Citrix NetScaler CVE-2026-88771 & 88772 Exploited: Patch Now

Two critical NetScaler ADC and Gateway zero-days are being exploited in the wild. Here is what Citrix's CTX697096 bulletin and CISA's KEV listing say, and how to patch.

Citrix NetScaler logo
Image: Citrix.

Citrix has confirmed that two zero-day vulnerabilities in NetScaler ADC and NetScaler Gateway are being actively exploited, and both are serious enough that unpatched appliances should be taken off the internet or patched immediately. CVE-2026-88771 is an unauthenticated, no-user-interaction remote code execution flaw that affects every NetScaler ADC and Gateway deployment on a vulnerable build. CVE-2026-88772 is a memory-overflow bug that leads to remote code execution or denial of service when DTLS is enabled — the default state for VPN virtual servers, meaning most Gateway deployments are exposed unless an administrator has manually turned DTLS off. Citrix shipped fixed builds on September 27, 2026, and CISA added both CVEs to its Known Exploited Vulnerabilities (KEV) catalog the same day, giving federal civilian agencies until September 30, 2026 to remediate.

If you run NetScaler ADC or NetScaler Gateway, the immediate action is the same regardless of your industry: update to a fixed build now, and treat any unpatched, internet-facing appliance as potentially already compromised.

Key facts

  • CVE-2026-88771 — improper input validation; unauthenticated remote code execution; CVSS 4.0 9.5 (Critical)
  • CVE-2026-88772 — memory overflow; RCE or denial of service when DTLS is enabled; CVSS 4.0 9.5 (Critical)
  • Bulletin — Citrix CTX697096, published September 27, 2026, covering eight CVEs in total
  • Fixed builds — NetScaler ADC/Gateway 14.1-73.37 and later, or 13.1-64.23 and later (FIPS/NDcPP builds also patched)
  • CISA KEV status — both CVEs added September 27, 2026; federal remediation due date September 30, 2026
  • Exploitation — Citrix and CISA both confirm active exploitation of unmitigated devices; reports describe webshells planted on compromised appliances

What happened

On September 27, 2026, Citrix published security bulletin CTX697096, disclosing eight vulnerabilities in NetScaler ADC and NetScaler Gateway. Two of them — CVE-2026-88771 and CVE-2026-88772 — were flagged as already under attack. Citrix's bulletin states plainly that "exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed."

The disclosure followed roughly a week of warnings from European government cybersecurity sources about active attacks against NetScaler appliances, though Citrix's bulletin is the first confirmation of the specific CVEs and fixed builds. The pattern echoes other enterprise network-appliance zero-days disclosed this year, including Check Point's exploited Security Gateway and Management flaws and F5's exploited BIG-IP APM vulnerability: internet-facing VPN and application-delivery appliances remain one of the most consistently targeted categories of enterprise infrastructure.

CVE-2026-88771: unauthenticated remote code execution

CVE-2026-88771 is described in the National Vulnerability Database record as an improper input validation vulnerability in NetScaler ADC and NetScaler Gateway that lets an unauthenticated attacker execute arbitrary commands. NVD lists a CVSS v4.0 base score of 9.5 (Critical), with an attack vector of network, low attack complexity, no privileges required, and no user interaction required. There is no special configuration or optional feature that needs to be enabled — every deployment on an affected build is exposed by default.

CVE-2026-88772: memory overflow via DTLS

CVE-2026-88772 is a memory overflow vulnerability that NVD's record for the CVE lists as leading to remote code execution or denial of service, also rated CVSS v4.0 9.5 (Critical). Citrix's bulletin ties exploitability to DTLS (Datagram Transport Layer Security) being enabled on a virtual server. Because DTLS is on by default for NetScaler Gateway VPN virtual servers, most Gateway deployments meet the precondition for exploitation unless an administrator has explicitly disabled it.

CVEIssuePreconditionCVSS 4.0
CVE-2026-88771Improper input validation → unauthenticated RCENone — affects default configuration9.5 Critical
CVE-2026-88772Memory overflow → RCE or DoSDTLS enabled on a virtual server (default for VPN)9.5 Critical

Timeline of the disclosure

DateEvent
~September 19–20, 2026European government cybersecurity sources begin warning of active attacks against NetScaler appliances, ahead of any public confirmation of a specific vulnerability
September 27, 2026Citrix publishes security bulletin CTX697096, disclosing eight CVEs and confirming exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated deployments
September 27, 2026CISA adds CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities catalog and publishes an alert urging patching
September 30, 2026CISA's remediation due date for U.S. federal civilian agencies under BOD 26-04

The gap between the earliest field warnings and Citrix's formal bulletin is a familiar pattern with pre-authentication appliance zero-days: defenders in the field often see exploitation activity before a vendor has finished root-causing it, assigned CVE identifiers, and built a tested fix. That gap is also why CISA's guidance emphasizes checking for compromise rather than assuming that a device which "was patched quickly" was never touched.

NetScaler ADC and NetScaler Gateway sit at the network perimeter by design: they terminate VPN connections, load-balance application traffic, and often broker authentication for internal applications. That position is exactly what makes an unauthenticated, no-user-interaction remote code execution flaw like CVE-2026-88771 so severe — a successful exploit gives an attacker a foothold that is both internet-reachable and, in many deployments, trusted by the internal network on the other side of it. Security teams have seen the same dynamic play out with other perimeter appliances this year, and it is the reason vendors and CISA alike treat this class of vulnerability with more urgency than a comparably scored bug in, say, a desktop application.

The other six CVEs in the same bulletin

CTX697096 also covers six additional, lower-severity issues patched in the same builds: CVE-2026-88773 (HTTP request smuggling), CVE-2026-88774 (a feature policy bypass involving HTTP URL expressions), CVE-2026-88775 and CVE-2026-88776 (memory-overflow denial-of-service issues affecting Gateway/AAA configurations and Oracle load-balancing virtual servers respectively), CVE-2026-88777 (a memory-overflow denial of service affecting non-HTTP Layer 7 protocols), and CVE-2026-88778 (a TCP initial sequence number prediction issue). Citrix has not indicated that any of these six are being actively exploited, but they are fixed by the same update and should be applied together with the two zero-days.

Affected versions and fixed builds

Citrix's bulletin lists the same fixed builds across both zero-day CVEs and the bulletin as a whole:

BranchVulnerableFixed build
NetScaler ADC / Gateway 14.1before 14.1-73.3714.1-73.37 and later
NetScaler ADC / Gateway 13.1before 13.1-64.2313.1-64.23 and later
NetScaler ADC 14.1 FIPSbefore 14.1-73.37 FIPS14.1-73.37 FIPS and later
NetScaler ADC 13.1 FIPS / NDcPPbefore 13.1-37.27913.1-37.279 and later

NetScaler ADC and Gateway builds outside active support are not covered by these fixes; Citrix's guidance for customers running end-of-life versions is to upgrade to a supported, patched branch rather than wait for a hotfix.

CISA's KEV listing and the patch deadline

CISA added both CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities catalog on September 27, 2026, the same day as Citrix's bulletin, and separately published an alert titled "Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway." CISA states that threat actors are "actively exploiting these vulnerabilities globally" and that CVE-2026-88771 and CVE-2026-88772 "can independently enable remote code execution." Under Binding Operational Directive 26-04, federal civilian agencies must remediate KEV-listed vulnerabilities on internet-facing assets by CISA's assigned due date — set at September 30, 2026 for these two CVEs.

KEV listing is not merely a compliance formality for the private sector, either: CISA reserves it for vulnerabilities with confirmed, real-world exploitation, so any organization running NetScaler — federal or not — should treat the September 30 date as a meaningful outer bound, not a target.

Reports of webshells on unpatched devices

Multiple incident-response accounts describe attackers using the NetScaler flaws to plant webshells on unpatched appliances, giving them persistent access that can survive a simple configuration change. CISA's alert specifically urges organizations to check for indicators of compromise and preserve forensic evidence before applying the patch, since patching alone does not remove a webshell or other artifacts an attacker may have already planted, and upgrading a compromised appliance can destroy the forensic evidence needed to confirm whether that appliance was breached.

What NetScaler administrators should do now

  1. Identify every NetScaler ADC and NetScaler Gateway instance in your environment, including any deployed as a VPN, AAA, authentication, or load-balancing virtual server.
  2. Check the running build against the fixed-build table above before assuming a device is safe.
  3. Before upgrading, review CISA's and Citrix's guidance for compromise indicators (unexpected files, unfamiliar scheduled tasks, or web-accessible files in unusual directories) and preserve logs and forensic images if anything looks unusual.
  4. Apply the fixed build (14.1-73.37 / 13.1-64.23 or later, or the corresponding FIPS/NDcPP build).
  5. Where DTLS is enabled on a Gateway virtual server and not required, consider disabling it as an interim mitigation on devices that cannot be patched immediately.
  6. Rotate credentials and session tokens associated with the appliance after patching, since a compromised NetScaler may have had visibility into authentication traffic.

A compromised NetScaler Gateway can expose an entire organization's remote-access infrastructure, not just one user's traffic, which is why enterprise perimeter devices warrant a faster response than a typical desktop patch.

How this compares to other September 2026 zero-days

NetScaler's disclosure lands in the same week as September's Patch Tuesday, which fixed two actively exploited Windows zero-days. The common thread across all of these is the same: attackers are increasingly targeting the software organizations use to run their own infrastructure — VPN gateways, collaboration platforms, and operating systems — rather than waiting for phishing or credential-stuffing to work. For IT and security teams, that means patch cadence for perimeter infrastructure now needs to be treated with the same urgency as a critical Windows or browser update.

Frequently asked questions

Is my NetScaler affected if I haven't enabled DTLS?
CVE-2026-88771 affects every NetScaler ADC and Gateway deployment on a vulnerable build regardless of configuration, since it requires no special feature to be enabled. CVE-2026-88772 requires DTLS to be enabled, but DTLS is on by default for VPN virtual servers, so most Gateway deployments are exposed unless it has been explicitly turned off.

What build do I need to update to?
Citrix's bulletin CTX697096 lists NetScaler ADC and NetScaler Gateway 14.1-73.37 and later, or 13.1-64.23 and later, as fixed. FIPS and NDcPP-certified builds have their own fixed versions (14.1-73.37 FIPS and 13.1-37.279 FIPS/NDcPP, respectively).

Is there a patch deadline?
CISA added both CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, with a due date of September 30, 2026 for U.S. federal civilian agencies under Binding Operational Directive 26-04. Other organizations aren't bound by that directive, but CISA reserves KEV listing for vulnerabilities with confirmed active exploitation, so the same timeline is a reasonable target for any organization.

Should I check for compromise before or after patching?
CISA recommends checking for indicators of compromise and preserving forensic evidence before patching, because upgrading a compromised device can erase the artifacts needed to determine whether it was breached.

Are all eight CVEs in the bulletin being actively exploited?
No. Citrix and CISA have only confirmed active exploitation of CVE-2026-88771 and CVE-2026-88772. The other six CVEs in bulletin CTX697096 are fixed by the same builds but have not been reported as exploited.

What next

Treat any internet-facing NetScaler ADC or Gateway on a build older than 14.1-73.37 or 13.1-64.23 as urgent. Confirm your build number, check for signs of prior compromise using CISA's guidance, and apply the fixed build from Citrix. If your organization is subject to CISA directives or works with federal agencies, the September 30, 2026 KEV due date is the hard deadline; everyone else should still move on the same timeline given confirmed active exploitation.

Frequently asked questions

Is my NetScaler affected if I haven't enabled DTLS?

CVE-2026-88771 affects every NetScaler ADC and Gateway deployment on a vulnerable build regardless of configuration, since it requires no special feature to be enabled. CVE-2026-88772 requires DTLS to be enabled, but DTLS is on by default for VPN virtual servers, so most Gateway deployments are exposed unless it has been explicitly turned off.

What build do I need to update to?

Citrix's bulletin CTX697096 lists NetScaler ADC and NetScaler Gateway 14.1-73.37 and later, or 13.1-64.23 and later, as fixed. FIPS and NDcPP-certified builds have their own fixed versions (14.1-73.37 FIPS and 13.1-37.279 FIPS/NDcPP, respectively).

Is there a patch deadline?

CISA added both CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, with a due date of September 30, 2026 for U.S. federal civilian agencies under Binding Operational Directive 26-04. Other organizations aren't bound by that directive, but CISA reserves KEV listing for vulnerabilities with confirmed active exploitation, so the same timeline is a reasonable target for any organization.

Should I check for compromise before or after patching?

CISA recommends checking for indicators of compromise and preserving forensic evidence before patching, because upgrading a compromised device can erase the artifacts needed to determine whether it was breached.

Are all eight CVEs in the bulletin being actively exploited?

No. Citrix and CISA have only confirmed active exploitation of CVE-2026-88771 and CVE-2026-88772. The other six CVEs in bulletin CTX697096 are fixed by the same builds but have not been reported as exploited.

Sources

More on Citrix NetScaler →CitrixNetScalerzero-dayCVECISAenterprise security
Sana Qureshi
Written bySana Qureshi

Sana Qureshi runs the security and privacy desk. She reports on actively exploited vulnerabilities, vendor patches and data breaches, and covers the password managers, VPNs and authentication tools readers use to protect themselves. Her alerts cite vendor advisories, CISA and the CVE record directly.

More from Security & Privacy

See all