Executive Summary: NetScaler RCE Risk and Patch Deadline
Two critical vulnerabilities (CVE-2026-88771 and CVE-2026-88772, both CVSS 9.5) were disclosed affecting Citrix NetScaler ADC and NetScaler Gateway, allowing attackers to achieve unauthenticated remote code execution via improper input validation and memory overflow flaws. Due to confirmed active exploitation globally and their inclusion in CISA’s Known Exploited Vulnerabilities catalog, immediate patching is required. Federal agencies face a remediation deadline of September 30, 2026.
About CVE-2026-88771 and CVE-2026-88772
The most severe issue, CVE-2026-88771, originates from improper input validation in the NetScaler management interface, where insufficient sanitization of user-supplied data leads to arbitrary code execution. This vulnerability affects every default NetScaler ADC and Gateway deployment. No additional features or special configuration need to be enabled. By sending specially crafted requests, attackers can execute arbitrary code on the appliance, potentially pivoting into internal networks and cloud workloads. No authentication is required to exploit this issue.
CVE-2026-88772 stems from a memory overflow condition that leads to remote code execution or denial of service. It requires DTLS to be enabled, which is turned on by default on VPN virtual servers, making the vast majority of VPN deployments vulnerable out of the box.
Six additional high-severity vulnerabilities were also patched in the same advisory (CTX697096):
- CVE-2026-88773 (CVSS 9.3): HTTP request smuggling that bypasses front-end security controls, affecting load balancing, content switching, VPN, and authentication virtual servers.
- CVE-2026-88774 (CVSS 7.0): Feature policy bypass via improper HTTP URL-based expression usage.
- CVE-2026-88775 (CVSS 8.8): Memory overflow causing denial of service on Gateway or AAA virtual servers.
- CVE-2026-88776 (CVSS 8.8): Memory overflow on Oracle-type load balancing virtual servers.
- CVE-2026-88777 (CVSS 8.8): Memory overflow affecting non-HTTP L7 protocols including FTP, RTSP, DNS64, and NAT64.
- CVE-2026-88778 (CVSS 8.8): TCP Initial Sequence Number predictability.
Affected Systems
The following components are affected: Citrix NetScaler ADC and NetScaler Gateway, versions 14.1 before 14.1-73.37, 13.1 before 13.1-64.23, FIPS 14.1 before 14.1-73.37 FIPS, and FIPS/NDcPP 13.1 before 13.1-37.279. Citrix Secure Private Access Hybrid deployments using affected NetScaler instances are also impacted. These appliances are widely deployed as internet-facing network edge devices handling VPN, load balancing, and application delivery across enterprise and government environments.
Users should upgrade immediately to NetScaler ADC and Gateway 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, or 13.1-37.279 (FIPS/NDcPP) as applicable. Citrix recommends checking for signs of compromise before applying patches, as updates may eliminate forensic evidence. Organizations that suspect compromise should isolate affected devices, revoke credentials, investigate connected systems, rebuild firmware, and rotate passwords, encryption keys, and SSL certificates.
CISA KEV Status and Business Impact of NetScaler Exploitation
At the time of writing, exploitation was observed globally before public disclosure, confirming zero-day status. Both CVEs have been added to CISA’s KEV catalog with active exploitation confirmed. The severity and ease of exploitation make these vulnerabilities extremely high risk, especially in internet-facing deployments where NetScaler appliances typically reside.
Successful exploitation could allow attackers to execute arbitrary code on the appliance, pivot laterally into internal networks and cloud workloads, and potentially exfiltrate sensitive data or deploy ransomware, leading to service disruption, data exposure, or full infrastructure compromise.
How Orca Can Help
Orca enables customers to quickly identify assets running vulnerable versions of Citrix NetScaler, understand their exposure in context (including internet accessibility, runtime reachability, and asset criticality), and prioritize remediation based on real risk rather than CVSS alone. Orca’s platform highlights affected assets directly in the alert view, helping security teams focus on the most critical remediation paths first.
