Home › Intelligence › Brief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical Remote Code Execution in Citrix NetScaler ADC & Gateway (CVE‑2026‑88771, CVE‑2026‑88772) – Exploited Globally

Citrix disclosed eight critical flaws; two (CVE‑2026‑88771, CVE‑2026‑88772) have been actively exploited to install web‑shells on NetScaler ADC and Gateway devices. The attacks bypass authentication, highlighting the need for continuous vulnerability management and auditable patch evidence for compliance readiness.

LiveThreat™ Intelligence · 📅 September 29, 2026· 📰 helpnetsecurity.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
5 recommended
📰
Source
helpnetsecurity.com

Critical Remote Code Execution in Citrix NetScaler ADC & Gateway (CVE‑2026‑88771, CVE‑2026‑88772) – Exploited Globally

What It Is – Citrix disclosed eight critical/high‑severity flaws in NetScaler ADC and NetScaler Gateway. Two of them (CVE‑2026‑88771, CVE‑2026‑88772) are being leveraged in active zero‑day attacks that drop web‑shells on vulnerable appliances.

Exploitability – Both flaws are remotely exploitable without user interaction. Public reports confirm exploitation in the wild for several weeks; a nation‑state‑aligned actor is suspected. CVSS v3.1 scores are 9.8 (critical) for CVE‑2026‑88771 and 9.3 (critical) for CVE‑2026‑88772.

Affected Products – Citrix NetScaler ADC and NetScaler Gateway v14.1 (pre‑v14.1‑73.37) and v13.1 (pre‑v13.1‑64.23), including FIPS‑mode releases.

Why It Matters for Trust & Control Assurance

  • Vulnerability Management – The incident underscores the need for continuous, evidence‑based vulnerability scanning and rapid patch deployment to satisfy the “Vulnerability Management” control objective across frameworks.
  • Access Control Assurance – Unauthenticated RCE bypasses traditional access controls; proving that controls are enforced requires auditable configuration baselines and real‑time monitoring.
  • Defensible Audit Trail – Enterprises must retain immutable logs of patch status and remediation actions to demonstrate due diligence during security reviews or regulator inquiries.

Recommended Actions

  • Apply the Citrix patches (v14.1‑73.37 or later, v13.1‑64.23 or later) immediately.
  • Verify that DTLS is disabled if not required, or that it is hardened per vendor guidance.
  • Run an authenticated scan of all NetScaler instances to confirm remediation.
  • Enable comprehensive logging of admin actions and network traffic on the appliance; forward logs to a SIEM for continuous monitoring.
  • Conduct a post‑remediation audit and capture evidence of patch status for your Trust Center.

Source: Help Net Security – Citrix NetScaler RCE zero‑days exploited globally for weeks

📰 Original Source
https://www.helpnetsecurity.com/2026/09/28/citrix-netscaler-rce-zero-days-exploited-for-weeks-cve-2026-88771-cve-2026-88772/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →