Citrix NetScaler RCE zero-day Vulnerabilities
What is the Attack? Threat actors are actively exploiting two critical remote code execution vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting Citrix NetScaler ADC and NetScaler Gateway appliances. Citrix confirmed that both vulnerabilities were exploited in the wild before security updates were available. CISA has subsequently added both vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog and…
|
What is the Attack? |
Threat actors are actively exploiting two critical remote code execution vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting Citrix NetScaler ADC and NetScaler Gateway appliances. Citrix confirmed that both vulnerabilities were exploited in the wild before security updates were available. CISA has subsequently added both vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog and reported that threat intelligence confirms exploitation globally. CVE-2026-88771 is an improper input validation vulnerability that can allow an unauthenticated remote attacker to execute arbitrary commands. It affects NetScaler deployments without requiring an additional feature to be enabled. CVE-2026-88772 is a memory overflow vulnerability that can lead to remote code execution or denial-of-service conditions. It affects appliances with DTLS enabled, which is enabled by default for VPN virtual servers. Both vulnerabilities have a CVSS v4 score of 9.5. |
|
What is the recommended Mitigation? |
Organizations should immediately identify exposed NetScaler ADC and Gateway appliances and apply the security updates provided by Citrix. Fixed releases include NetScaler ADC/Gateway 14.1-73.37 and later and 13.1-64.23 and later, with corresponding updates for FIPS and NDcPP builds. Because both vulnerabilities were exploited as zero-days before patches were available, patching alone should not be treated as confirmation that an appliance was not compromised. Organizations should review NetScaler and supporting security logs for suspicious activity, preserve forensic evidence where compromise is suspected, and investigate the appliance before making changes that could destroy evidence. If compromise is suspected, organizations should isolate the affected appliance, review administrative and outbound connections, investigate for persistence, and consider resetting credentials, invalidating sessions, and replacing potentially exposed certificates or keys. |
|
What FortiGuard Coverage is available? |
• FortiGuard Labs continues to monitor this vulnerability and associated attack activity. We will provide updates as new intelligence, detections, and protections become available. |
