Marcus Chen, YuSMP Group
Marcus Chen Staff Engineer (Backend & Cloud), YuSMP Group · Infrastructure security for US and EU enterprise teams
A dark network appliance in a data center with its front panel cracked open, red glowing circuitry exposed and a cyan stream of light escaping through the breach

The short answer

Two critical flaws in Citrix NetScaler ADC and NetScaler Gateway, CVE-2026-88771 and CVE-2026-88772 (both CVSS 9.5), let an unauthenticated attacker run code on the appliance, and both were exploited before Citrix had a fix. Citrix published bulletin CTX697096 with patched builds on September 27, 2026, the same day CISA added both CVEs to its Known Exploited Vulnerabilities catalog with a September 30 federal deadline.

For most teams this is an emergency change for this week. CVE-2026-88771 works against default configurations, and the August fix for the earlier NetScaler bypass does not cover it. Treat the gateway that fronts your VPN and apps as part of your cloud and DevOps infrastructure, with the same patch speed and monitoring as production services: upgrade, preserve evidence, then rotate secrets.

What did Citrix disclose?

On September 27, 2026, Citrix released security bulletin CTX697096 covering eight vulnerabilities in NetScaler ADC and NetScaler Gateway, the appliances enterprises use to terminate VPN sessions, balance traffic and publish internal apps. Two of the eight are critical remote code execution flaws, and Citrix states that exploitation of both “on unmitigated NetScaler deployments” has been observed. They were used as zero-days: attackers had working exploits before a patch existed.

CVE-2026-88771 is the more dangerous of the two. It is an improper input validation bug that lets a remote attacker execute arbitrary commands with no credentials, and it applies to every NetScaler deployment on a vulnerable build, including the default configuration. CVE-2026-88772 is a memory overflow that can lead to code execution or a crash on appliances with DTLS enabled. DTLS is on by default for VPN virtual servers, so most NetScaler Gateway deployments meet that condition.

The disclosure moved quickly. On September 26 the Dutch National Cyber Security Centre privately warned organizations, and some administrators were told by suppliers to shut their appliances down. The next day Citrix shipped fixed builds and CISA listed both CVEs as known exploited. CISA says threat actors are exploiting the flaws globally and gave federal civilian agencies three days to fix them. Shadowserver data cited by BleepingComputer puts the internet-exposed NetScaler population at about 23,000 instances.

Why doesn’t the August patch protect you?

This is the third critical NetScaler exploitation wave in about a month. In August, Citrix fixed CVE-2026-19490, an authentication bypass that CISA added to KEV on September 9. Many teams upgraded to 14.1-73.32 or 13.1-63.21 at that point and closed the ticket. Those builds do not fix the new flaws. As watchTowr notes in its FAQ, appliances patched for CVE-2026-19490 stay vulnerable to CVE-2026-88771 and CVE-2026-88772 unless they run 14.1-73.37, 13.1-64.23 or the matching FIPS build.

A patch has limits too. CISA advises preserving forensic evidence before updating, because the upgrade can remove traces of an intrusion that already happened. Citrix offers an indicator-of-compromise scan through NetScaler Console, but warns that the indicators do not cover every technique. A clean scan lowers the odds of a breach without ruling one out. On an appliance that holds VPN sessions, LDAP bind credentials and TLS private keys, the realistic assumption for a box exposed before September 27 is that someone tried it.

What it means for US & EU software teams

First, the edge appliance is now the most-attacked component in many stacks, and it is often the least engineered. Application code goes through reviews, CI checks and staged rollouts. The vendor box in front of it usually gets patched by hand when someone reads an advisory. Three exploited critical flaws in one product within weeks show that this cadence is too slow. Gateway upgrades need a runbook, a tested rollback and an owner who can ship them within hours, just like any other production deploy.

Second, “patched” is a moving target. A team that only tracks whether an appliance received the last critical update will get this one wrong. Version inventory has to be checked against the latest advisory, not the previous one. That is a good argument for automated build tracking of edge devices in the same system that tracks your container images and dependencies.

Third, code execution on the gateway puts everything behind it in scope. Code execution on NetScaler gives an attacker a foothold at the point where sessions and credentials pass through. For EU organizations holding personal or financial data, that brings GDPR breach-assessment duties, NIS2 incident reporting and, for financial entities, DORA ICT-incident rules into play. The honest position is “we patched, preserved evidence and checked for compromise”, not “we patched”. Regulators and customers will ask which of the two you can show.

What should you do now?

  1. Inventory every NetScaler. List every ADC and Gateway, including DR, lab and forgotten appliances, with its exact build. Anything below 14.1-73.37 or 13.1-64.23 (or the matching FIPS build) is vulnerable, even if it was patched in August.
  2. Preserve evidence, then upgrade. Capture logs, configuration and a system snapshot before patching, as CISA recommends. Then upgrade as an emergency change. Appliances on 12.1 or 13.0 are end of life and must move to a supported branch.
  3. Reduce exposure until you patch. If an upgrade needs a maintenance window, cut internet exposure where the business allows it, and never leave the management interface reachable from the internet.
  4. Check for compromise. Run the Citrix IOC scan, review logs for unexpected processes, new admin accounts, configuration changes or files, and forward NetScaler logs to your SIEM. A clean result is a data point, not proof.
  5. Rotate what the appliance touched. Terminate active sessions and rotate passwords, service-account credentials, secrets and TLS certificates stored on or used through the appliance. Then add your edge devices to the next penetration test.

Frequently asked questions

What are CVE-2026-88771 and CVE-2026-88772?

They are two critical remote code execution vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway, both rated CVSS 9.5. CVE-2026-88771 is an improper input validation flaw that lets an unauthenticated attacker run arbitrary commands on any deployment, including the default configuration. CVE-2026-88772 is a memory overflow that can lead to code execution or denial of service on appliances with DTLS enabled, which is the default for VPN virtual servers. Citrix disclosed both on September 27, 2026 in bulletin CTX697096.

Which NetScaler versions are affected and what are the fixed builds?

NetScaler ADC and Gateway 14.1 before 14.1-73.37 and 13.1 before 13.1-64.23 are affected, as are FIPS builds before 14.1-73.37 FIPS and FIPS/NDcPP builds before 13.1-37.279. Upgrade to 14.1-73.37, 13.1-64.23 or the matching FIPS build. Versions 12.1 and 13.0 are end of life and will not be fixed, so those appliances must be moved to a supported release.

Are these NetScaler flaws being exploited?

Yes. Citrix states that exploitation of both flaws on unmitigated appliances has been observed, and they were used before any patch existed. The Dutch NCSC privately warned organizations on September 26, 2026. CISA added both CVEs to its Known Exploited Vulnerabilities catalog on September 27 and set a September 30 remediation deadline for US federal civilian agencies, noting that threat actors are exploiting them globally.

We patched NetScaler in August for CVE-2026-19490. Are we protected?

No. The August builds (14.1-73.32 and 13.1-63.21) fixed the earlier authentication bypass but do not fix CVE-2026-88771 or CVE-2026-88772. Any appliance that is not on 14.1-73.37, 13.1-64.23 or the matching FIPS build remains vulnerable, regardless of earlier patching.

What should we do besides installing the patch?

Preserve forensic evidence first, because CISA warns the update can remove traces of compromise. Run the Citrix indicator-of-compromise scan, bearing in mind that a clean result is not proof the appliance was never breached. After upgrading, rotate passwords, secrets and certificates stored on or used through the appliance, terminate active sessions, send NetScaler logs to your SIEM and keep management interfaces off the internet.

Sources

Citrix — NetScaler ADC and NetScaler Gateway Security Bulletin CTX697096 (CVE-2026-88771 to CVE-2026-88778)
CISA — Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway (Sept 27, 2026)
BleepingComputer — Citrix confirms two NetScaler RCE zero-days exploited in attacks
BleepingComputer — CISA orders feds to patch exploited Citrix flaws by Wednesday
watchTowr — Citrix NetScaler Zero-Day RCE FAQ: CVE-2026-88771 and CVE-2026-88772