Citrix released fixed builds for NetScaler ADC and NetScaler Gateway on Sunday, September 27, 2026, covering eight vulnerabilities. Two of them, CVE-2026-88771 and CVE-2026-88772, were already being exploited against unpatched appliances before the fixes existed. CISA added both to its Known Exploited Vulnerabilities (KEV) catalog the same day and set a September 30 remediation deadline for federal civilian agencies.
The patch followed a weekend in which some NetScaler administrators were advised to take their appliances offline entirely, before any CVE identifiers or fixes had been published.
What Citrix disclosed
Citrix's security bulletin, CTX697096, lists CVE-2026-88771 through CVE-2026-88778. The two exploited flaws both carry a CVSS v4.0 score of 9.5.
CVE-2026-88771 is an improper input validation flaw that lets an unauthenticated remote attacker execute arbitrary commands on the appliance. It affects NetScaler ADC and NetScaler Gateway on affected versions in their default configuration, with no additional features enabled (Unit 42, 2026; watchTowr, 2026).
CVE-2026-88772 is a memory buffer flaw that can lead to remote code execution or denial of service. It requires DTLS to be enabled. DTLS is on by default for VPN virtual servers, so most NetScaler Gateway deployments meet that condition unless an administrator has switched it off (Unit 42, 2026).
The other six CVEs in the bulletin depend on specific configurations and include HTTP request smuggling and denial-of-service issues (Help Net Security, 2026). None of them has been reported as exploited.
No workaround has been published for the two exploited flaws. The fix is an upgrade. For CVE-2026-88778, a TCP sequence number prediction issue, the bulletin also directs customers to enable enhanced ISN generation in the TCP configuration.
Affected and fixed versions
According to the bulletin, as summarised by watchTowr and SOCRadar, the fixed builds are:
- NetScaler ADC and NetScaler Gateway 14.1: 14.1-73.37 or later
- NetScaler ADC and NetScaler Gateway 13.1: 13.1-64.23 or later
- NetScaler ADC 14.1-FIPS: 14.1-73.37 FIPS or later
- NetScaler ADC 13.1-FIPS and 13.1-NDcPP: 13.1-37.279 or later
Versions 12.1 and 13.0 are end of life and no longer receive security updates. NHS England's cyber alert describes them as likely vulnerable and advises organisations still running them to move to a supported release.
How the disclosure unfolded
The warning reached some organisations before Citrix published anything. According to BleepingComputer and SecurityWeek, the Dutch National Cyber Security Centre (NCSC-NL) sent a private pre-notification under TLP:AMBER restrictions. It said it had learned of the two flaws from a European partner CERT and that exploitation had been identified at multiple Citrix customers worldwide. On September 26, IT suppliers and security teams told some NetScaler administrators to shut their appliances down.
The same day, security firm watchTowr publicly warned that unpatched NetScaler remote code execution flaws were circulating, that they had been found during forensic investigations, and that Citrix patches were expected shortly (Help Net Security, 2026).
Citrix published the bulletin and fixed builds on September 27. CISA issued an alert and added both CVEs to the KEV catalog that day. The Canadian Centre for Cyber Security and NHS England issued their own alerts.
Citrix has not said publicly when exploitation began.
What attackers have done
Sophos and Unit 42 report the flaws being used for initial access, with post-exploitation activity including webshell deployment, credential theft and lateral movement (Sophos, 2026; Unit 42, 2026). Help Net Security reported that the webshells were unique to each appliance and that attackers ran anti-forensics commands to delete artifacts.
The scale of confirmed compromise is less clear. Cybersecurity Dive reported that there have been compromises but that confirmed cases are not widespread.
None of the advisories cited here names a threat actor. This brief does not speculate on attribution.
How many appliances are exposed
Exposure estimates vary with how they are counted. Shadowserver Foundation reported more than 20,000 exposed instances potentially at risk (Cybersecurity Dive, 2026). Palo Alto Networks said its Cortex Xpanse telemetry identified 50,277 exposed instances as of September 27 that could potentially be vulnerable (Unit 42, 2026). Both figures count internet-facing appliances, not confirmed vulnerable or compromised ones.
What affected organisations should know
Patching alone does not answer whether an appliance was compromised before the upgrade. CISA's two alerts make three points:
- Check for indicators of compromise before patching. Citrix has made indicators available through NetScaler Console and in the bulletin.
- If compromise is suspected, preserve forensic evidence before applying updates, because updating may remove forensic visibility.
- Prioritise remediation of vulnerabilities listed in the KEV catalog.
Citrix also publishes NetScaler Console guidance for identifying affected instances.
This is not the first time NetScaler flaws have prompted guidance that goes beyond patching. CISA published advisories on webshell implants through CVE-2023-3519 and on CVE-2023-4966, known as Citrix Bleed. Both covered detecting existing compromise, not only applying the fix.
What happens next
The federal deadline is Wednesday, September 30, 2026, for civilian agencies covered by CISA's KEV requirements (Tenable, 2026). Organisations outside that mandate are not bound by the date, but CISA's alert urges all users and administrators to review Citrix's advisories. Research teams including Rapid7 and watchTowr are tracking the flaws. It is not yet clear how many organisations were compromised before September 27, or when the first intrusions took place.
Sources
- Citrix (Cloud Software Group). "Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778 (CTX697096)." 2026. https://support.citrix.com/external/article/CTX697096/citrix-netscaler-adc-and-citrix-netscale.html
- CISA. "Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway." 2026. https://www.cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway
- CISA. "CISA Adds Two Known Exploited Vulnerabilities to Catalog." 2026. https://www.cisa.gov/news-events/alerts/2026/09/27/cisa-adds-two-known-exploited-vulnerabilities-catalog
- CISA. "Threat Actors Exploiting Citrix CVE-2023-3519 to Implant Webshells." 2023. https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-201a
- CISA. "Guidance for Addressing Citrix NetScaler ADC and Gateway Vulnerability CVE-2023-4966, Citrix Bleed." 2023. https://www.cisa.gov/guidance-addressing-citrix-netscaler-adc-and-gateway-vulnerability-cve-2023-4966-citrix-bleed
- Canadian Centre for Cyber Security. "AL26-024: Critical vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway." 2026. https://www.cyber.gc.ca/en/alerts-advisories/al26-024-critical-vulnerabilities-affecting-citrix-netscaler-adc-netscaler-gateway-cve-2026-88771-cve-2026-88772
- NHS England Digital. "Exploitation of Zero-Day Vulnerabilities affecting Citrix NetScaler (CC-4858)." 2026. https://digital.nhs.uk/cyber-alerts/2026/cc-4858
- NetScaler. "Identify and remediate vulnerabilities for CVE-2026-88771." 2026. https://docs.netscaler.com/en-us/netscaler-console-service/instance-advisory/remediate-vulnerabilities-cve-2026-88771
- Palo Alto Networks Unit 42. "Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild." 2026. https://unit42.paloaltonetworks.com/netscaler-zero-days-exploited/
- Sophos. "Citrix NetScaler vulnerabilities (CVE-2026-88771, CVE-2026-88772) in active exploitation." 2026. https://www.sophos.com/en-us/blog/citrix-netscaler-cve-2026-88771-cve-2026-88772-in-active-exploitation
- watchTowr. "CVE-2026-88771: Citrix NetScaler ADC and Citrix NetScaler Gateway Vulnerability." 2026. https://watchtowr.com/intelligence/citrix-netscaler-adc-citrix-netscaler-gateway-remote-code-execution-cve-2026-88771/
- watchTowr. "Citrix NetScaler Zero-Day RCE FAQ: CVE-2026-88771 and CVE-2026-88772." 2026. https://watchtowr.com/intelligence/citrix-netscaler-zero-day-vulnerabilities-faq/
- Tenable. "Citrix NetScaler Zero-Day RCE vulnerabilities: FAQ." 2026. https://www.tenable.com/blog/frequently-asked-questions-about-reported-citrix-netscaler-zero-day-vulnerabilities
- Rapid7. "Zero-Day Exploitation of Citrix NetScaler ADC and Gateway: CVE-2026-88771 and CVE-2026-88772." 2026. https://www.rapid7.com/blog/post/etr-zero-day-exploitation-of-citrix-netscaler-adc-and-gateway-cve-2026-88771-and-cve-2026-88772/
- SOCRadar. "Citrix NetScaler Zero-Days FAQ: CVE-2026-88771 & 88772." 2026. https://socradar.io/blog/citrix-netscaler-cve-2026-88771-88772/
- BleepingComputer. "Citrix confirms two NetScaler RCE zero-days exploited in attacks." 2026. https://www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/
- SecurityWeek. "Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug." 2026. https://www.securityweek.com/citrix-confirms-2-netscaler-zero-days-after-admins-pulled-the-plug/
- Help Net Security. "Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772)." 2026. https://www.helpnetsecurity.com/2026/09/28/citrix-netscaler-rce-zero-days-exploited-for-weeks-cve-2026-88771-cve-2026-88772/
- Cybersecurity Dive. "Citrix urges immediate upgrades of NetScaler amid widespread exploitation attempts." 2026. https://www.cybersecuritydive.com/news/citrix-upgrades-netscaler-exploitation/831502/
