StratosAlly – Cybersecurity for digital safety

Critical NetScaler RCE Flaws Put Internet-Facing Gateways at Risk

Picture of StratosAlly

StratosAlly

Critical NetScaler RCE Flaws Put Internet-Facing Gateways at Risk

Citrix has pushed out security updates for NetScaler ADC and NetScaler Gateway after confirming that attackers are already exploiting two critical vulnerabilities.

The flaws are tracked as CVE-2026-88771 and CVE-2026-88772, and both have a CVSS v4.0 score of 9.5. Attacks against unpatched NetScaler systems have already been seen in the wild.

CVE-2026-88771 is an input validation flaw that can allow an unauthenticated attacker to execute arbitrary commands. It does not depend on an optional feature being enabled, so affected NetScaler ADC and Gateway deployments can be exposed even with their default configuration.

The second flaw, CVE-2026-88772, is a memory overflow that can lead to remote code execution or a denial of service. Exploitation requires DTLS, but that may not narrow the exposure as much as it sounds. DTLS is enabled by default on VPN virtual servers.

That makes these vulnerabilities especially important for organizations using NetScaler for remote access. These devices are often internet-facing and handle VPN sessions, authentication and traffic entering internal networks. If an attacker takes control of one, they are already in a useful position to look for credentials or other ways into the environment.

Citrix has fixed the issues in NetScaler ADC and Gateway 14.1-73.37 and later and 13.1-64.23 and later, with fixes also available for affected FIPS and NDcPP versions.

There is one important catch: updating the appliance only fixes the vulnerability. It does not tell you whether someone exploited it before you patched.

Organizations with exposed NetScaler systems should therefore check more than the firmware version. Authentication logs, unexpected files, unusual processes, configuration changes and suspicious outbound connections are all worth reviewing. If there are signs of compromise, credentials, certificates and secrets associated with the appliance may also need to be rotated.

For systems that were exposed while vulnerable, patching should be followed by a compromise assessment rather than treated as the end of the incident.

Let’s refine your stalking skills; go through our Instagram and LinkedIn. 

 
 

more Related articles