Vulnerability Management, Firewalls, Routers, Patch/Configuration Management, Threat Intelligence

Citrix NetScaler vulnerabilities exploited by attackers

Attackers are actively exploiting two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway, identified as CVE-2026-88771 and CVE-2026-88772. Citrix confirmed these flaws on September 27, noting that both enable remote code execution, as detailed in Smarter MSP.

These vulnerabilities allow unauthenticated attackers to execute arbitrary commands and can lead to remote code execution or denial-of-service attacks. Researchers have observed attackers using tunneling to route traffic from compromised NetScaler appliances into internal networks. Over 50,277 internet-exposed instances may be vulnerable. CVE-2026-88771 affects all NetScaler ADC and Gateway deployments, while CVE-2026-88772 affects appliances with DTLS enabled, which is the default for VPN virtual servers. Affected releases include NetScaler 14.1 and 13.1.

Citrix recommends updating to NetScaler ADC and Gateway 14.1-73.37 or later, or 13.1-64.23 or later. Organizations should review Citrix advisories, check for signs of compromise before patching, and investigate potential credential exposure.

Source: Smarter MSP

You can skip this ad in 5 seconds