{
  "id": 12283112,
  "title": "Citrix NetScaler CVE-2026-88771 and CVE-2026-88772: two edge RCE flaws attacked before a fix existed",
  "url": "https://urgent.news/2026/10/06/citrix-netscaler-cve-2026-88771-and-cve-2026-88772-two-edge-rce-flaws",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-06T02:40:37.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/jeffreyciend/citrix-netscaler-cve-2026-88771-and-cve-2026-88772-two-edge-rce-flaws-attacked-before-a-fix-existed-1og6"
  },
  "original_language": "en",
  "account": "Two critical vulnerabilities were discovered in Citrix NetScaler, a network security appliance. Citrix released patches on September 27, 2026, after reports of unpatched remote code execution bugs were found active. Both vulnerabilities are rated 9.5 on the CVSS v4 scale. The first flaw, CVE-2026-88771, is due to improper input validation that allows an unauthenticated attacker to execute arbitrary commands. The second vulnerability, CVE-2026-88772, is a memory overflow that can lead to remote code execution or denial of service. The latter affects appliances with DTLS enabled, which is enabled by default for VPN virtual servers. This means NetScaler Gateway appliances are affected unless DTLS is explicitly disabled. Citrix did not confirm whether the vulnerabilities match the ones reported by watchTowr, but they align with the account. Administrators on the Citrix forum were advised to shut down NetScalers immediately. Exploits of these vulnerabilities have been observed on unmitigated deployments, but the extent of the exploitation, the perpetrators, and the timeline are unknown. The affected versions include 14.1-73.32, 13.1-63.21, and subsequent builds that fixed the August authentication bypass vulnerability. The fixes are available for NetScaler ADC and NetScaler Gateway versions 14.1-73.37 and later, 13.1-64.23 and later, and 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later. Citrix recommends preserving authentication and VPN logs before applying the patches and investigating for anomalous command execution and outbound connections.",
  "summary": "Citrix NetScaler CVE-2026-88771 and CVE-2026-88772: two edge RCE flaws attacked before a fix existed Citrix published fixes for two NetScaler flaws on 2026-09-27 after watchTowr reported unpatched remote code execution bugs under active exploitation. Both flaws are rated 9.5 under CVSS v4. The two vulnerabilities CVE-2026-88771 is improper input validation that lets an unauthenticated attacker…",
  "key_points": [
    "Two critical vulnerabilities discovered in Citrix NetScaler",
    "CVE-2026-88771 allows arbitrary command execution via improper input validation",
    "CVE-2026-88772 is memory overflow leading to remote code execution or denial of service"
  ],
  "editors_take": "The emergence of exploits for Citrix NetScaler vulnerabilities forces administrators to urgently apply patches, as unpatched systems are exposed to remote code execution and potential denial of service attacks.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}