If you depend on Citrix NetScaler ADCs to keep apps online, a recent security wave deserves your attention. In the last 24 hours, security researchers and government advisories flagged two critical remote code execution flaws being actively exploited on exposed NetScaler appliances.
What happened
Citrix confirmed two high-severity remote code execution vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are being exploited in active campaigns. Security advisories note that these flaws allow attackers to execute code remotely, potentially taking control of the affected appliance. Citrix has released security updates and recommended applying them as soon as possible. For authoritative details, visit the official advisories from Citrix and government bodies like CISA and Citrix.
Why it matters
NetScaler ADCs are a common entry point for apps and identities in many small businesses and managed service providers. If an attacker gains control, they can access sensitive data, pivot to other systems, or deploy malware. The risk is higher for internet-facing appliances with weak credentials or outdated firmware. For creators and IT teams, it’s a reminder to inventory exposed devices, apply patches, and test changes in a safe environment before rolling out to production.
Practical steps you can take now
- Identify affected devices: List all Citrix NetScaler ADC/SDX appliances and check firmware versions against the latest advisories.
- Patch or mitigate: Update to the latest firmware that includes fixes for CVE-2026-88771/88772. If patching isn’t immediately possible, apply recommended mitigations from Citrix guidance (restrict exposed management interfaces, tighten access controls, and monitor traffic).
- Limit exposure: Place affected devices behind a firewall or VPN, restrict admin access to trusted networks, and enable MFA on admin accounts where available.
- Monitor and detect: Enable enhanced logging and monitor for unusual HTTP requests, new web shells, or unusual outbound connections from the appliance.
- Credential hygiene: Rotate admin credentials and review access controls for all NetScaler admins.
- Incident readiness: Have a plan to isolate or quarantine appliances if compromise is suspected, and review recovery backups.
- Stay informed: Follow official advisories and vendor updates, and consider subscribing to CISA alerts and related feeds.
Final thoughts
Active exploitation of these NetScaler flaws underscores the importance of keeping internet-facing network gear up to date. The steps above are part of ongoing cyber hygiene, not a one-off patch. If you’re unsure how to proceed, reach out to vendor support or a trusted security partner to help validate your environment.