Citrix has confirmed two critical remote code execution vulnerabilities in its NetScaler appliances are being actively exploited in the wild. Tracked as CVE-2026-88771 and CVE-2026-88772, both carry a 9.5 severity rating and require immediate patching.

NetScaler appliances sit at the network perimeter, handling remote access and application delivery for corporate networks. A successful compromise grants attackers direct access to internal systems without first breaching an endpoint.

CVE-2026-88771 stems from improper input validation and allows unauthenticated attackers to execute arbitrary commands. It affects all NetScaler ADC and Gateway deployments regardless of configuration or enabled features.

CVE-2026-88772 is a memory overflow vulnerability exploitable when Datagram Transport Layer Security (DTLS) is enabled. Citrix specified that DTLS is enabled by default on VPN virtual servers, making this flaw broadly accessible.

Citrix released patches through security bulletin CTX697096 covering both affected product lines. Cybersecurity firm watchTowr publicly warned about the vulnerabilities before Citrix's formal confirmation, noting it had verified exploitation with authoritative sources.