By Emma Woollacott
Publication Date: 2026-09-29 12:46:00
Citrix has patched eight vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway, two of which have been confirmed as being actively exploited.
The first of the two, CVE-2026-88771 is a remote code execution (RCE) flaw, in which improper input validation enables an unauthenticated attacker to execute arbitrary commands. It affects all NetScaler ADC and NetScaler Gateway deployments and has a severity score of 9.5.
Meanwhile, CVE-2026-88772 is a memory overflow vulnerability that can lead to RCE or denial of service. It affects any deployment with DTLS configuration enabled – which it is, by default, on VPN virtual servers. This, too, has a severity score of 9.5.
“Both are critical, zero-day vulnerabilities that can independently enable remote code execution,” said the US Cybersecurity and Infrastructure Security Agency (CISA). “CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities…



