CVE-2026-88771, CVE-2026-88772: NetScaler Active Exploitation

CVE-2026-88771, CVE-2026-88772: NetScaler Active Exploitation

By Bitsight
Publication Date: 2026-09-28 00:00:00

CVE-2026-88771 and CVE-2026-88772 impact to organizations

Successful exploitation could give attackers control over the appliance or disrupt service. From there, attackers can use a compromised NetScaler handling remote access or core apps to pivot to connected networks, harvest credentials, or breach internal databases. While these risks are severe, the exact scope of public attacks remains unconfirmed.

Risk also extends to third-party vendors. If a key vendor runs an affected NetScaler managing your access or applications, you should confirm that they patched their systems and checked for prior signs of compromise.

Recommendations

  1. Locate and update affected appliances. Cross-reference customer-managed NetScaler ADC and Gateway instances (including hybrid deployments) against Citrix’s advisory. Since Citrix disclosed eight total vulnerabilities in this release, review the full bulletin when planning updates.

  2. Preserve forensic evidence before rebooting. Save…