Citrix NetScaler vulnerabilities being actively exploited

Citrix NetScaler vulnerabilities being actively exploited

By Emma Woollacott
Publication Date: 2026-09-29 12:46:00

Citrix has patched eight vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway, two of which have been confirmed as being actively exploited.

The first of the two, CVE-2026-88771 is a remote code execution (RCE) flaw, in which improper input validation enables an unauthenticated attacker to execute arbitrary commands. It affects all NetScaler ADC and NetScaler Gateway deployments and has a severity score of 9.5.