{
  "id": 10428147,
  "title": "Citrix NetScaler CVE-2026-88771 and CVE-2026-88772: Two Pre-Authentication RCE Zero-Days Under Active Exploitation",
  "url": "https://urgent.news/2026/09/28/citrix-netscaler-cve-2026-88771-and-cve-2026-88772-two-pre",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-28T11:14:18.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/anoymask/citrix-netscaler-cve-2026-88771-and-cve-2026-88772-two-pre-authentication-rce-zero-days-under-21ob"
  },
  "original_language": "en",
  "account": "Citrix has released a security bulletin addressing four critical vulnerabilities (CVE-2026-88771 through CVE-2026-88778) affecting its NetScaler ADC and Gateway products. These vulnerabilities, identified as pre-authentication remote code execution (RCE) flaws, are actively being exploited in unpatched environments.\n\nThe first vulnerability, CVE-2026-88771, impacts all NetScaler ADC and Gateway deployments, including those with default configurations. It allows an attacker to execute arbitrary code with elevated privileges on the device prior to authentication. This is achieved through crafting improperly validated input, bypassing the authentication process. The vulnerability does not require any additional features to be enabled and remains unmitigated even when certain mitigations are applied.\n\nCVE-2026-88772 is specific to VPN or DTLS virtual servers that have DTLS enabled. This vulnerability can either result in arbitrary code execution or cause a denial-of-service (DoS) condition. The attack involves sending crafted network traffic to the affected virtual server, triggering a memory overflow that leads to the RCE or DoS. Disabling DTLS removes this vulnerability, but it does not provide protection against CVE-2026-88771.\n\nMitigation strategies for both vulnerabilities include updating to the latest patched versions of NetScaler software. For CVE-2026-88772, turning off DTLS in VPN virtual servers can serve as a temporary mitigation, but it does not address CVE-2026-88771. Administrators are advised to monitor for abnormal network activity, unexpected changes to device configurations, and suspicious authentication events. Additionally, enabling NetScaler Console Security Advisory scans and integrating with a Security Information and Event Management (SIEM) system can aid in detecting and investigating the impact of these vulnerabilities.",
  "summary": "1. Basic Information Article Name : Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778 Publisher : Citrix Publication Date : 2026-09-27 Original Source : Citrix Related Information Sources : Citrix Tech Zone: NetScaler security bulletin guidance ,…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}