NetScaler RCE exploited in the wild (CVE-2026-88772)
CVE-2026-88772
Actively exploited: CVE-2026-88772 lets unauthenticated attackers run code on NetScaler ADC and Gateway (CVSS 9.5). Update to 14.1-73.37 or 13.1-64.23 now.
Actively exploited in the wild - CVE-2026-88772 is a critical remote code execution and denial of service flaw in Citrix NetScaler ADC (before 14.1-73.37, before 13.1-64.23, and the FIPS/NDcPP builds) and NetScaler Gateway (before 14.1-73.37, before 13.1-64.23) that grants unauthenticated attackers code execution on the appliance. Patched builds are available; update immediately.
Overview
CVE-2026-88772 is a memory-safety class vulnerability in Citrix NetScaler ADC and NetScaler Gateway. An attacker who can reach the appliance over the network can trigger memory corruption that leads to arbitrary code execution or a crash that takes the device offline. No credentials are required, and no victim interaction is needed. The only friction is attack complexity, which Citrix and the CVSS vector rate as High - meaning exploitation requires some timing or environment-specific conditions, not that it is hard to attempt.
NetScaler ADC and Gateway are the remote access and load-balancing tier that sits directly between the internet and internal applications. That position makes them a high-value target: compromise the appliance and you inherit its position inside the network.
Impact
Successful exploitation gives an attacker the ability to run code on the appliance itself. From there, the usual post-exploitation path applies - reading configuration and session data, harvesting credentials, and pivoting to internal systems the appliance can reach. The denial of service outcome is a secondary effect: a failed exploit attempt can still reboot or crash the device, dropping remote access for every user behind it.
Because CISA has added this to the Known Exploited Vulnerabilities catalog, treat internet-facing NetScaler instances as likely targets right now.
Remediation
- Update ADC to 14.1-73.37 or 13.1-64.23 or later. FIPS and NDcPP deployments need 14.1-73.37 or 13.1.37.279.
- Update Gateway to 14.1-73.37 or 13.1-64.23 or later.
- Where patching is not immediately possible, restrict management and VPN interfaces to trusted networks and disable any unused virtual servers.
- After patching, review logs for unexpected process crashes, reboots, or outbound connections from the appliance, and rotate credentials that the device handled.
Security Insight
This is the third NetScaler memory-safety issue to reach active exploitation in recent years, following the Bleed lineage that ransomware crews adopted as a standard entry point. The pattern is consistent: perimeters move fast on detection but slow on the maintenance windows these appliances require, so a fix that ships on day one is still unapplied months later. Attackers have learned to keep cataloging the same target class rather than hunting for something novel. Related reading: Critical Citrix NetScaler memory actively exploited, Anubis Ransomware exploits Citrix Bleed 2 for access, and the Weekly Threat Roundup.
Further Reading
Never miss a critical vulnerability
Get real-time security alerts delivered to your preferred platform.
Related Advisories
Sonos Era 300 SMB Response Out-Of-Bounds Access Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sonos Era 300. Au...
Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, ...
Memory safety bugs present in Firefox ESR 115.34.0, Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and w...
A vulnerability has been found in Tenda A15 15.13.07.13. The impacted element is the function UploadCfg of the file /cgi-bin/UploadCfg. The manipulation of the argument File leads to stack-based buffe...