Critical Remote Code Execution in Citrix NetScaler ADC & Gateway (CVE‑2026‑88771, CVE‑2026‑88772) – Exploited Globally
What It Is – Citrix disclosed eight critical/high‑severity flaws in NetScaler ADC and NetScaler Gateway. Two of them (CVE‑2026‑88771, CVE‑2026‑88772) are being leveraged in active zero‑day attacks that drop web‑shells on vulnerable appliances.
Exploitability – Both flaws are remotely exploitable without user interaction. Public reports confirm exploitation in the wild for several weeks; a nation‑state‑aligned actor is suspected. CVSS v3.1 scores are 9.8 (critical) for CVE‑2026‑88771 and 9.3 (critical) for CVE‑2026‑88772.
Affected Products – Citrix NetScaler ADC and NetScaler Gateway v14.1 (pre‑v14.1‑73.37) and v13.1 (pre‑v13.1‑64.23), including FIPS‑mode releases.
Why It Matters for Trust & Control Assurance
- Vulnerability Management – The incident underscores the need for continuous, evidence‑based vulnerability scanning and rapid patch deployment to satisfy the “Vulnerability Management” control objective across frameworks.
- Access Control Assurance – Unauthenticated RCE bypasses traditional access controls; proving that controls are enforced requires auditable configuration baselines and real‑time monitoring.
- Defensible Audit Trail – Enterprises must retain immutable logs of patch status and remediation actions to demonstrate due diligence during security reviews or regulator inquiries.
Recommended Actions
- Apply the Citrix patches (v14.1‑73.37 or later, v13.1‑64.23 or later) immediately.
- Verify that DTLS is disabled if not required, or that it is hardened per vendor guidance.
- Run an authenticated scan of all NetScaler instances to confirm remediation.
- Enable comprehensive logging of admin actions and network traffic on the appliance; forward logs to a SIEM for continuous monitoring.
- Conduct a post‑remediation audit and capture evidence of patch status for your Trust Center.
Source: Help Net Security – Citrix NetScaler RCE zero‑days exploited globally for weeks