Citrix Patches Critical Zero-Day Vulnerabilities in NetScaler ADC and Gateway
Citrix has released critical security patches for two zero-day vulnerabilities in its NetScaler ADC and Gateway products. The vulnerabilities, identified as CVE-2026-88771 and CVE-2026-88772, enable remote code execution and have been actively exploited in attacks. With severity scores of 9.5/10, these flaws pose significant risks to organizations relying on these appliances for network security.
Editor, Lazyfounder

Citrix has released critical security patches for two zero-day vulnerabilities in its NetScaler ADC and Gateway products. The vulnerabilities, identified as CVE-2026-88771 and CVE-2026-88772, enable remote code execution and have been actively exploited in attacks. With severity scores of 9.5/10, these flaws pose significant risks to organizations relying on these appliances for network security.
30 SEC SUMMARY
- Citrix has released urgent patches for two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in NetScaler ADC and Gateway.
- The vulnerabilities enable remote code execution and have a severity score of 9.5/10.
- Exploits have been detected in active attacks, prompting warnings from Citrix and regulators like CISA.
- CISA has set a September 30 deadline for federal agencies to apply the patches.
- NetScaler appliances are high-value targets due to their internet exposure and privileged access.
TABLE OF CONTENTS
- Critical Vulnerabilities Patched
- Active Exploitation and Regulatory Response
- Why NetScaler Appliances Are Targeted
- Affected Versions and Patch Availability
- Background: Security Risks in Edge Appliances
- What this means
- Key takeaways
- FAQ
- Sources
KEY HIGHLIGHTS
- Citrix patched two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in NetScaler ADC and Gateway.
- Both vulnerabilities enable remote code execution and have severity scores of 9.5/10.
- Exploits have been observed in active attacks, with CISA setting a September 30 patch deadline for federal agencies.
- The vulnerabilities affect NetScaler versions before 14.1-73.37 and 13.1-64.23, including FIPS builds.
- NetScaler appliances are prime targets due to their internet exposure and privileged access.
Critical Vulnerabilities Patched
Citrix has released patches for two critical zero-day vulnerabilities, identified as CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway products. According to TechRadar, both vulnerabilities enable remote code execution and have been assigned a severity score of 9.5 out of 10.
CVE-2026-88771 is described as an improper input validation flaw, allowing unauthenticated attackers to execute arbitrary commands remotely. The second vulnerability, CVE-2026-88772, involves a buffer overflow or memory-corruption issue that could enable remote code execution or trigger a Denial of Service (DoS) attack.
Active Exploitation and Regulatory Response
TechRadar reports that exploits targeting these vulnerabilities have been observed in active attacks. The Cybersecurity and Infrastructure Security Agency (CISA) has added both vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog and set a deadline of September 30 for Federal Civilian Executive Branch (FCEB) agencies to apply the patches.
The Dutch National Cyber Security Center (NCSC-NL) reportedly notified organizations in the Netherlands about the vulnerabilities before Citrix’s public disclosure, indicating coordinated efforts to mitigate risks.
Why NetScaler Appliances Are Targeted
NetScaler ADC and Gateway appliances are frequently targeted by attackers due to their internet-facing nature, privileged access within networks, and limited monitoring visibility. According to TechRadar, these factors make them ideal candidates for exploitation, particularly in disruptive attacks like ransomware.
Affected Versions and Patch Availability
The vulnerabilities impact Citrix NetScaler ADC and NetScaler Gateway versions released before 14.1-73.37 and 13.1-64.23, including corresponding FIPS builds. Citrix has released patches for these versions and urges organizations to apply them immediately to mitigate risks.
Background: Security Risks in Edge Appliances
Edge appliances like NetScaler ADC and Gateway are often internet-facing and serve as critical components of enterprise networks. However, their exposure and privileged access make them high-value targets for attackers. This incident aligns with broader industry concerns about securing edge devices, similar to best practices for router security and vulnerability management.
What this means
Lazyfounder analysis — our interpretation, not reported fact.
For founders and operators, this incident highlights the critical importance of rapid patch management, especially for internet-facing infrastructure. NetScaler ADC and Gateway are widely used in enterprise environments, often serving as gatekeepers for sensitive networks. Their exposure to the internet makes them prime targets for attackers, and the active exploitation of these vulnerabilities demonstrates how quickly zero-days can be weaponized.
Startups and small teams, in particular, should take note: even if your organization isn’t using NetScaler, the pattern is familiar. Edge appliances—like load balancers, VPN gateways, and firewalls—are often overlooked in security monitoring but are frequently targeted due to their privileged access. This is a reminder to audit your infrastructure, prioritize patching for critical vulnerabilities, and ensure compliance with regulatory deadlines like CISA’s.
The limited visibility into these appliances also underscores the need for layered security. Relying solely on perimeter defenses is no longer sufficient; operators should assume breaches are inevitable and invest in detection and response capabilities to limit damage.
Key takeaways
- Citrix has patched two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in NetScaler ADC and Gateway.
- Both vulnerabilities enable remote code execution and have been assigned a severity score of 9.5/10.
- Exploits have been observed in active attacks, prompting urgent warnings from Citrix and CISA.
- CISA has set a September 30 deadline for federal agencies to apply the patches.
- NetScaler appliances are high-value targets due to their internet exposure and privileged access within networks.
FAQ
What are CVE-2026-88771 and CVE-2026-88772?
CVE-2026-88771 and CVE-2026-88772 are critical zero-day vulnerabilities affecting Citrix NetScaler ADC and Gateway. Both enable remote code execution and have a severity score of 9.5/10. CVE-2026-88771 involves improper input validation, while CVE-2026-88772 is a buffer overflow or memory-corruption flaw.
Which NetScaler versions are affected?
The vulnerabilities affect NetScaler ADC and Gateway versions released before 14.1-73.37 and 13.1-64.23, including corresponding FIPS builds. Citrix has released patches for these versions.
Why are NetScaler appliances targeted by attackers?
NetScaler appliances are prime targets due to their internet exposure, privileged access within networks, and limited monitoring visibility. These factors make them attractive for attackers seeking to execute disruptive attacks like ransomware.
What is CISA’s role in this incident?
CISA added the vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog and set a September 30 deadline for Federal agencies to apply the patches. This underscores the urgency of addressing these vulnerabilities to prevent potential breaches.
What steps should organizations take to protect themselves?
Organizations should immediately apply the patches released by Citrix for NetScaler ADC and Gateway. They should also monitor for unusual activity, especially on internet-facing appliances, and consider implementing layered security measures to mitigate risks.
Related on Lazyfounder
Sources
- TechRadar · 2026-09-28
Citrix says two worrying NetScaler RCE zero-days exploited in attacks
This story is an original summary drafted with AI by Lazyfounder from the reporting listed above and checked by automated validation. Facts are attributed to their original publishers; sections marked as analysis are Lazyfounder's. Where a source is in another language, facts were machine-translated and quotations are reported, not reproduced. Read the original coverage via the links, and see our AI policy and corrections policy.
About the author
Editor, Lazyfounder
Tarun Mottlia edits LazyFounders, covering Indian startups, funding rounds, AI and product launches. Every story on the site is AI-assisted and checked against its cited sources before publication.
More stories by Tarun MottliaGet the LazyFounder Brief
Startup, funding and AI news in a five-minute read. Join the early-access list.


