Two exploited NetScaler zero-days give unauthenticated network callers code execution on the appliance.
One arbitrary-command path is present in default deployments; the other is a memory overflow behind DTLS, which is enabled by default on VPN virtual servers.
Affects
NetScaler ADC and NetScaler Gateway, customer-managed application-delivery and remote-access appliances.
What it enables
Unauthenticated code execution on a customer-managed NetScaler appliance
Reach a customer-managed NetScaler ADC or Gateway virtual service over the network without credentials.→↓For CVE-2026-88771, send input to the vulnerable path present in every deployment, including the default configuration; alternatively, reach a DTLS-enabled service for CVE-2026-88772.→↓Improper input validation permits arbitrary commands, or the DTLS memory overflow yields remote code execution.→↓Execute code in the appliance service context; Citrix says exploitation of both flaws has been observed on unmitigated deployments.
Why this matters
These are pre-authentication paths through default or normally enabled services, and exploitation was observed before unmitigated customers had closed them.
Detail and 3 sources
Required access
Network reachability to a customer-managed NetScaler ADC or Gateway service; CVE-2026-88771 affects default configurations, while CVE-2026-88772 requires DTLS, which is enabled by default on VPN virtual servers
Affected versions
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37, NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23, NetScaler ADC FIPS 14.1 before 14.1-73.37 FIPS, NetScaler ADC FIPS and NDcPP 13.1 before 13.1-37.279
A network caller can reach CVE-2026-88771 without credentials or an optional feature and execute arbitrary commands through improper input validation. On a DTLS-enabled service, CVE-2026-88772 can turn crafted traffic into code execution or denial of service through a memory overflow.
Citrix has published fixed builds for the affected NetScaler versions.
Evidence
Citrix's bulletin identifies both unauthenticated execution primitives, their deployment preconditions, affected versions, fixed builds and observed exploitationCitrix's accompanying threat-intelligence post confirms exploitation on unmitigated deployments and states that CVE-2026-88771 needs no optional featureThe Canadian Cyber Centre independently reports exploitation across multiple customer environmentsNo public exploit code or researcher reproduction was located
Preconditions
access:network:internet
reachable from the public internet
interaction:none
no user action required
Patch reality
Pre-fix images still accepted
Yes
Reaches end-of-life hardware
No
The downgrade finding is explicitly documented for standalone NetScaler appliances. The sources establish lack of fixes for EOL software branches, but do not separately enumerate every EOL hardware model.
The same brief, every morning. One email a day, nothing else.
Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.