Home › Intelligence › Brief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Active Exploitation of Critical RCE Vulnerabilities (CVE‑2026‑88771 & CVE‑2026‑88772) in Citrix NetScaler ADC and Gateway

Citrix disclosed eight flaws in NetScaler ADC/Gateway; two (CVE‑2026‑88771, CVE‑2026‑88772) are being actively exploited to achieve unauthenticated remote code execution. Organizations must patch and evidence remediation to maintain control‑assurance posture.

LiveThreat™ Intelligence · 📅 September 29, 2026· 📰 ncsc.gov.uk
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
4 recommended
📰
Source
ncsc.gov.uk

Active Exploitation of Critical RCE Vulnerabilities (CVE‑2026‑88771 & CVE‑2026‑88772) in Citrix NetScaler ADC and Gateway

What Happened — Citrix disclosed eight security flaws in its NetScaler ADC and NetScaler Gateway products. Two of them—CVE‑2026‑88771 (unauthenticated remote command execution) and CVE‑2026‑88772 (remote code execution/denial‑of‑service via out‑of‑bounds memory access)—are confirmed to be actively exploited in the wild.

Why It Matters for Trust & Control Assurance

  • The scenario tests an organization’s ability to detect, prioritize, and remediate critical vulnerabilities on time—a core control‑assurance activity.
  • Continuous evidence of patch status and remediation actions feeds a defensible audit trail and satisfies the “vulnerability management” control objective across multiple frameworks.
  • Leveraging automated control‑mapping lets you demonstrate that remediation steps are not ad‑hoc but part of a repeatable, monitored process.

Who Is Affected — Any enterprise that runs Citrix NetScaler ADC or Gateway on‑premises, spanning finance, healthcare, government, SaaS providers, and other sectors that rely on application delivery controllers.

Recommended Actions

  • Review the Citrix security bulletin and associated IoCs immediately.
  • Apply the vendor‑supplied patches for all affected versions (14.1‑< 73.37, 13.1‑< 64.23, etc.).
  • If patching cannot be done instantly, isolate the vulnerable instances (firewall block, IP‑range restriction, or component disablement).
  • Conduct forensic scans using the published IoCs to detect any compromise.
  • Record remediation steps in a centralized control‑mapping repository to provide continuous audit evidence.

Source: NCSC advisory

Technical Notes

  • CVE‑2026‑88771 – Improper input validation → unauthenticated remote command execution.
  • CVE‑2026‑88772 – Out‑of‑bounds memory write → remote code execution or DoS.
  • Additional findings include HTTP request smuggling (CVE‑2026‑88773) and several memory‑overflow issues (CVE‑2026‑88775‑88778).
  • Exploits are network‑visible; no authentication is required.

Source: Citrix Security Bulletin (linked above)

📰 Original Source
https://www.ncsc.gov.uk/news/exploitation-of-vulnerabilities-affecting-citrix-netscaler-adc-and-citrix-netscaler-gateway ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →