Two critical NetScaler ADC and Gateway flaws were used in attacks before Citrix had fixes. Here's what the vendor, CISA and researchers have actually confirmed, and what to do before you install the update.
Over the weekend of September 26 and 27, NetScaler admins started getting phone calls telling them to switch their appliances off. No CVE numbers, no advisory, no details. Just "shut it down." [3]
By Sunday the reason was public. Citrix published security bulletin CTX697096 and confirmed that two critical flaws, CVE-2026-88771 and CVE-2026-88772, have been exploited on unmitigated NetScaler ADC and Gateway deployments [1]. CISA added both to its Known Exploited Vulnerabilities (KEV) catalog the same day [2] [4].
If you only have a minute: update every customer-managed NetScaler ADC and Gateway to a fixed build (table below), but capture evidence first. CISA warns that an update can wipe out forensic visibility [2]. Federal civilian agencies have until September 30 [4]. Everyone else should treat that date as a hint.
The weekend, in order
Before Citrix said anything, administrators reported being told by suppliers and security teams to shut appliances down. Those warnings followed what was described as a private pre-notification from the Dutch national cyber security centre, NCSC-NL [5]. NCSC-NL wouldn't confirm the notice to BleepingComputer, saying the reporter wasn't part of its constituency [3]. So what's in that notice is reported, not verified.
On September 26, watchTowr publicly warned that unpatched NetScaler remote code execution flaws were being exploited. It said the information was credible and came from forensic investigations [5]. Citrix published its bulletin the next day [1].
One more detail circulated with the leaked notice. It reportedly said one bug let attackers place shellcode directly into memory, while the second was still being researched [3]. That's a leaked document described by a news site. Don't build detection logic on it.
Two bugs, two very different preconditions
The distinction matters because one of these hits every appliance and the other needs a feature switched on. Both are rated 9.5 under CVSS v4.0 in Citrix's bulletin [1].
| CVE | Flaw | What must be true | CVSS v4.0 (per Citrix) |
|---|---|---|---|
| CVE-2026-88771 | Improper input validation (CWE-20). An unauthenticated attacker can execute arbitrary commands. | Any NetScaler ADC or Gateway on an affected build. Default configuration, no extra feature needed. | 9.5 AV:N/AC:L/AT:P/PR:N/UI:N |
| CVE-2026-88772 | Memory overflow (CWE-119). Can lead to remote code execution or denial of service. | DTLS enabled. That's the default on VPN virtual servers. | 9.5 AV:N/AC:H/AT:N/PR:N/UI:N |
Both vectors also rate all six impact metrics (VC, VI, VA, SC, SI, SA) as High.
These scores come from Citrix's bulletin. The NVD entries wouldn't load for me, so I can't say whether NVD scores them differently.
Look at the vectors side by side and they aren't twins. CVE-2026-88771 is low complexity but marks attack requirements as "present," meaning some condition about the target has to hold. Citrix doesn't say what that condition is, and I won't guess. CVE-2026-88772 is the reverse: high attack complexity, no attack requirements. They land on the same 9.5 because neither needs credentials or user interaction and the impact ratings are maxed out.
Citrix's bulletin shows how to check the DTLS precondition. A VPN virtual server defined without -dtls OFF has DTLS on by default [1]:
# DTLS not explicitly disabled = enabled by default
add vpn vserver vpn1 SSL 10.0.0.0 443 -Listenpolicy NONE
# DTLS explicitly disabled = precondition not met
add vpn vserver vpn1 SSL 10.0.0.0 443 -dtls OFF -Listenpolicy NONE
Fixed builds, and one thing to double-check
| Product | Affected | Fixed |
|---|---|---|
| ADC and Gateway 14.1 | Before 14.1-73.37 | 14.1-73.37 and later |
| ADC and Gateway 13.1 | Before 13.1-64.23 | 13.1-64.23 and later 13.1 releases |
| ADC 14.1-FIPS | Before 14.1-73.37 FIPS | 14.1-73.37 FIPS and later |
| ADC 13.1-FIPS and 13.1-NDcPP | Before 13.1-37.279 | 13.1.37.279 and later |
Citrix writes that last build two ways, 13.1-37.279 in the affected list and 13.1.37.279 in the fix list [1]. It's probably one build with a typo, but that's my inference. Confirm with Citrix support before you plan around it.
Scope notes from the bulletin: Secure Private Access Hybrid deployments that use NetScaler instances are also affected, and the bulletin covers customer-managed appliances only. Cloud Software Group upgrades Citrix-managed cloud services itself [1].
Already patched in August? watchTowr says appliances fixed for the earlier CVE-2026-19490 are still vulnerable to these two unless they're on one of the builds above [5]. A clean patch record for the last NetScaler bug tells you nothing about this one.
Evidence first, then update
This is the part people will be tempted to skip. CISA advises checking for indicators of compromise before patching where possible, and preserving forensic evidence if you suspect a compromise, because updates can destroy it [2].
watchTowr's version of the sequence: capture logs, a snapshot, a support bundle and a core dump from each exposed appliance; check for compromise; install the fixed build; rotate passwords, secrets and certificates stored on or used through the appliance; forward NetScaler logs to a SIEM; and keep management interfaces off the public internet [5].
Citrix provides generic IOCs through NetScaler Console. watchTowr says the scan needs Console 14.1-73.36 or later with telemetry enabled [5]. Citrix itself cautions that these indicators may miss real compromises and suggests bringing in experienced forensic investigators [4].
My read: a clean scan is weak evidence. Nobody I read says when exploitation began, so an appliance that was internet-facing on an affected build should be treated as possibly exposed even if the scan finds nothing. Rotating credentials and certificates isn't overkill here. NetScaler terminates VPN sessions and handles authentication, so what it holds is exactly what an intruder would want.
watchTowr also flags a reboot-loop problem on 13.1. If show ns variable returns any variables, it recommends 13.1-64.24 instead [5]. That's watchTowr's guidance, not something I found in Citrix's bulletin, so check with Citrix before relying on it.
What's actually known about the attacks
Exploitation is confirmed by the vendor. Citrix says exploits of both flaws on unmitigated deployments have been observed [1]. CISA says it has reports and partner threat intelligence confirming that threat actors are actively exploiting them globally [2]. The KEV listing followed, with a September 30 deadline for federal civilian agencies under Binding Operational Directive 26-04 [4].
Nearly everything else is unknown. No attribution has been made public [5]. The leaked NCSC-NL notice reportedly said exploitation was seen at multiple customers worldwide but that the agency didn't know whether it was widespread [3]. The same notice reportedly warned that attempts could rise once patches and technical details were out. None of the pages I read mention public exploit code, but that's an absence in my reading, not proof none exists.
You'll see exposure numbers quoted. Shadowserver tracks more than 23,000 IP addresses with NetScaler fingerprints, nearly 22,000 of them ADC and just over 1,500 Gateway. BleepingComputer points out there's no breakdown of how many are honeypots, already patched, or actually vulnerable [4]. It's a rough size of the pool, not a count of vulnerable systems.
A note on watchTowr: it sells exposure-management tooling, and its FAQ includes a product pitch. The technical points I've cited match Citrix's own bulletin where they overlap, but read the marketing as marketing.
Six more bugs in the same bulletin
CTX697096 fixes eight vulnerabilities in total. CVE-2026-88773 through CVE-2026-88778 depend on specific configurations: HTTP request smuggling (9.3), a feature policy bypass (7.0), three memory overflows that can cause denial of service or erratic behavior (8.8 each), and TCP initial sequence number prediction (8.8) [1]. Citrix reports observed exploitation only for the first two CVEs.
The TCP one needs extra work. Citrix tells affected customers to apply a TCP configuration change (Enhanced ISN Generation) [1], and watchTowr says the upgrade alone doesn't fix it [5].
What I'd do first
- Build the list. Every customer-managed ADC and Gateway, including FIPS and NDcPP builds and any NetScaler behind a Secure Private Access hybrid setup.
- Preserve evidence on the exposed ones before changing anything.
- Patch the internet-facing Gateway, VPN and authentication servers first. watchTowr's priority list [5] makes sense, but remember CVE-2026-88771 hits every deployment, so an ADC doing plain load balancing isn't safe just because it isn't a VPN.
- Rotate secrets and certificates after the update, then apply the TCP setting for CVE-2026-88778.
- Keep watching. Citrix's bulletin showed only its initial publication when I read it, and attribution and scale are still open.
The pattern is the bigger story. Since November 2021, CISA has flagged 26 exploited Citrix vulnerabilities, six of them abused by ransomware gangs [4]. CVE-2026-19490 went into KEV on September 9 and these two followed less than three weeks later. They're separate bugs. Which one you've patched says nothing about the others.
Published September 28, 2026. This story is still moving. If Citrix updates the bulletin or new exploitation details emerge, the change will be noted here.
Sources & References
- Citrix, "NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778" (CTX697096), published September 27, 2026: https://support.citrix.com/external/article/CTX697096
- CISA, "Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway" (September 27, 2026): https://www.cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway. See also CISA's KEV addition alert: https://www.cisa.gov/news-events/alerts/2026/09/27/cisa-adds-two-known-exploited-vulnerabilities-catalog
- BleepingComputer, "Citrix confirms two NetScaler RCE zero-days exploited in attacks" (September 27, 2026): https://www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/
- BleepingComputer, "CISA orders feds to patch exploited Citrix flaws by Wednesday" (September 28, 2026): https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-exploited-citrix-flaws-by-wednesday/
- watchTowr, "Citrix NetScaler Zero-Day RCE FAQ: CVE-2026-88771 and CVE-2026-88772" (September 27, 2026): https://watchtowr.com/intelligence/citrix-netscaler-zero-day-vulnerabilities-faq/

Technical Discussion & Feedback
Leave a Comment (Authenticated Users)