Skip to content

Citrix NetScaler Zero-Days CVE-2026-88771 and CVE-2026-88772 Exploited

Citrix NetScaler Zero-Days CVE-2026-88771 and CVE-2026-88772 Exploited

Two critical NetScaler ADC and Gateway flaws were used in attacks before Citrix had fixes. Here's what the vendor, CISA and researchers have actually confirmed, and what to do before you install the update.

Simple diagram showing the internet on the left, a red NetScaler ADC and Gateway box in the middle, and internal applications on the right, with arrows running left to right.
Conceptual diagram by UnpanicTech. It shows where NetScaler sits in a typical deployment. It is not a screenshot or an exploit trace.

Over the weekend of September 26 and 27, NetScaler admins started getting phone calls telling them to switch their appliances off. No CVE numbers, no advisory, no details. Just "shut it down." [3]

By Sunday the reason was public. Citrix published security bulletin CTX697096 and confirmed that two critical flaws, CVE-2026-88771 and CVE-2026-88772, have been exploited on unmitigated NetScaler ADC and Gateway deployments [1]. CISA added both to its Known Exploited Vulnerabilities (KEV) catalog the same day [2] [4].

If you only have a minute: update every customer-managed NetScaler ADC and Gateway to a fixed build (table below), but capture evidence first. CISA warns that an update can wipe out forensic visibility [2]. Federal civilian agencies have until September 30 [4]. Everyone else should treat that date as a hint.

The weekend, in order

Before Citrix said anything, administrators reported being told by suppliers and security teams to shut appliances down. Those warnings followed what was described as a private pre-notification from the Dutch national cyber security centre, NCSC-NL [5]. NCSC-NL wouldn't confirm the notice to BleepingComputer, saying the reporter wasn't part of its constituency [3]. So what's in that notice is reported, not verified.

On September 26, watchTowr publicly warned that unpatched NetScaler remote code execution flaws were being exploited. It said the information was credible and came from forensic investigations [5]. Citrix published its bulletin the next day [1].

Vertical timeline with four entries: private shutdown warnings before September 26, watchTowr warning on Saturday September 26, Citrix bulletin and CISA KEV listing on Sunday September 27, and the federal agency deadline on Wednesday September 30.
Timeline assembled from the Citrix bulletin, CISA's alerts as relayed by BleepingComputer, and watchTowr's FAQ.

One more detail circulated with the leaked notice. It reportedly said one bug let attackers place shellcode directly into memory, while the second was still being researched [3]. That's a leaked document described by a news site. Don't build detection logic on it.

Two bugs, two very different preconditions

The distinction matters because one of these hits every appliance and the other needs a feature switched on. Both are rated 9.5 under CVSS v4.0 in Citrix's bulletin [1].

CVE Flaw What must be true CVSS v4.0 (per Citrix)
CVE-2026-88771 Improper input validation (CWE-20). An unauthenticated attacker can execute arbitrary commands. Any NetScaler ADC or Gateway on an affected build. Default configuration, no extra feature needed. 9.5
AV:N/AC:L/AT:P/PR:N/UI:N
CVE-2026-88772 Memory overflow (CWE-119). Can lead to remote code execution or denial of service. DTLS enabled. That's the default on VPN virtual servers. 9.5
AV:N/AC:H/AT:N/PR:N/UI:N

Both vectors also rate all six impact metrics (VC, VI, VA, SC, SI, SA) as High.

These scores come from Citrix's bulletin. The NVD entries wouldn't load for me, so I can't say whether NVD scores them differently.

Nested boxes. The outer amber box covers every NetScaler ADC or Gateway on an affected build and is labeled CVE-2026-88771. The inner red box adds DTLS enabled and is labeled CVE-2026-88772 also applies.
Conceptual scope diagram by UnpanicTech, based on the preconditions in Citrix's bulletin.

Look at the vectors side by side and they aren't twins. CVE-2026-88771 is low complexity but marks attack requirements as "present," meaning some condition about the target has to hold. Citrix doesn't say what that condition is, and I won't guess. CVE-2026-88772 is the reverse: high attack complexity, no attack requirements. They land on the same 9.5 because neither needs credentials or user interaction and the impact ratings are maxed out.

Citrix's bulletin shows how to check the DTLS precondition. A VPN virtual server defined without -dtls OFF has DTLS on by default [1]:

# DTLS not explicitly disabled = enabled by default
add vpn vserver vpn1 SSL 10.0.0.0 443 -Listenpolicy NONE

# DTLS explicitly disabled = precondition not met
add vpn vserver vpn1 SSL 10.0.0.0 443 -dtls OFF -Listenpolicy NONE
Turning DTLS off won't save you. CVE-2026-88771 needs nothing enabled. Citrix points to updated builds as the remedy [1], and watchTowr states there is no workaround [5].

Fixed builds, and one thing to double-check

Product Affected Fixed
ADC and Gateway 14.1 Before 14.1-73.37 14.1-73.37 and later
ADC and Gateway 13.1 Before 13.1-64.23 13.1-64.23 and later 13.1 releases
ADC 14.1-FIPS Before 14.1-73.37 FIPS 14.1-73.37 FIPS and later
ADC 13.1-FIPS and 13.1-NDcPP Before 13.1-37.279 13.1.37.279 and later

Citrix writes that last build two ways, 13.1-37.279 in the affected list and 13.1.37.279 in the fix list [1]. It's probably one build with a typo, but that's my inference. Confirm with Citrix support before you plan around it.

Scope notes from the bulletin: Secure Private Access Hybrid deployments that use NetScaler instances are also affected, and the bulletin covers customer-managed appliances only. Cloud Software Group upgrades Citrix-managed cloud services itself [1].

Already patched in August? watchTowr says appliances fixed for the earlier CVE-2026-19490 are still vulnerable to these two unless they're on one of the builds above [5]. A clean patch record for the last NetScaler bug tells you nothing about this one.

Evidence first, then update

This is the part people will be tempted to skip. CISA advises checking for indicators of compromise before patching where possible, and preserving forensic evidence if you suspect a compromise, because updates can destroy it [2].

Four stacked boxes connected by downward arrows: capture logs, snapshot and core dump; check for compromise with the Citrix IOC scan; install the fixed build; rotate passwords, secrets and certificates.
Workflow by UnpanicTech, following the sequence CISA and watchTowr describe.

watchTowr's version of the sequence: capture logs, a snapshot, a support bundle and a core dump from each exposed appliance; check for compromise; install the fixed build; rotate passwords, secrets and certificates stored on or used through the appliance; forward NetScaler logs to a SIEM; and keep management interfaces off the public internet [5].

Citrix provides generic IOCs through NetScaler Console. watchTowr says the scan needs Console 14.1-73.36 or later with telemetry enabled [5]. Citrix itself cautions that these indicators may miss real compromises and suggests bringing in experienced forensic investigators [4].

My read: a clean scan is weak evidence. Nobody I read says when exploitation began, so an appliance that was internet-facing on an affected build should be treated as possibly exposed even if the scan finds nothing. Rotating credentials and certificates isn't overkill here. NetScaler terminates VPN sessions and handles authentication, so what it holds is exactly what an intruder would want.

watchTowr also flags a reboot-loop problem on 13.1. If show ns variable returns any variables, it recommends 13.1-64.24 instead [5]. That's watchTowr's guidance, not something I found in Citrix's bulletin, so check with Citrix before relying on it.

What's actually known about the attacks

Exploitation is confirmed by the vendor. Citrix says exploits of both flaws on unmitigated deployments have been observed [1]. CISA says it has reports and partner threat intelligence confirming that threat actors are actively exploiting them globally [2]. The KEV listing followed, with a September 30 deadline for federal civilian agencies under Binding Operational Directive 26-04 [4].

Nearly everything else is unknown. No attribution has been made public [5]. The leaked NCSC-NL notice reportedly said exploitation was seen at multiple customers worldwide but that the agency didn't know whether it was widespread [3]. The same notice reportedly warned that attempts could rise once patches and technical details were out. None of the pages I read mention public exploit code, but that's an absence in my reading, not proof none exists.

You'll see exposure numbers quoted. Shadowserver tracks more than 23,000 IP addresses with NetScaler fingerprints, nearly 22,000 of them ADC and just over 1,500 Gateway. BleepingComputer points out there's no breakdown of how many are honeypots, already patched, or actually vulnerable [4]. It's a rough size of the pool, not a count of vulnerable systems.

A note on watchTowr: it sells exposure-management tooling, and its FAQ includes a product pitch. The technical points I've cited match Citrix's own bulletin where they overlap, but read the marketing as marketing.

Six more bugs in the same bulletin

CTX697096 fixes eight vulnerabilities in total. CVE-2026-88773 through CVE-2026-88778 depend on specific configurations: HTTP request smuggling (9.3), a feature policy bypass (7.0), three memory overflows that can cause denial of service or erratic behavior (8.8 each), and TCP initial sequence number prediction (8.8) [1]. Citrix reports observed exploitation only for the first two CVEs.

The TCP one needs extra work. Citrix tells affected customers to apply a TCP configuration change (Enhanced ISN Generation) [1], and watchTowr says the upgrade alone doesn't fix it [5].

What I'd do first

  1. Build the list. Every customer-managed ADC and Gateway, including FIPS and NDcPP builds and any NetScaler behind a Secure Private Access hybrid setup.
  2. Preserve evidence on the exposed ones before changing anything.
  3. Patch the internet-facing Gateway, VPN and authentication servers first. watchTowr's priority list [5] makes sense, but remember CVE-2026-88771 hits every deployment, so an ADC doing plain load balancing isn't safe just because it isn't a VPN.
  4. Rotate secrets and certificates after the update, then apply the TCP setting for CVE-2026-88778.
  5. Keep watching. Citrix's bulletin showed only its initial publication when I read it, and attribution and scale are still open.

The pattern is the bigger story. Since November 2021, CISA has flagged 26 exploited Citrix vulnerabilities, six of them abused by ransomware gangs [4]. CVE-2026-19490 went into KEV on September 9 and these two followed less than three weeks later. They're separate bugs. Which one you've patched says nothing about the others.

Published September 28, 2026. This story is still moving. If Citrix updates the bulletin or new exploitation details emerge, the change will be noted here.

Sources & References

  1. Citrix, "NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778" (CTX697096), published September 27, 2026: https://support.citrix.com/external/article/CTX697096
  2. CISA, "Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway" (September 27, 2026): https://www.cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway. See also CISA's KEV addition alert: https://www.cisa.gov/news-events/alerts/2026/09/27/cisa-adds-two-known-exploited-vulnerabilities-catalog
  3. BleepingComputer, "Citrix confirms two NetScaler RCE zero-days exploited in attacks" (September 27, 2026): https://www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/
  4. BleepingComputer, "CISA orders feds to patch exploited Citrix flaws by Wednesday" (September 28, 2026): https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-exploited-citrix-flaws-by-wednesday/
  5. watchTowr, "Citrix NetScaler Zero-Day RCE FAQ: CVE-2026-88771 and CVE-2026-88772" (September 27, 2026): https://watchtowr.com/intelligence/citrix-netscaler-zero-day-vulnerabilities-faq/
NK

Naseem Khan (Technical Editor)

Cybersecurity Researcher & Technical Editor

UnpanicTech is supported by a dedicated team of cybersecurity specialists and writers. All research and articles are comprehensively reviewed and published by our Technical Editor, Naseem Khan, covering vulnerability analysis, defensive security, incident response, cloud security, and practical security engineering.

Technical Discussion & Feedback

Leave a Comment (Authenticated Users)