NetScaler admins told to patch critical zero-days in ADC and Gateway now
Summary
Citrix has released urgent patches for two critical unauthenticated remote code execution zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and NetScaler Gateway. The vulnerabilities are under active attack, and administrators are advised to take affected systems offline and patch them immediately.
IFF Assessment
This article details critical vulnerabilities that are actively being exploited, posing a significant risk to organizations using vulnerable Citrix NetScaler products.
Severity
CVE-2026-88771 has a CVSS score of 9.5 and is a critical RCE vulnerability due to improper input validation, allowing unauthenticated attackers to execute arbitrary commands.
CISA KEV: Listed as actively exploited. Federal patch due: September 30, 2026. Known ransomware use: Unknown.
Defender Context
This alert highlights the immediate need for defenders to patch critical vulnerabilities in widely used network appliances like Citrix NetScaler. Organizations should prioritize patching and monitor for any signs of exploitation, as these zero-days are already being actively targeted.