What happened
Citrix security bulletin CTX697096, published September 27, 2026, covers eight CVEs in NetScaler ADC and NetScaler Gateway, CVE-2026-88771 through CVE-2026-88778. Two are critical remote code execution flaws, and Citrix states that "exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed."
- CVE-2026-88771 (CVSS v4.0 9.5, CWE-20): improper input validation that "can allow an unauthenticated attacker to execute arbitrary commands." Citrix lists the precondition as all NetScaler ADC and Gateway deployments in the default configuration, with no additional feature required.
- CVE-2026-88772 (CVSS v4.0 9.5, CWE-119): a memory overflow leading to remote code execution or denial of service when DTLS is enabled. Citrix notes DTLS is enabled by default on VPN virtual servers, so most Gateway deployments meet the condition.
The other six include an HTTP request smuggling flaw (CVE-2026-88773, CVSS 9.3), a policy bypass (CVE-2026-88774, 7.0), three memory overflows in specific features (CVE-2026-88775 to 88777, 8.8 each) and a TCP initial sequence number prediction issue (CVE-2026-88778, 8.8) that needs a configuration change in addition to the upgrade. Only the first two are listed as exploited.
CISA added CVE-2026-88771 and CVE-2026-88772 to the KEV catalog on September 27. Help Net Security reports a federal due date of September 30, and that the attacks had been unfolding for weeks before disclosure, with the Dutch NCSC among those warning organizations; attackers were reported to plant webshells and run anti-forensics commands to delete artefacts. A researcher quoted there assessed the activity as probably nation-state aligned and espionage driven; that attribution is unconfirmed, and neither Citrix nor Unit 42 has named an actor. Unit 42 reports that Cortex Xpanse saw 50,277 exposed instances that could potentially be vulnerable as of September 27.
Why it matters if you run public infrastructure
This is the second time this month NetScaler has landed on the KEV catalog, after CVE-2026-19490 on September 9, and it is worse: no special configuration, no credentials, and exploitation that started before anyone could patch. An organization that upgraded to 14.1-73.32 for the earlier bug in September is still vulnerable to these two. And because the attacks predate the fix, a patched appliance may already carry a webshell. Upgrading closes the door; it does not tell you whether someone is inside.
What to check this week
- Find every NetScaler you expose, including secondary Gateways, test
appliances and ones in other business units. Signs from outside are the
/vpn/index.htmland/logon/LogonPoint/paths andNSC_cookies. - Check each build with
show ns version. Anything below 14.1-73.37 or 13.1-64.23 (13.1-37.279 for FIPS/NDcPP) is affected by CVE-2026-88771 regardless of configuration. - Upgrade outside the normal cycle. Rapid7 advises treating this as an emergency. If you cannot upgrade today, restrict access to the appliance and follow Unit 42's advice to isolate it. Update, October 7: a new Citrix bulletin (October 3) raised the minimum builds to 14.1-73.41 and 13.1-64.28 for an exploited SAML flaw that crashes appliances already on 14.1-73.37; see our follow-up.
- Hunt for compromise before and after patching. Preserve snapshots, logs and core dumps first, then look for webshells, unexpected administrative sessions and unexpected outbound connections from the appliance.
- Apply the TCP configuration change for CVE-2026-88778 as described in the bulletin; the upgrade alone does not cover it.
How Attack Surface Scan covers this
Attack Surface Scan recognizes NetScaler Gateway and ADC login pages on hosts under your verified
domains, including hosts discovered through certificate transparency logs, and alerts when a new
one appears. NetScaler does not reveal its build to anonymous visitors, so we cannot confirm whether
an appliance has 14.1-73.37 or 13.1-64.23. Instead, NetScaler is one of the edge products for which
we raise potential matches against KEV-listed CVEs, capped at medium severity and
tagged potential, with instructions for checking the real build. KEV data refreshes
nightly, so new listings like these reach existing findings on the next scan. We do not send exploit
traffic and cannot detect a webshell. See Vulnerability matching.
Sources
- Citrix: NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-88771 to CVE-2026-88778 (CTX697096)
- CISA: CISA Adds Two Known Exploited Vulnerabilities to Catalog (September 27, 2026)
- Unit 42: Threat Brief, NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild
- Rapid7: Zero-Day Exploitation of Citrix NetScaler ADC and Gateway, CVE-2026-88771 and CVE-2026-88772
- Help Net Security: Citrix NetScaler RCE zero-days exploited globally for weeks