Citrix published a security bulletin on Sunday covering eight CVEs affecting NetScaler. CVE-2026-88771 is a remote code execution vulnerability that allows an unauthenticated attacker to execute arbitrary commands. CVE-2026-88772 is a memory overflow vulnerability that can lead to remote code execution or denial of service. Both are rated critical with a CVSS score of 9.5.
A third critical issue, CVE-2026-88773, is rated 9.3 and allows HTTP request smuggling, an attack technique that can bypass security controls on front-end servers. The bulletin also describes three 8.8-rated memory overflow bugs that can make NetScaler appliances unstable, an 8.8-rated bug related to TCP Initial Sequence Number prediction, and a 7.0-rated feature policy bypass caused by improper HTTP URL-based expression usage.
CISA issued an alert on Sunday, stating that it "has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally." The alert notes that updating Citrix NetScaler appliances can be complex and may require downtime, and is intended to help organizations assess exposure, prioritize mitigation, and account for the vulnerabilities in risk-management activities.
Citrix said it has observed both critical vulnerabilities under attack and has published guidance on detecting whether a NetScaler appliance needs a fix, along with OS refreshes that contain the patches.
A Reddit thread alleges that at least one Citrix channel partner knew of the flaws on Saturday and urged users to take their NetScalers offline a day before Citrix's disclosure. That claim has not been independently confirmed.
NetScaler has a long history of security problems. Critical vulnerabilities disclosed in March 2026 were quickly attacked, the same occurred twice in 2025 and once in 2023, and NetScaler flaws appeared on the Five Eyes alliance's annual list of most-exploited bugs from 2020 to 2023. Despite this, some users choose not to patch the product, often because finding a maintenance window is difficult. Security vendors have been building compensating controls to make flawed devices safer to operate without patches.