Skip to finding
§
High
Edge
Confirmed
CVE-2026-88771

Actively exploited NetScaler flaws give unauthenticated internet callers code execution on perimeter gateways.

Citrix confirms exploitation of both paths on unmitigated deployments.

Affects

Citrix NetScaler ADC and NetScaler Gateway, customer-managed application-delivery, VPN, and remote-access appliances

What it enables

Unauthenticated remote code execution on an enterprise perimeter gateway

An unauthenticated caller reaches a NetScaler deployment in its default configuration, or a DTLS-enabled virtual server.→↓Crafted input reaches the improper-validation path in CVE-2026-88771 or the DTLS memory-overflow path in CVE-2026-88772.→↓The appliance executes attacker-controlled commands or code; Citrix confirms exploitation of both flaws on unmitigated deployments.
Why this matters

The change is current exploitation: a caller without credentials can now cross a deliberately deployed perimeter boundary through either of two code-execution paths.

Detail, proof-of-concept code and 7 sources
Required access

Internet reachability to an affected NetScaler virtual server; no credentials. CVE-2026-88772 additionally requires DTLS, which is enabled by default on VPN virtual servers.

Affected versions

14.1 before 14.1-73.37, 13.1 before 13.1-64.23, 14.1-FIPS before 14.1-73.37 FIPS, 13.1-FIPS and 13.1-NDcPP before 13.1-37.279, NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23, NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37, NetScaler ADC FIPS 14.1 before 14.1-73.37 FIPS, NetScaler ADC FIPS and NDcPP 13.1 before 13.1-37.279, NetScaler ADC and Gateway 14.1 before 14.1-73.37, NetScaler ADC and Gateway 13.1 before 13.1-64.23, NetScaler ADC 14.1-FIPS before 14.1-73.37 FIPS, NetScaler ADC 13.1-FIPS and 13.1-NDcPP before 13.1-37.279

Internet reachability to an affected virtual server is sufficient; CVE-2026-88772 additionally needs DTLS, which is enabled by default on VPN virtual servers.

CVE-2026-88771 reaches attacker-controlled commands through improper input validation, while CVE-2026-88772 reaches code execution through a DTLS memory overflow.

Citrix says both flaws are being exploited on unmitigated systems.

Fixes are available, but complete revocation of pre-fix NetScaler images has not been established.

Evidence
Citrix states both primitives and confirms exploitation on unmitigated deploymentsPublic exploit or independent technical reproduction
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Tuesday, September 29, 2026