External risk intelligence

Citrix NetScaler Remote Code Execution and Denial of Service Vulnerability

CVE advisoryKnown Exploit

CVE-2026-88772

Citrix NetScaler ADC and Gateway are enterprise edge appliances designed specifically to be public-facing, acting as internet gateways, load balancers, and remote access entry points in typical network deployments.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Citrix NetScaler ADC and Gateway products, which are used for application delivery and secure remote access. This flaw could potentially allow unauthorized actors to execute arbitrary code or disrupt services remotely. The primary concern is to determine if our deployed systems are affected and to what extent.

  • Flaw in Citrix NetScaler could allow remote code execution.
  • Affects critical network access and application delivery.
  • Confirm relevance and exposure to our environment.

Attack Path

How an attacker could exploit the issue

An attacker could reach this vulnerability by accessing Citrix NetScaler Application Delivery Controller or Gateway from the internet. Without any authentication or privileges, an attacker could trigger the vulnerability, potentially leading to remote code execution or denial of service.

  • Network access required.
  • Triggered without authentication.
  • Leads to code execution or DoS.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to remotely execute code or cause a denial of service on affected Citrix NetScaler ADC and Gateway devices. The risk is associated with unpatched devices that are accessible from the internet, potentially impacting the availability and integrity of services managed by these appliances.

  • Asset at risk: Network access control and services.
  • Exposure: Network access with no authentication.
  • Consequence: Service disruption or code execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

Citrix NetScaler ADC and Gateway are likely managed by infrastructure or platform teams, with security teams overseeing exposure and vendor coordination. The immediate priority is to identify all instances of the affected technology, assess their business criticality and external reachability, and assign ownership for remediation planning.

  • Determine asset ownership and exposure.
  • Verify external reachability and criticality.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Citrix NetScaler ADC and Gateway?

Citrix NetScaler ADC (Application Delivery Controller) and NetScaler Gateway are enterprise-grade network appliances. Organizations use them to optimize application traffic, provide load balancing, and serve as secure remote access entry points for users connecting to internal corporate resources.

What does CVE-2026-88772 mean in simple terms?

This vulnerability is classified as an improper restriction of operations within the bounds of a memory buffer (CWE-119). Essentially, the software fails to properly manage memory when processing data, which can be manipulated by an attacker to either crash the service, causing a Denial of Service, or run unauthorized commands on the device.

How is this vulnerability triggered?

An attacker can trigger this vulnerability by sending specially crafted network requests to the affected NetScaler device. Because the flaw exists in how the software processes these requests, no prior authentication or administrative privileges are required for the attacker to attempt exploitation.

Is my NetScaler appliance at risk?

Per Halo Surface Signal, these appliances are typically designed to be internet-facing to function as gateways and load balancers. If your device is directly reachable from the internet, it is at higher risk. You should review your network perimeter to confirm if these specific management or access interfaces are exposed publicly.

What steps should I take if I use NetScaler?

Identify all NetScaler ADC and Gateway instances in your environment and compare their versions against the affected releases listed by the vendor. Prioritize updating these systems to the patched versions provided by Citrix, as this is the standard method to address the underlying memory buffer flaw.

References

Cyber Threat Intelligence (CTI)

Sources: tool