Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Sep 28, 2026 · 9 min read

CVE-2026-88771 and 88772: NetScaler Zero Days Exploited

On September 27, 2026, Citrix confirmed that attackers had exploited two NetScaler ADC and NetScaler Gateway flaws before any fix existed. One of them affects every deployment in its default configuration. CISA gave federal agencies until September 30 to patch.

The first warning did not come from Citrix. It came from phone calls. "We got a call from our IT supplier's security team, they couldn't give any details but they advised to shut our Netscalers down immediately," one administrator wrote on Reddit, according to BleepingComputer. Others said CERTs, national agencies and law enforcement were making the same calls.

A day later Citrix published security bulletin CTX697096 and confirmed the rumor: two unauthenticated remote code execution bugs, CVE-2026-88771 and CVE-2026-88772, both rated 9.5 under CVSS v4.0, both already used in attacks.

Key Takeaways

  • CVE-2026-88771 is an improper input validation flaw that lets an unauthenticated attacker run arbitrary commands on any NetScaler ADC or Gateway running an affected build, with no extra feature enabled.
  • CVE-2026-88772 is a memory overflow reachable through DTLS, which Citrix says is enabled by default on VPN virtual servers.
  • Citrix says "exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed," and CISA added both to its Known Exploited Vulnerabilities catalog on September 27, 2026.
  • Fixed builds are 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS and 13.1-37.279 for FIPS and NDcPP, and appliances on the builds that fixed CVE-2026-19490 still need this update.
  • NCSC-NL, the Dutch national cyber security centre, says the update blocks new exploitation but does not rule out an earlier compromise, so memory dumps and logs should be preserved before patching.
A dark data center aisle with a rack mounted network appliance showing a single amber warning light while a technician with a laptop stands out of focus in the background

What Is CVE-2026-88771?

CVE-2026-88771 is a remote code execution vulnerability in NetScaler ADC and NetScaler Gateway, caused by improper input validation (CWE-20), that lets an attacker with no credentials execute arbitrary commands. The NVD record repeats the fixed builds, and Citrix lists its precondition as "All NetScaler ADC and NetScaler Gateway deployments (Default configuration / No additional feature required)."

Earlier 2026 NetScaler bugs needed a specific setup: CVE-2026-3055 and CVE-2026-8451 hit appliances configured as SAML identity providers, and CVE-2026-19490 needed a Gateway or AAA virtual server. This one needs no feature at all. A vulnerable build that an attacker can reach is enough. The CVSS v4.0 vector in the bulletin, AV:N/AC:L/AT:P/PR:N/UI:N, spells that out: network reachable, low complexity, no privileges, no user interaction. The AT:P flag means some condition outside the attacker's control must hold, and Citrix has not said what it is.

Citrix has published no root cause. An advance notice that circulated before the bulletin, attributed to NCSC-NL and quoted by BleepingComputer, said one of the two flaws let attackers place shellcode directly into memory. The agency declined to confirm the document, so treat that detail as reported rather than official.

What Is CVE-2026-88772?

CVE-2026-88772 is a memory overflow (CWE-119) that can lead to remote code execution or denial of service on any NetScaler with DTLS enabled. DTLS is the datagram flavor of TLS that Gateway uses for VPN tunnels, and Citrix notes it is "Enabled by default on VPN vServer." Its CVSS vector marks attack complexity as high, yet it still scores 9.5.

The Citrix bulletin gives admins a quick config test. A Gateway is vulnerable if DTLS is not explicitly disabled:

  • add vpn vserver vpn1 SSL 10.0.0.0 443 -Listenpolicy NONE means DTLS is on by default, so the box is exposed.
  • add vpn vserver vpn1 SSL 10.0.0.0 443 -dtls OFF -Listenpolicy NONE means DTLS is off and the precondition is not met.
  • Any add vpn vserver or add lb vserver line of type DTLS also meets the precondition.

Turning DTLS off shrinks exposure to CVE-2026-88772 only. It does nothing for CVE-2026-88771, which is why no one should treat it as a workaround.

Which NetScaler Builds Are Affected and Fixed?

Every customer managed NetScaler ADC and Gateway on 14.1 or 13.1 below the builds below is affected, per CTX697096:

  • NetScaler ADC and Gateway 14.1: upgrade to 14.1-73.37 or later.
  • NetScaler ADC and Gateway 13.1: upgrade to 13.1-64.23 or later.
  • NetScaler ADC 14.1-FIPS: upgrade to 14.1-73.37 FIPS or later.
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP: upgrade to 13.1-37.279 or later.

Secure Private Access Hybrid deployments that use NetScaler instances are affected too. Citrix managed cloud services are patched by Cloud Software Group, Citrix's parent company.

Two details catch teams out. First, The Hacker News points out that builds 14.1-73.32 and 13.1-63.21, which fixed the exploited authentication bypass CVE-2026-19490, fall inside the affected range. Admins who patched weeks ago must patch again. Second, the same bulletin fixes six more CVEs, and one of them, the TCP sequence number prediction bug CVE-2026-88778, is closed by a config change rather than the upgrade. Check it with show ns tcpparam | grep "Enhanced ISN Generation". If it reads DISABLED, the upgrade alone leaves that flaw open.

How Did the Zero Days Come to Light?

Citrix found the flaws while investigating incidents in customer environments, according to the advance notice described by BleepingComputer. That notice said NCSC-NL had the information from a European partner CERT, that exploitation had been identified at multiple Citrix customers worldwide, and that Citrix had filed a notification under the EU Cyber Resilience Act. It also said the agency did not know whether the attacks were widespread.

The timeline moved fast:

  • September 26: admins report calls telling them to power down NetScalers, and security firm watchTowr calls the rumors of unpatched RCE flaws credible.
  • September 27: Citrix publishes CTX697096 with eight CVEs. CISA adds CVE-2026-88771 and CVE-2026-88772 to the Known Exploited Vulnerabilities catalog with a September 30 due date.
  • September 27, 18:55 Amsterdam time: NCSC-NL publishes advisory NCSC-2026-0394 and urges immediate patching.

The shutdown advice made sense before a patch existed, and it was the second such call that weekend. Kiteworks asked customers to take servers offline the same Saturday, covered in Kiteworks Zero Day Warning: Why It Told Customers to Unplug. Nothing public connects the two events, but both treated a powered off box as the only safe one.

Is Patching Enough?

No. Patching stops new exploitation but does not remove an attacker who got in before the fix. The Dutch NCSC alert tells admins to secure the memory dump and log files going back at least one month before installing the update, and to keep monitoring the appliance afterwards. CISA's KEV entries are marked for forensic triage under Binding Operational Directive 26-04, and they note that "running the provided IOCs in the NetScaler console may help identify indicators of exploitation." The Citrix bulletin links to a NetScaler blog post with an Indicators of Compromise section.

For appliances you suspect were hit, Citrix's standing guide CTX694799 sets the order of work:

  • Preserve evidence first: snapshot VPX instances, pull logs from remote syslog and NetScaler Console, generate a support bundle, and capture a Packet Engine core dump. The core dump triggers a warm restart.
  • Isolate the device from the network.
  • Revoke credentials: LDAP service accounts, RADIUS shared secrets, OAuth tokens, API keys, SNMP community names, every user who authenticated through Gateway or AAA virtual servers, and all certificates and private keys on the box.
  • Investigate connected systems, especially authentication servers and management jump hosts.
  • Rebuild, don't clean: Citrix recommends replacing VPX instances and wiping MPX appliances, then restoring a backup that predates the compromise.
  • Watch for 90 days after recovery, and keep the management interface off the internet. Citrix's words: "The NetScaler Management Services should never be exposed to the public internet."

NetScaler's 2026 Track Record

This is the fourth exploited NetScaler flaw CISA has listed in 32 days. The KEV catalog shows CVE-2026-8452 added on August 26, CVE-2026-19490 on September 9, and both new CVEs on September 27. Count the March SAML memory leak we covered in Citrix NetScaler Has a 9.3 Severity Flaw That Leaks Memory and the tally for 2026 reaches five NetScaler KEV entries by the end of September, against three for all of 2025.

In between came CitrixBleed Echo, CVE-2026-8451, which drew scanning within a day of its June 30 patch. The difference this time is that no patch diff was needed. Attackers had working exploits first, and defenders learned about them from their suppliers' phone calls.

Branch support adds pressure. NetScaler 13.1 reached End of Maintenance on September 15, according to The Hacker News, twelve days before this fix shipped. Teams on that branch should plan the move to 14.1 rather than count on the next emergency build.

What This Means for Your Inbox

NetScaler Gateway is the front door for remote work. NCSC-NL describes it as a service that lets employees connect to the corporate network and log in everywhere with a single user account. That is why Citrix's compromise guide tells companies to reset every account that authenticated through the Gateway and to rotate the LDAP and OAuth credentials stored on the appliance. When the same directory account also opens Microsoft 365 or Google Workspace mail, a gateway compromise puts your mailbox password at risk as well.

If your employer runs NetScaler, expect forced password resets and new sign in prompts this week. Attackers know that too. Incidents like this one generate a wave of genuine "reset your password" and "reconnect your VPN" emails, which makes fake ones easier to slip past people. Verify any reset request through your IT portal or a known phone number, never through a link in the message, and watch for the session hijacking tricks that bypass MFA that follow credential leaks. VPN gateways are a proven source of stolen logins: FortiBleed exposed 73,000 VPN passwords from Fortinet appliances.

What Should Security Teams Do Today?

Security teams should inventory every NetScaler, preserve evidence, patch, and then hunt, in that order. A working checklist built from the Citrix bulletin, NCSC-NL and CISA BOD 26-04:

  • List every customer managed ADC and Gateway, plus Secure Private Access Hybrid instances, including lab and DR boxes.
  • If you cannot patch within hours, reduce internet exposure where operations allow. A powered off or firewalled appliance cannot be hit.
  • Before upgrading, capture a memory dump and at least one month of logs.
  • Upgrade each appliance to its fixed build from the list above, then enable Enhanced ISN Generation for CVE-2026-88778.
  • Run the Citrix IOCs from NetScaler Console on every appliance that was exposed before the upgrade.
  • On any hit, follow CTX694799: isolate, rotate secrets, reset Gateway users, and rebuild.

Federal agencies have until September 30. Everyone else should assume attackers will not wait that long.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.