Actively exploited NetScaler flaws give unauthenticated internet callers code execution on perimeter gateways.
Citrix confirms exploitation of both paths on unmitigated deployments.
Citrix NetScaler ADC and NetScaler Gateway, customer-managed application-delivery, VPN, and remote-access appliances
Unauthenticated remote code execution on an enterprise perimeter gateway
The change is current exploitation: a caller without credentials can now cross a deliberately deployed perimeter boundary through either of two code-execution paths.
Detail, proof-of-concept code and 7 sources
Internet reachability to an affected virtual server is sufficient; CVE-2026-88772 additionally needs DTLS, which is enabled by default on VPN virtual servers.
CVE-2026-88771 reaches attacker-controlled commands through improper input validation, while CVE-2026-88772 reaches code execution through a DTLS memory overflow.
Citrix says both flaws are being exploited on unmitigated systems.
Fixes are available, but complete revocation of pre-fix NetScaler images has not been established.
- access:network:internet
- reachable from the public internet
- interaction:none
- no user action required
- Pre-fix images still accepted
- Yes
- Reaches end-of-life hardware
- No