Citrix NetScaler vulnerabilities (CVE-2026-88771, CVE-2026-88772) in active exploitation
On September 27, 2026, Citrix disclosed eight vulnerabilities affecting NetScaler Application Delivery Controller (ADC) and NetScaler Gateway. Two of these vulnerabilities are critical (CVSS score of 9.5) and can allow an unauthenticated remote attacker to execute code:
- CVE-2026-88771 results from improper input validation and can allow an unauthenticated attacker to execute arbitrary commands.
- CVE-2026-88772 involves a memory overflow that can lead to remote code execution or denial of service.
Citrix has observed exploitation against unmitigated NetScaler deployments, and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added both vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog on September 27.
The remaining six vulnerabilities (CVE-2026-88773 through CVE-2026-88778) have been assigned CVSS scores ranging from 7.0 to 9.3. Exploitation of these issues can result in HTTP request smuggling, policy bypass, denial of service, and TCP sequence number prediction.
Recommended actions
Counter Threat Unit™ (CTU) researchers recommend that organizations identify affected NetScaler ADC and NetScaler Gateway instances in their environments, prioritize internet-facing systems, and apply Citrix security updates or mitigations as appropriate. Organizations that suspect a compromise should review Citrix’s guidance describing assessment, recovery, and validation steps. Simply applying the security updates may not remove attacker access from an appliance that was compromised prior to remediation.
Sophos countermeasures
SophosLabs continues to monitor the threat landscape for activity related to these vulnerabilities and will deliver detections and protections as available.
