Citrix NetScaler Zero-Days: Two RCE Flaws Under Active Exploitation With No Authentication Required
Two critical remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being exploited right now. One of them needs no authentication at all and works on a default-configured appliance out of the box.
Citrix published an emergency security bulletin on 27 September 2026 confirming that both CVE-2026-88771 and CVE-2026-88772, each rated CVSS 9.5, are being actively weaponised. CVE-2026-88771 is the more dangerous of the pair: it exploits improper input validation and requires zero authentication, meaning an attacker anywhere on the internet can attempt to execute code on your appliance without needing a username or password. CVE-2026-88772 targets a memory overflow that kicks in when DTLS is enabled, which is the default setting on NetScaler Gateway VPN virtual servers. BleepingComputer confirmed active exploitation as of 27 September 2026.
| CVE | CVSS | Type | Auth Required? | Trigger Condition |
|---|---|---|---|---|
| CVE-2026-88771 | 9.5 Critical | Remote Code Execution | None | Default configuration |
| CVE-2026-88772 | 9.5 Critical | RCE / Denial of Service | None (DTLS path) | DTLS enabled (default on VPN servers) |
NetScaler ADC and Gateway are the remote access and application delivery backbone for a significant number of Australian businesses, including many that expanded their remote work setup quickly between 2020 and 2022. We consistently find these appliances in client environments that were configured during that rush, handed over to an internal team, and largely left untouched since. That posture is now a serious liability. A CVSS 9.5 unauthenticated RCE on an internet-facing device isn't a "monitor and patch this cycle" situation. Fixed builds are already available: NetScaler ADC and Gateway 14.1-73.37 or 13.1-64.23, and FIPS builds 14.1-73.37 FIPS or 13.1-37.279. Apply them now.
What To Do Right Now
- Patch to fixed builds immediately. NetScaler ADC/Gateway 14.1-73.37, 13.1-64.23, FIPS 14.1-73.37 FIPS, or NDcPP 13.1-37.279.
- If you can't patch immediately: Restrict internet access to the NetScaler management interface until the patch is deployed.
- Review your audit logs. Check for anomalous sessions or unusual connection patterns from the past 30 days.
- Confirm your DTLS setting. If CVE-2026-88772 applies, check whether DTLS is enabled on your VPN virtual servers and mitigate per Citrix's guidance.
Written by Dan Briggs, Senior IT Consultant, All IT Services. All IT is a Sydney-based managed IT provider supporting businesses across the Northern Beaches, Central West NSW, Melbourne, and Brisbane.
Frequently Asked Questions
Not Sure If Your Citrix Deployment Is Affected?
Our team works with Australian businesses to identify and patch critical vulnerabilities fast. Get in touch and we'll assess your NetScaler environment today.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
Read the Full Guide →
