Critical NetScaler RCE Zero‑Days (CVE‑2026‑88771 & CVE‑2026‑88772) Actively Exploited – Immediate Patch Required
What It Is — Citrix has confirmed two critical remote‑code‑execution vulnerabilities in its NetScaler ADC and NetScaler Gateway appliances (CVE‑2026‑88771, CVE‑2026‑88772). Both receive a CVSS 9.5 rating and can be triggered without any authentication.
Exploitability — Active exploitation is verified by Citrix and multiple threat‑intel sources; proof‑of‑concept code is already circulating. No fix existed until Citrix issued bulletin CTX697096.
Affected Products — All NetScaler ADC and NetScaler Gateway deployments, including those running with default configurations. The DTLS‑enabled variant is also vulnerable.
Why It Matters for Trust & Control Assurance
- Highlights the need for continuous vulnerability management and rapid patch deployment as a core control objective.
- Demonstrates that perimeter‑facing devices must be part of an auditable asset inventory and evidence‑rich remediation process.
- Reinforces the importance of maintaining defensible logs that prove remediation timelines to regulators, partners, and auditors.
Recommended Actions
- Deploy the CTX697096 security updates to every NetScaler appliance without delay.
- Verify patch status through automated inventory tools and retain installation logs for audit trails.
- Integrate NetScaler scanning into your continuous control‑mapping program to ensure future gaps are detected early.
Source: BleepingComputer