Share This:

Cybersecurity Threat AdvisoryAttackers are actively exploiting two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway. Citrix confirmed the vulnerabilities, CVE-2026-88771 and CVE-2026-88772, on September 27. Both flaws enable remote code execution, and attackers have used them to deploy web shells and tunneling tools.

What is the threat?

CVE-2026-88771 (CVSS 9.5) is an improper input validation vulnerability that allows unauthenticated attackers to execute arbitrary commands.

CVE-2026-88772 (CVSS 9.5) is a memory overflow vulnerability that can result in remote code execution or denial-of-service (DoS).

Researchers observed attackers using tunneling activity to route traffic from compromised NetScaler appliances into internal networks. Citrix confirmed exploitation on unpatched deployments.

Why is it noteworthy?

As of September 27, Palo Alto Networks identified more than 50,277 internet-exposed instances that may be vulnerable to these flaws. According to information shared in a Reddit thread, the Dutch National Cyber Security Centre (NCSC-NL) learned of the vulnerabilities from a European partner CERT. The agency also reported exploitation at multiple Citrix customers worldwide.

What is the exposure or risk?

CVE-2026-88771 affects all NetScaler ADC and NetScaler Gateway deployments and does not require any additional features to be enabled.

CVE-2026-88772 affects appliances with DTLS enabled. Because DTLS is enabled by default for VPN virtual servers, NetScaler Gateway deployments are at risk unless administrators have explicitly disabled DTLS.

Affected releases include:

  • NetScaler 14.1
  • NetScaler 13.1
  • NetScaler 14.1 FIPS
  • NetScaler 13.1 FIPS/NDcPP

What are the recommendations?

Barracuda recommends the following actions to reduce the risk from CVE-2026-88771 and CVE-2026-88772:

  • Install the latest fixes as soon as possible:
    • NetScaler ADC and NetScaler Gateway 14.1-73.37 or later
    • NetScaler ADC and NetScaler Gateway 13.1-64.23 or later
    • NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS or later
    • NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 or later
  • Review Citrix advisories and, where possible, check for signs of compromise before applying patches.
  • Investigate post-compromise activity documented by researchers and assess whether credentials or active sessions may have been exposed.

References

For more information, review the following resources:

If you have any questions about this Cybersecurity Threat Advisory, don’t hesitate to get in touch with Barracuda Managed XDR’s Security Operations Center.


Share This:
Zachary Beaudet

Posted by Zachary Beaudet

Zachary is a Cybersecurity Analyst at Barracuda MSP. He's a security expert, working on our Blue Team within our Security Operations Center. Zachary supports our XDR service delivery and is highly skilled at analyzing security events to detect cyber threats, helping keep our partners and their customers protected.

Leave a reply

Your email address will not be published. Required fields are marked *

 

This site uses Akismet to reduce spam. Learn how your comment data is processed.