Back to Blog
Vulnerabilities & Exploitation

Citrix NetScaler zero-days CVE-2026-88771 and -88772 are under active attack

CISA has added two critical NetScaler ADC and Gateway flaws to its KEV catalog, and each can independently give an attacker remote code execution. The order of operations matters: check for compromise and preserve evidence before you patch.

PyramidLedger Research3 min read
Share

Key Takeaways

  • CVE-2026-88771 and CVE-2026-88772 affect Citrix NetScaler ADC and NetScaler Gateway. CISA says each can independently enable remote code execution.
  • CISA reports threat actors are exploiting these flaws globally, and it has added both to the Known Exploited Vulnerabilities (KEV) catalog.
  • CISA advises checking for indicators of compromise and preserving forensic evidence before applying updates.
  • Patching alone does not answer the question of whether an appliance was already compromised.

What CISA has confirmed

CISA's alert describes critical zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway. It says threat actors are actively exploiting them globally. Two of the CVEs, CVE-2026-88771 and CVE-2026-88772, "can independently enable remote code execution", and both are now in the KEV catalog.

The alert refers to a wider Citrix security bulletin covering eight CVEs, CVE-2026-88771 through CVE-2026-88778. CISA says reports and partner threat intelligence confirm exploitation of at least some of them. Only the first two are listed in KEV so far. We are not making claims about the other six beyond what the alert states.

Why this matters

NetScaler ADC and Gateway typically sit at the network edge. They terminate remote access and front applications, so they are exposed to the internet by design. Remote code execution on such a device gives an attacker a foothold on infrastructure that is trusted by the internal network and is often poorly instrumented. Edge appliances usually cannot run standard EDR agents, so compromise can go unseen unless you look for it deliberately.

There are two independent code-execution paths. Closing one does not remove the exposure from the other, so defenders should not treat a partial mitigation as sufficient.

Investigate first, then patch

CISA's guidance reverses the usual reflex. Its alert tells organisations to check for indicators of compromise before patching and to preserve forensic evidence prior to applying updates. Applying a fix, or rebooting, can destroy volatile state that would show whether an attacker was already on the box.

  1. 1Identify every NetScaler ADC and Gateway instance you run, including ones managed by other teams or suppliers.
  2. 2Review the Citrix security bulletin and support article CTX697096 for affected versions and the fixed builds relevant to your deployment.
  3. 3Check for indicators of compromise, using those available through NetScaler Console. Citrix article CTX694799 covers the steps to take if an appliance is suspected to be compromised.
  4. 4Preserve forensic evidence, such as memory, logs and configuration, before you apply updates.
  5. 5Patch, then assume credentials and session material handled by the appliance may be exposed if you find evidence of compromise, and rotate accordingly.

Treat KEV listing as a deadline signal

A KEV entry means exploitation is confirmed, not theoretical. For teams that use KEV to prioritise, these two CVEs should jump the normal patch queue. For those outside US federal scope, the practical reading is the same: exploitation is under way, and the exposure window is measured in hours rather than weeks.

What we would do this week

Inventory first, because unmanaged or forgotten gateways are where these incidents tend to hide. Then run the compromise check, preserve evidence, and patch. If the check finds anything, move to incident response rather than continuing with routine patching, and scope for lateral movement from the appliance.

Frequently Asked Questions

Which Citrix products are affected by CVE-2026-88771 and CVE-2026-88772?

According to CISA, both vulnerabilities affect Citrix NetScaler ADC and Citrix NetScaler Gateway. Check the Citrix bulletin (CTX697096) for the specific affected versions and fixed builds.

Should I patch immediately or check for compromise first?

CISA advises checking for indicators of compromise and preserving forensic evidence before applying updates. Do this quickly, since exploitation is active, but avoid patching or rebooting in a way that destroys evidence.

Are these vulnerabilities being exploited in the wild?

Yes. CISA states that threat actors are actively exploiting them globally, and has added both CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities catalog.

Sources

  1. 1Critical zero-day vulnerabilities exploited in Citrix NetScaler ADC and Gateway — CISA
  2. 2Known Exploited Vulnerabilities Catalog — CISA
  3. 3CTX694799: Steps to take if NetScaler ADC is suspected to be compromised — Citrix
Share

Read next