CRITICAL 1 min read 28 Sep 2026

Multiple vulnerabilities in Citrix NetScaler Leads Today's Security Review

Threat Level: Critical Tags: cve-2026-88771, cve-2026-88772, cve-2026-88773, cve-2026-88774, cve-2026-88778, cve-2026-88775, cve-2026-88776, cve-2026-88777, cwe-20, security-brief

Key findings
01
Multiple vulnerabilities in Citrix NetScaler
CRITICAL
CVE coverage: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88778, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777. CVE-2026-88771 and CVE-2026-88772 are critical RCE flaws; CVE-2026-88773 is also critical, while CVE-2026-88774 through CVE-2026-88778 are high severity.

Executive assessment

Today's brief leads with Multiple vulnerabilities in Citrix NetScaler. The single selected finding retains its own technical scope, action, observed status, and evidence limits.

Finding 01 — Multiple vulnerabilities in Citrix NetScaler

What changed: CVE coverage: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88778, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777. CVE-2026-88771 and CVE-2026-88772 are critical RCE flaws; CVE-2026-88773 is also critical, while CVE-2026-88774 through CVE-2026-88778 are high severity.

Technical evidence: CVE-2026-88771; CVSS v4.0 9.5; weakness CWE-20; technical confidence High.

Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.

Observed status: Observed in-the-wild exploitation is confirmed.

Analyst note: For CVE-2026-88772 only, explicitly disable DTLS on VPN virtual servers; Citrix says this makes its precondition unmet. If compromise is suspected, remove the appliance from the network and keep NetScaler Management Services off the public internet. Cloud Software Group reports that exploits of CVE-2026-88771 and CVE-2026-88772 have been observed on unmitigated NetScaler deployments. ([support.citrix.com](https://support.citrix.com/external/article/CTX697096), [support.citrix.com](https://support.citrix.com/external/article/CTX694799/steps-to-take-if-netscaler-adc-is-suspected-to-be-compromised.html))

Affected: Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 BEFORE 14.1-73.37; Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 BEFORE 13.1-64.23; Citrix NetScaler ADC FIPS BEFORE 14.1-73.37 FIPS ([support.citrix.com](https://support.citrix.com/external/article/CTX697096))

Fix: Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later releases; Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1. ([support.citrix.com](https://support.citrix.com/external/article/CTX697096))

Action: Map CVE-2026-88771 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: thehackernews.com](https://thehackernews.com/2026/09/warning-two-unpatched-citrix-netscaler.html)

cve-2026-88771cve-2026-88772cve-2026-88773cve-2026-88774cve-2026-88775cve-2026-88776cve-2026-88777cve-2026-88778cwe-20security-brief

Act on this brief

Map detection coverage gaps for the techniques above, or generate Sigma rules from the named CVEs.