Citrix NetScaler ADC and Gateway Hit by Eight Exploited RCE Flaws
High · CISA Advisories ·
CISA KEV · Exploited
Key points
- Eight CVEs (CVE-2026-88771 through CVE-2026-88778) affect Citrix NetScaler ADC and NetScaler Gateway.
- Exploitation allows remote code execution and is occurring on a global scale.
- The vulnerabilities were disclosed, added to the KEV catalog, and an alert was issued on September 27, 2026.
- Threat actors are actively leveraging these flaws against exposed systems.
On September 27, 2026, eight vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway were disclosed. These flaws, tracked as CVE-2026-88771 through CVE-2026-88778, permit remote code execution. Threat actors have already begun exploiting them, and the issues have been added to the Known Exploited Vulnerabilities (KEV) catalog. An alert was issued to warn organizations.
Any organization using the affected Citrix NetScaler ADC or NetScaler Gateway products, especially those with internet-facing instances, is at risk. This includes government, education, healthcare, and private sector entities worldwide, given the global scale of exploitation.
Remote code execution vulnerabilities are among the most severe because they allow attackers to run arbitrary code on targeted systems, potentially leading to full compromise, data theft, or lateral movement. The fact that exploitation is already happening globally and the flaws are in KEV underscores the urgency.
Citrix NetScaler is widely deployed for application delivery and remote access, making it a high-value target. The rapid exploitation following disclosure highlights the speed at which threat actors weaponize new flaws. The KEV addition means U.S. federal agencies must patch by a set deadline, but all organizations should treat this as critical.
Monitor vendor advisories for patches and mitigation guidance. Watch for signs of compromise such as unusual outbound traffic, unexpected processes, or new administrative accounts. Expect further exploitation attempts and possibly new attack variants. Stay informed through official channels and threat intelligence feeds.
What to do now
- Immediately inventory all Citrix NetScaler ADC and NetScaler Gateway deployments; identify internet-facing instances.
- Apply available patches for CVE-2026-88771 through CVE-2026-88778 without delay; if patches are not yet available, implement vendor-recommended mitigations.
- Isolate or disable unpatched, internet-exposed NetScaler systems until they can be secured.
- Review logs and network traffic for exploitation indicators, including anomalous process execution, outbound connections, or web shells.
- Rotate all credentials, API keys, and certificates that could have been exposed on affected appliances.
- If compromise is suspected, conduct a forensic investigation and follow incident response procedures.
- Subscribe to vendor and government alerts (e.g., KEV updates) for ongoing developments.
CVE references
- CVE-2026-88771
- CVE-2026-88772
- CVE-2026-88773
- CVE-2026-88774
- CVE-2026-88775
- CVE-2026-88776
- CVE-2026-88777
- CVE-2026-88778
Original source
Original AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.