Active Exploitation of Critical Vulnerabilities Affecting Citrix NetScaler ADC and NetScaler Gateway

Published on 30-Sep-2026 11:30:00

Executive Summary

The Cyber Threat Intelligence (CTI) Unit of BGD e-GOV CIRT is warning organizations across Bangladesh of the active exploitation of multiple vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway.

Citrix has disclosed eight vulnerabilities (CVE-2026-88771 through CVE-2026-88778). Of these, CVE-2026-88771 and CVE-2026-88772 are confirmed to be actively exploited in the wild, with both rated CVSS 4.0: 9.5 (Critical). CVE-2026-88771 is particularly significant as it can allow unauthenticated remote code execution without requiring any additional feature to be enabled.

Organizations operating internet-facing NetScaler appliances, particularly those supporting VPN, remote access, authentication or application delivery, are advised to treat this as an urgent remediation priority.