
Attackers are actively exploiting two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway. Citrix confirmed the vulnerabilities, CVE-2026-88771 and CVE-2026-88772, on September 27. Both flaws enable remote code execution, and attackers have used them to deploy web shells and tunneling tools.
What is the threat?
CVE-2026-88771 (CVSS 9.5) is an improper input validation vulnerability that allows unauthenticated attackers to execute arbitrary commands.
CVE-2026-88772 (CVSS 9.5) is a memory overflow vulnerability that can result in remote code execution or denial-of-service (DoS).
Researchers observed attackers using tunneling activity to route traffic from compromised NetScaler appliances into internal networks. Citrix confirmed exploitation on unpatched deployments.
Why is it noteworthy?
As of September 27, Palo Alto Networks identified more than 50,277 internet-exposed instances that may be vulnerable to these flaws. According to information shared in a Reddit thread, the Dutch National Cyber Security Centre (NCSC-NL) learned of the vulnerabilities from a European partner CERT. The agency also reported exploitation at multiple Citrix customers worldwide.
What is the exposure or risk?
CVE-2026-88771 affects all NetScaler ADC and NetScaler Gateway deployments and does not require any additional features to be enabled.
CVE-2026-88772 affects appliances with DTLS enabled. Because DTLS is enabled by default for VPN virtual servers, NetScaler Gateway deployments are at risk unless administrators have explicitly disabled DTLS.
Affected releases include:
- NetScaler 14.1
- NetScaler 13.1
- NetScaler 14.1 FIPS
- NetScaler 13.1 FIPS/NDcPP
What are the recommendations?
Barracuda recommends the following actions to reduce the risk from CVE-2026-88771 and CVE-2026-88772:
- Install the latest fixes as soon as possible:
- NetScaler ADC and NetScaler Gateway 14.1-73.37 or later
- NetScaler ADC and NetScaler Gateway 13.1-64.23 or later
- NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS or later
- NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 or later
- Review Citrix advisories and, where possible, check for signs of compromise before applying patches.
- Investigate post-compromise activity documented by researchers and assess whether credentials or active sessions may have been exposed.
References
For more information, review the following resources:
- https://thehackernews.com/2026/09/warning-two-unpatched-citrix-netscaler.html
- https://www.ibtimes.sg/citrix-netscaler-zero-day-patch-now-then-check-if-hackers-were-already-inside-94445
- https://www.securityweek.com/citrix-confirms-2-netscaler-zero-days-after-admins-pulled-the-plug/
If you have any questions about this Cybersecurity Threat Advisory, don’t hesitate to get in touch with Barracuda Managed XDR’s Security Operations Center.
This post originally appeared on Smarter MSP.

