Organizations using Citrix NetScaler ADC or Gateway should review Citrix security bulletins for CVE-2026-88771 through CVE-2026-88778. Check for indicators of compromise via NetScaler Console prior to patching. Preserve forensic evidence before applying updates. Apply available patches or mitigations as released by Citrix. Monitor CISA and Citrix advisories for updates on the remaining six vulnerabilities.
Quick answers
What is CVE-2026-88774?
Organizations using Citrix NetScaler ADC or Gateway should review Citrix security bulletins for CVE-2026-88771 through CVE-2026-88778. Check for indicators of compromise via NetScaler Console prior to patching. Preserve forensic evidence before applying updates. Apply available patches or mitigations as released by Citrix. Monitor CISA and Citrix advisories for updates on the remaining six vulnerabilities.
How severe is CVE-2026-88774?
critical
Is CVE-2026-88774 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-88774 be mitigated?
Organizations using Citrix NetScaler ADC or Gateway should review Citrix security bulletins for CVE-2026-88771 through CVE-2026-88778. Check for indicators of compromise via NetScaler Console prior to patching. Preserve forensic evidence before applying updates. Apply available patches or mitigations as released by Citrix. Monitor CISA and Citrix advisories for updates on the remaining six vulnerabilities.
CVSS
—
Vendor
Citrix
Published
Sep 30, 2026 · 08:42
Patch
Unknown / not confirmed
Affected products
Citrix NetScaler ADC, Citrix NetScaler Gateway
Mitigation
Organizations using Citrix NetScaler ADC or Gateway should review Citrix security bulletins for CVE-2026-88771 through CVE-2026-88778. Check for indicators of compromise via NetScaler Console prior to patching. Preserve forensic evidence before applying updates. Apply available patches or mitigations as released by Citrix. Monitor CISA and Citrix advisories for updates on the remaining six vulnerabilities.
CISA has added CVE-2026-88771 and CVE-2026-88772 to the Known Exploited Vulnerabilities catalog, citing confirmed active exploitation. Both are critical, zero-day vulnerabilities enabling remote code execution. Citrix disclosed eight total vulnerabilities (CVE-2026-88771 through CVE-2026-88778) affecting NetScaler ADC and NetScaler Gateway. Organizations are advised to check for indicators of compromise before patching and to preserve forensic evidence, as updates may reduce visibility.