By Rescana
Publication Date: 2026-09-28 00:00:00
Executive Summary
Multiple critical vulnerabilities have been disclosed in Citrix NetScaler ADC and NetScaler Gateway, most notably CVE-2026-88771 and CVE-2026-88772, which are confirmed to be exploited in the wild. These vulnerabilities enable unauthenticated remote code execution (RCE), denial of service (DoS), and other high-impact attacks on affected appliances. The vulnerabilities are trivial to exploit in default configurations, and immediate action is required for all organizations running impacted versions. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-88771 to its Known Exploited Vulnerabilities (KEV) catalog as of 2026-09-27, mandating urgent remediation.
Technical Information
The vulnerabilities span a range of critical and high-severity issues in NetScaler ADC and NetScaler Gateway. The most severe, CVE-2026-88771, is a remote code execution flaw caused by improper input validation (CWE-20). This allows an unauthenticated attacker…


