Home › Intelligence › Brief
VULNERABILITY BRIEF🔴 Critical Vulnerability

NetScaler Zero‑Day RCE & DTLS Overflow (CVE‑2026‑88771, CVE‑2026‑88772) Exploited in the Wild

Citrix NetScaler ADC and Gateway are affected by two critical zero‑day flaws (CVE‑2026‑88771, CVE‑2026‑88772) that are actively exploited. The exposure underscores the need for continuous vulnerability management and auditable patch‑remediation processes.

LiveThreat™ Intelligence · 📅 September 29, 2026· 📰 unit42.paloaltonetworks.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
unit42.paloaltonetworks.com

NetScaler Zero‑Day RCE & DTLS Overflow (CVE‑2026‑88771, CVE‑2026‑88772) Exploited in the Wild

What It Is – Citrix disclosed two critical zero‑day flaws in NetScaler ADC and NetScaler Gateway. CVE‑2026‑88771 enables unauthenticated remote code execution via input validation failure; CVE‑2026‑88772 is a memory‑overflow that can lead to RCE or denial‑of‑service on the DTLS stack.

Exploitability – Both vulnerabilities have a CVSS v4.0 base score of 9.5 and are confirmed to be exploited in the wild. Palo Alto Networks’ Cortex Xpanse telemetry shows > 50 k exposed instances as of 27 Sept 2026.

Affected Products – Citrix NetScaler ADC (hardware and VPX) and NetScaler Gateway (any version prior to the vendor’s emergency patch).

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for a continuous vulnerability‑management control that can surface unpatched exposures before attackers exploit them.
  • Provides concrete evidence for auditors that you maintain a defensible patch‑and‑remediation workflow, a key control across NIST CSF 2.0, ISO 27001 and other frameworks.
  • Highlights the importance of real‑time asset discovery and exposure monitoring (e.g., Xpanse) as part of an auditable trust‑posture program.

Recommended Actions

  • Apply Citrix’s emergency patches for CVE‑2026‑88771 and CVE‑2026‑88772 immediately.
  • Verify exposure using Citrix’s “pre‑condition” checklist or a trusted external asset‑inventory tool.
  • Isolate any vulnerable NetScaler instances from production networks.
  • Preserve forensic evidence – snapshot VPX, collect syslog, console logs, support bundle, and core dumps.
  • Conduct targeted hunting for anomalous admin sessions, unexpected outbound traffic, and logging gaps.

Source: Unit 42 Threat Brief – NetScaler Zero Days

📰 Original Source
https://unit42.paloaltonetworks.com/netscaler-zero-days-exploited/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →