Citrix NetScaler Zero-Days CVE-2026-88771/88772 Exploited; CISA Gives 3 Days
Two unauthenticated RCE flaws in NetScaler ADC and Gateway were exploited before Citrix's 27 September bulletin. One hits the default config; CISA set a 30 September deadline with forensic triage.
Citrix published bulletin CTX697096 on 27 September 2026 covering eight new vulnerabilities in NetScaler ADC and NetScaler Gateway. Two of them, CVE-2026-88771 and CVE-2026-88772, are unauthenticated remote code execution flaws that were being exploited before the bulletin existed. CISA added both to the Known Exploited Vulnerabilities catalog the same day and set a remediation deadline of 30 September, three days out, with the forensic-triage flag switched on. If you run a NetScaler that faces the internet, this is a patch-tonight event, and the patch is the easy part.
What Happened
The story surfaced a day before the vendor said anything. On 26 September, watchTowr warned publicly that multiple unpatched NetScaler remote code execution bugs were being exploited in the wild, citing forensic investigations rather than lab research. BleepingComputer reported NetScaler administrators being told by their IT suppliers' security teams to shut their appliances down immediately without being given a reason, and others hearing from law enforcement, national CERTs, and cybersecurity agencies before any advisory was available. That is the profile of an incident already in progress, not a coordinated disclosure.
Citrix's bulletin landed on 27 September with a single line on exploitation: exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed. NVD published the CVE-2026-88771 record at 17:16 UTC that afternoon, and CISA's catalog update followed with a dateAdded of 27 September. CISA's Stakeholder-Specific VulnerabilityVulnerability🛡️A weakness in software, hardware, or processes that can be exploited by attackers to gain unauthorized access or cause harm. Categorization decision for CVE-2026-88771 records exploitation as active, technical impact as total, and automatable as no.
Who Is Affected
Citrix lists four affected lines, all fixed by moving to the first clean build:
- NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
- NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
- NetScaler ADC FIPS before 14.1-73.37 FIPS
- NetScaler ADC FIPS and NDcPP before 13.1-37.279
The bulletin says nothing about the 12.1 and 13.0 branches, which have been out of support for some time. Treat silence as "no fix coming" and plan a version migration, not a patch. Citrix also states that Secure Private Access Hybrid deployments that use NetScaler instances are affected, while cloud-managed NetScaler services receive their updates separately from Citrix.
The exposure question is the important one. CVE-2026-88771 affects the default configuration; Citrix and every researcher who has written it up agree that no optional feature needs to be enabled. CVE-2026-88772 requires DTLS, but DTLS is enabled by default on VPN virtual servers, so the practical population is every NetScaler Gateway that terminates remote-access VPN sessions and has not had DTLS explicitly turned off. Our guide on how to confirm whether a configuration-dependent CVE applies to your appliance fleet walks through separating those two populations, but for this bulletin the shortcut is simple: if the appliance is reachable from the internet and below the fixed build, it is in scope.
Technical Analysis
CVE-2026-88771 is classified as CWE-20, improper input validation, and carries a CVSS 4.0 base score of 9.5 with a vector of AV:N/AC:L/AT:P/PR:N/UI:N and high impact across every confidentiality, integrity, and availability metric on both the vulnerable and subsequent systems. NIST's independent CVSS 3.1 assessment scores it 9.8. The Citrix description is terse: an unauthenticated attacker can execute arbitrary commands. No component or endpoint has been named publicly, and no proof-of-concept had been published as of 28 September.
CVE-2026-88772 is a memory-safety bug, CWE-119, also scored 9.5 under CVSS 4.0, with a vector of AV:N/AC:H/AT:N/PR:N/UI:N. The high attack complexity reflects the reality of turning a memory overflow into reliable code execution on an appliance; the attacker either gets code execution or crashes the packet engine, and both outcomes are bad for you. The precondition is DTLS, the UDP-based variant of TLS that NetScaler Gateway uses to carry VPN traffic with lower latencyLatency🌐The delay between sending a request and receiving a response, measured in milliseconds (ping). than a TCP tunnel. We explain the mechanism and why it matters for perimeter devices in our explainer on how DTLS works and why it widens a VPN gateway's attack surfaceAttack Surface🛡️The sum of all points where an unauthorized user could attempt to enter or extract data from a system: exposed services, interfaces, accounts, and integrations. Reducing attack surface means removing reachability, not just patching..
The other six CVEs in the bulletin are not confirmed exploited but are not trivial either. CVE-2026-88773 is an HTTP request smugglingHTTP Request Smuggling🛡️An attack that exploits disagreement between two HTTP parsers, typically a front-end proxy and a back-end server, about where one request ends and the next begins. The attacker slips a hidden request past the front end's security checks to reach the back end directly. flaw, CWE-444, scored 9.3, affecting any deployment with HTTP configured. CVE-2026-88774 is a policy bypass through improperly evaluated HTTP URL expressions at 7.0. CVE-2026-88775, CVE-2026-88776, and CVE-2026-88777 are memory overflows scored 8.8 that produce crashes or erratic behavior on Gateway and AAA virtual servers, Oracle load-balancing virtual servers, and non-HTTP layer-7 or CGNAT configurations respectively. CVE-2026-88778, scored 8.8, is predictable TCP initial sequence numbers, CWE-342, and is the one item that a firmwareFirmware🏠Permanent software programmed into a device's hardware that controls its basic functions. upgrade alone does not close: Citrix directs customers to a configuration change enabling enhanced ISN generation.
Immediate Actions
Do these in order, because the order matters.
First, decide whether the appliance stays online while you work. Given confirmed exploitation of a default-configuration RCE, taking the Gateway off the internet for a few hours is a defensible call, and the administrators who did so on 26 September on their suppliers' advice were not overreacting. We make the case for having that decision pre-authorized in why pulling a perimeter appliance offline is a legitimate zero-dayZero-Day🛡️A security vulnerability that is exploited or publicly disclosed before the software vendor can release a patch, giving developers 'zero days' to fix it. response.
Second, preserve evidence before you upgrade. CISA's BOD 26-04BOD 26-04🛡️CISA Binding Operational Directive 26-04, issued 10 June 2026, which replaced BOD 22-01. It assigns federal civilian agencies remediation deadlines of 3, 14, or 60 days based on asset exposure, KEV status, exploit automation, and post-exploitation impact, and requires forensic triage for the 3-day tier. forensic-triage requirement applies here, and an upgrade overwrites the system partition and reboots the packet engine, destroying volatile state. Citrix's compromise-response article CTX694799 is the checklist: snapshot a VPX, record system time and NTP configuration, collect the technical support bundle, generate a packet-engine core file and copy it from the highest-numbered folder under `/var/core/`, where the files carry an `NSPPE-` prefix. For MPX and SDX hardware, Citrix recommends powering down after memory capture, imaging the disks with a write-blocker, and keeping two copies under documented chain of custodyChain of Custody🛡️A documented record of who handled a piece of evidence, when, and how, from the moment it was collected until it is presented. Disk images and logs taken from a compromised device without chain-of-custody records may be unusable in legal or regulatory proceedings.. Our walkthrough on how to preserve forensic evidence on a network appliance before you patch it turns that list into a repeatable procedure.
Third, run the indicator check. Citrix offers an IOC scan from the NetScaler Console security advisory page on 14.1-73.36 and later with telemetry enabled, or you can request the indicators from Citrix Support. Read the caveat carefully: Citrix says the indicators do not cover every technique, so a clean scan is not proof the appliance was untouched. Truesec's write-up lists three command-and-control addresses observed in the campaign: 104.248.244.66, 139.180.152.138, and 77.83.199.39. Search your egress logs for connections from the NetScaler's subnet IP to any of them.
Fourth, upgrade. On the 13.1 branch, watchTowr flags an operational trap: run `show ns variable` before upgrading, and if any variables are returned, use 13.1-64.24 rather than 13.1-64.23 to avoid a reboot loop. Rapid7 shipped authenticated checks for the CVEs in its 28 September content release if you need fleet-wide verification.
Fifth, apply the enhanced ISN configuration for CVE-2026-88778 and rotate everything the appliance held: local account passwords, key encryptionEncryption🛡️The process of converting data into a coded format that can only be read with the correct decryption key. keys, service-account credentials for LDAP and RADIUSRADIUS🌐Remote Authentication Dial-In User Service, the protocol network devices use to ask a central server whether a user or device should be granted access and with what attributes. Each device shares a secret with the server, so a compromised server exposes the secrets of every device that trusts it. binds, and every SSL certificate and private key that lived on the box. If the IOC scan came back positive, Citrix's guidance is to rebuild from the latest firmware and restore a backup that predates the compromise, then rotate the restored secrets again. Our earlier piece, after a firewallFirewall🌐Security system that monitors and controls network traffic based on predetermined rules. breach, assume every stored credential is compromised, explains why that second rotation is not paranoia.
Long-Term Outlook
This is the second NetScaler entry in the KEV catalog this month, after the CVE-2026-19490 authentication bypassAuthentication Bypass📖A security vulnerability that allows an attacker to circumvent the login verification process and gain unauthorized access to a system without providing valid credentials. added on 9 September. A remote-access gateway concentrates credentials, session cookies, and trust relationships from every user who logs in through it, which is why attackers keep coming back to the product line and why each new bug is exploited within days rather than months. The eight-CVE bulletin also suggests a broad code audit is underway inside Citrix, which usually means more advisories follow.
The strategic fix is not faster patching, though you need that too. It is treating the Gateway as a tier-0 asset: no shared service accounts, short-lived certificates, egress filteringEgress Filtering🌐Restricting the outbound connections a system may make to an explicit list of required destinations, enforced at the network layer or through an egress proxy. It breaks payload downloads, mining-pool connections and callback channels, and turns an attacker's success signal into a detection event. so a compromised appliance cannot phone home, and an emergency shutdown procedure that a night-shift engineer can execute without a change board. The organizations that took their NetScalers offline on 26 September had that latitude. The ones that waited for the bulletin gave the attackers another day.
Sources
- Citrix, "NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778", CTX697096 (27 September 2026): https://support.citrix.com/external/article/CTX697096/citrix-netscaler-adc-and-citrix-netscale.html
- Citrix, "Steps to Take if NetScaler ADC is Suspected to be Compromised", CTX694799: https://support.citrix.com/external/article/CTX694799/steps-to-take-if-netscaler-adc-is-suspec.html
- CISA Known Exploited Vulnerabilities feed (catalog version 2026.09.27): https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
- NVD entry for CVE-2026-88771: https://nvd.nist.gov/vuln/detail/CVE-2026-88771
- watchTowr, "Citrix NetScaler Zero-Day RCE FAQ: CVE-2026-88771 and CVE-2026-88772" (27 September 2026): https://watchtowr.com/intelligence/citrix-netscaler-zero-day-vulnerabilities-faq/
- Rapid7, "Zero-Day Exploitation of Citrix NetScaler ADC and Gateway: CVE-2026-88771 and CVE-2026-88772" (28 September 2026): https://www.rapid7.com/blog/post/etr-zero-day-exploitation-of-citrix-netscaler-adc-and-gateway-cve-2026-88771-and-cve-2026-88772/
- BleepingComputer, "Citrix confirms two NetScaler RCE zero-days exploited in attacks": https://www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/
- Truesec, "Multiple Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway" (28 September 2026): https://www.truesec.com/hub/blog/multiple-critical-vulnerabilities-in-citrix-netscaler-adc-and-netscaler-gateway