Citrix Fixes Two Exploited Zero-Days in NetScaler
Citrix published fixes for CVE-2026-88771 and CVE-2026-88772, critical remote execution vulnerabilities in NetScaler ADC and Gateway that were exploited pre-patch.

On Sunday (27), Citrix released security bulletin CTX697096, addressing two critical vulnerabilities in NetScaler ADC and NetScaler Gateway that had already been exploited before a patch was available. The vulnerabilities, CVE-2026-88771 and CVE-2026-88772, received a score of 9.5 on the CVSS 4.0 scale and allow for remote code execution. According to the bulletin, the company observed exploitation of both in unmitigated installations. The CISA, the U.S. cybersecurity agency, issued an alert the same day stating that threat actors are exploiting the vulnerabilities globally, adding both to the KEV catalog, which mandates U.S. federal civilian agencies to patch within a fixed timeframe.
The bulletin covers eight CVEs, from 88771 to 88778. Only the first two are noted as being exploited.
What Each Vulnerability Opens
CVE-2026-88771 is the most severe for those running the device with default settings. It involves inadequate input validation, allowing an unauthenticated attacker to execute arbitrary commands on the appliance. According to an analysis by watchTowr, a security firm that publicized the case, it affects any installation of the ADC or Gateway on a vulnerable version, without requiring a specific feature to be activated.
CVE-2026-88772 is a memory overflow that leads to remote execution or denial of service when DTLS is enabled. DTLS is enabled by default on VPN virtual servers, which places most Gateway installations in a state of vulnerability, unless the administrator has disabled it.
The patched versions, according to Citrix's bulletin, are 14.1-73.37 and 13.1-64.23, as well as 14.1-73.37 FIPS and 13.1-37.279 for the FIPS and NDcPP lines.
A Weekend Between the Alert and the Patch
The sequence of events is of interest to those managing risk. Last week, administrators reported on the r/Citrix forum recommendations to power down the devices, attributed to a pre-notification from the NCSC-NL, the Dutch national cybersecurity center, distributed under the TLP:AMBER+STRICT designation. On Friday (26), watchTowr publicly stated that unpatched remote execution vulnerabilities were being exploited and had been identified during forensic investigations. Over the weekend, managed service providers and MDR vendors began advising clients to take their NetScalers offline. The patch was only issued on Sunday.
This period exposes an operational dilemma. The NetScaler resides at the network's edge, concentrating VPN, remote access, load balancing, and user authentication. Powering it down disconnects the entire remote work of a company; keeping it online without a patch leaves a door that bypasses authentication. According to reports about the Dutch pre-notification, the NCSC-NL chose to issue a warning before the patch precisely because updating the NetScaler typically causes downtime, and preparing the maintenance window in advance shortens exposure time.
Second Incident on the Same Product in September
This is not the first alert this month. In early September, CVE-2026-19490, a critical authentication bypass vulnerability in the same NetScaler, moved from patching to exploitation in attacks within a few weeks, according to Rapid7 and BleepingComputer. The history weighs heavily: in 2023, Citrix Bleed (CVE-2023-4966) became a gateway for ransomware campaigns targeting banks, law firms, and public agencies, including the U.S. operation of the Chinese bank ICBC.
The context shifts based on the market. In the United States, the KEV catalog turns the alert into a legal obligation for the federal government and, in practice, a deadline reference for suppliers and banks following the CISA. In the Netherlands, the NCSC-NL notified organizations under confidentiality before public disclosure, allowing for the preparation of maintenance windows before the patch existed; those outside this list learned about the issue through forums and watchTowr. For operations that rely on third-party remote access, such as shared service centers and integrators serving clients across continents, the client’s NetScaler also becomes a problem for the provider, as it is the gateway for teams to enter.
The Question After the Patch
Since exploitation began before a patch was available, updating the device closes the door but does not inform who passed through it. watchTowr stated that the vulnerabilities were found during forensic investigations, meaning in environments where someone had already entered. For the CISO, the indicator that matters to the board this week shifts from the percentage of updated appliances to what happened in each of them between the first exploitation and Sunday. This is a more costly question to answer, and the only one that determines whether the incident has concluded.
Sources
- support.citrix.comhttps://support.citrix.com/external/article/CTX697096
- cisa.govhttps://www.cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway
- watchtowr.comhttps://watchtowr.com/intelligence/citrix-netscaler-zero-day-vulnerabilities-faq/
- bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/
- thehackernews.comhttps://thehackernews.com/2026/09/warning-two-unpatched-citrix-netscaler.html