Citrix has patched two NetScaler zero-days that attackers exploited before any fix existed. The flaws, CVE-2026-88771 and CVE-2026-88772, both score 9.5 out of 10 and allow remote code execution. Citrix published the fixes on 27 September 2026; CISA added both to its exploited-vulnerability catalogue the same day.
Which Two Flaws Attackers Used
Both flaws let an attacker who has never logged in run their own code on the appliance. NetScaler ADC and NetScaler Gateway, made by Cloud Software Group under the Citrix brand, are the boxes that sit at the edge of a corporate network to balance traffic and hand out remote-access VPN sessions, so code running on one sits in front of everything behind it.
- CVE-2026-88771: an improper input validation flaw, rated 9.5 on the CVSS version 4 scale, that lets an unauthenticated attacker run arbitrary commands. Citrix lists its precondition as all deployments, including appliances left in the default configuration.
- CVE-2026-88772: a memory overflow, also rated 9.5, leading to remote code execution or a crash. It requires DTLS to be enabled, which Citrix notes is the default on a VPN virtual server.
Citrix stated in security bulletin CTX697096 that “exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed”. A zero-day is a flaw used in attacks before the vendor has a patch out, which is what happened here: the attacks came first and the fix followed on 27 September.
Which NetScaler Versions Are Affected
Anything below the builds in the right-hand column is affected. The version numbers matter more than the branch name, because two of the fixed builds carry lower-looking numbers than releases that came out earlier this month.
| Product and branch | Affected versions | Install this build or later |
|---|---|---|
| NetScaler ADC and NetScaler Gateway 14.1 | Before 14.1-73.37 | 14.1-73.37 |
| NetScaler ADC and NetScaler Gateway 13.1 | Before 13.1-64.23 | 13.1-64.23 |
| NetScaler ADC 14.1-FIPS | Before 14.1-73.37 FIPS | 14.1-73.37 FIPS |
| NetScaler ADC 13.1-FIPS and 13.1-NDcPP | Before 13.1-37.279 | 13.1-37.279 |
Citrix adds that Secure Private Access Hybrid deployments that use NetScaler instances are affected as well. One consequence of those version ranges is easy to miss: the builds Citrix shipped in August for the separate authentication-bypass flaw CVE-2026-19490, 14.1-73.32 and 13.1-63.21, both sit below the new fixed builds and are therefore still in the affected range. Installing August’s update does not cover these two zero-days.
Check for Compromise Before You Install the Update
CISA’s advice is to look for evidence of intrusion first, because the upgrade itself can destroy it. The agency’s 27 September alert warns that “updates may result in loss of forensic visibility” and tells organisations to preserve forensic evidence before applying the update. That ordering is the opposite of the usual patch-first reflex, and it is the step most coverage of this bulletin leaves out.
- Cut the exposure first: BleepingComputer reported that administrators were advised over the weekend of 26 to 27 September to shut internet-facing appliances down, or reduce their internet exposure, until they could be upgraded.
- Capture evidence before you touch the build: take and keep a copy of logs, configuration and any crash or core dumps while they still reflect the vulnerable appliance.
- Ask for indicators of compromise: Tenable’s advisory points administrators to Citrix Support for indicators, and to NetScaler Console with telemetry enabled to search for them.
- Then install the fixed build from the table above, including on appliances you updated in August.
- Escalate if anything looks wrong: CISA asks organisations that suspect a compromise to contact the appropriate authorities rather than quietly rebuilding.
This is the same sequencing problem that followed the Cisco ISE vulnerability in September, where an exploited perimeter product had to be triaged and patched at once.
What Patching Alone Does Not Fix
An upgrade closes the hole but does not evict an attacker who came through it earlier. The precedent is documented: in 2025, after a NetScaler flaw was exploited as a zero-day against Dutch organisations, the Netherlands’ National Cyber Security Centre said updating alone did not remove the risk, because an intruder could keep the access gained before the patch, and it published compromise-check scripts for administrators to run.
The Hacker News reported that administrators in this round are advised to change every service-account password and secret stored on the appliance, reset the passwords of users who signed in through it, revoke its certificates and private keys, and keep the management interface off the internet. Citrix’s own bulletin does not set out those steps; treat them as the reported remediation guidance rather than vendor instructions, and confirm the specifics with Citrix Support for your deployment.
The Six Other CVEs in the Same Bulletin
CTX697096 covers eight vulnerabilities in total, and the six that were not exploited still need the same upgrade. Citrix has not reported attacks against any of them.
- CVE-2026-88773: HTTP request smuggling, rated 9.3, on appliances with an HTTP configuration enabled.
- CVE-2026-88774: a feature policy bypass, rated 7.0, caused by improper use of HTTP URL-based policy expressions.
- CVE-2026-88775: a memory overflow leading to denial of service, rated 8.8, where a Gateway or AAA virtual server is configured.
- CVE-2026-88776: a memory overflow leading to denial of service, rated 8.8, where a load-balancing virtual server of type Oracle is configured.
- CVE-2026-88777: a memory overflow leading to denial of service, rated 8.8, on load-balancing, content-switching or CGNAT configurations using non-HTTP layer-7 features.
- CVE-2026-88778: TCP initial sequence number prediction, rated 8.8, where TCP is configured. Citrix points to its documented enhanced ISN generation setting as a configuration change for this one.
Two of those six carry scores that would headline a normal patch cycle on their own, which is worth remembering the next time a vendor bulletin gets read only for the flaw with a name. The same pattern showed up in the Zyxel GS1900 switch breaches reported earlier this month.
Status as of 28 September 2026
As of 28 September 2026, patches exist for all eight flaws and both exploited CVEs are in CISA’s Known Exploited Vulnerabilities catalogue, added on 27 September. CISA lists them as the Citrix NetScaler Improper Input Validation Vulnerability and the Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability, and says “threat actors are actively exploiting these vulnerabilities globally”, citing partner threat intelligence.
No remediation deadline was attached. CISA’s catalogue entry cites Binding Operational Directive 26-04, which applies only to Federal Civilian Executive Branch agencies, and the alert publishes no due date for these two CVEs. That is a change from the fixed dates the agency has set elsewhere, such as the 28 September deadline on a WordPress flaw. Every other organisation is simply encouraged to prioritise catalogue entries.
Several things remain unknown. Citrix has not said how many appliances were compromised, when exploitation started, or who is behind it. The security firm watchTowr said publicly on 26 September that reports of unpatched NetScaler remote code execution flaws were credible and that it had encountered them during forensic investigations, according to The Hacker News. BleepingComputer reported that the Dutch National Cyber Security Centre warned organisations in the Netherlands before public disclosure and declined to say more, telling the site: “As you’re not part of our constituency, we cannot disclose any further information at this time.”
Frequently Asked Questions
Which Builds Fix CVE-2026-88771 and CVE-2026-88772?
NetScaler ADC and Gateway 14.1-73.37 or later, and 13.1-64.23 or later. FIPS deployments need 14.1-73.37 FIPS, and 13.1-FIPS and 13.1-NDcPP need 13.1-37.279.
Is the Appliance Safe if DTLS Is Turned Off?
Turning DTLS off removes the precondition for CVE-2026-88772 only. CVE-2026-88771 applies to all deployments including the default configuration, so the upgrade is still required.
Did August’s NetScaler Patch Cover These Zero-Days?
No. The August builds issued for CVE-2026-19490, 14.1-73.32 and 13.1-63.21, fall below the new fixed builds and remain inside the affected range.
Does Installing the Update Remove an Attacker Who Is Already In?
Not on its own. NCSC-NL made that point after the 2025 NetScaler zero-day, and reported guidance in this round is to rotate service-account passwords and secrets, reset the passwords of users who signed in through the appliance, and revoke its certificates and private keys.
Has CISA Set a Fix Deadline for These Two CVEs?
No date was published with the 27 September catalogue additions. The directive CISA cites, BOD 26-04, binds only United States federal civilian agencies; everyone else is encouraged rather than required to act.




