and 3 sources
Required access

Network reachability to a customer-managed NetScaler ADC or Gateway service; CVE-2026-88771 affects default configurations, while CVE-2026-88772 requires DTLS, which is enabled by default on VPN virtual servers

Affected versions

NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37, NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23, NetScaler ADC FIPS 14.1 before 14.1-73.37 FIPS, NetScaler ADC FIPS and NDcPP 13.1 before 13.1-37.279

A network caller can reach CVE-2026-88771 without credentials or an optional feature and execute arbitrary commands through improper input validation. On a DTLS-enabled service, CVE-2026-88772 can turn crafted traffic into code execution or denial of service through a memory overflow.

Citrix has published fixed builds for the affected NetScaler versions.

Evidence
Citrix's bulletin identifies both unauthenticated execution primitives, their deployment preconditions, affected versions, fixed builds and observed exploitationCitrix's accompanying threat-intelligence post confirms exploitation on unmitigated deployments and states that CVE-2026-88771 needs no optional featureThe Canadian Cyber Centre independently reports exploitation across multiple customer environmentsNo public exploit code or researcher reproduction was located
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Monday, September 28, 2026