Organizations using Citrix NetScaler ADC or Gateway should review Citrix security bulletins for CVE-2026-88771 through CVE-2026-88778. Check for indicators of compromise via NetScaler Console prior to patching. Preserve forensic evidence before applying updates. Apply available patches or mitigations as released by Citrix. Monitor CISA and Citrix advisories for updates on the remaining six vulnerabilities.
Quick answers
What is CVE-2026-88771?
Organizations using Citrix NetScaler ADC or Gateway should review Citrix security bulletins for CVE-2026-88771 through CVE-2026-88778. Check for indicators of compromise via NetScaler Console prior to patching. Preserve forensic evidence before applying updates. Apply available patches or mitigations as released by Citrix. Monitor CISA and Citrix advisories for updates on the remaining six vulnerabilities.
How severe is CVE-2026-88771?
critical
Is CVE-2026-88771 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-88771 be mitigated?
Organizations using Citrix NetScaler ADC or Gateway should review Citrix security bulletins for CVE-2026-88771 through CVE-2026-88778. Check for indicators of compromise via NetScaler Console prior to patching. Preserve forensic evidence before applying updates. Apply available patches or mitigations as released by Citrix. Monitor CISA and Citrix advisories for updates on the remaining six vulnerabilities.
CVSS
—
Vendor
Citrix
Published
Sep 30, 2026 · 08:05
Patch
Unknown / not confirmed
Affected products
Citrix NetScaler ADC, Citrix NetScaler Gateway
Mitigation
Organizations using Citrix NetScaler ADC or Gateway should review Citrix security bulletins for CVE-2026-88771 through CVE-2026-88778. Check for indicators of compromise via NetScaler Console prior to patching. Preserve forensic evidence before applying updates. Apply available patches or mitigations as released by Citrix. Monitor CISA and Citrix advisories for updates on the remaining six vulnerabilities.
The Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. CVE-2026-88771 involves improper input validation and CVE-2026-88772 involves improper restriction of operations within the bounds of a memory buffer, both affecting Citrix NetScaler products. The additions trigger remediation requirements under Binding Operational Directive 26-04 for Federal Civilian Executive Branch agencies.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities in Citrix NetScaler ADC and Gateway to its Known Exploited Vulnerabilities (KEV) catalog. The move follows reports of active exploitation in the wild and applies mandatory remediation requirements for U.S. federal agencies. Organizations using unpatched appliances are advised to apply security updates immediately.
CISA has added CVE-2026-88771 and CVE-2026-88772 to the Known Exploited Vulnerabilities catalog, citing confirmed active exploitation. Both are critical, zero-day vulnerabilities enabling remote code execution. Citrix disclosed eight total vulnerabilities (CVE-2026-88771 through CVE-2026-88778) affecting NetScaler ADC and NetScaler Gateway. Organizations are advised to check for indicators of compromise before patching and to preserve forensic evidence, as updates may reduce visibility.