Threat Advisories

Critical Citrix NetScaler Zero-Day vulnerabilities actively exploited CVE-2026-88771 | CVE-2026-88772

Written by Integrity360 | Sep 29, 2026, 7:12:41 AM

Citrix has released emergency security updates addressing two critical remote code execution vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting customer-managed NetScaler ADC and NetScaler Gateway appliances.

Both vulnerabilities carry a CVSS v4.0 score of 9.5 and have been exploited in the wild. Citrix states that exploitation of both vulnerabilities has been observed against unmitigated NetScaler deployments.

CVE-2026-88771 is particularly significant because it can allow an unauthenticated remote attacker to execute arbitrary commands on vulnerable appliances and applies to affected NetScaler deployments in their default configuration. No additional feature needs to be enabled.

CVE-2026-88772 is a memory-overflow vulnerability that can result in remote code execution or denial of service when DTLS is enabled. DTLS is enabled by default on VPN virtual servers, making NetScaler Gateway deployments a priority for review.

Organisations operating internet-accessible NetScaler ADC or Gateway appliances should treat this as an urgent incident-response and remediation activity, rather than a routine patching exercise.

 

Vulnerability Details

CVE

Description

Severity

Exploitation

CVE-2026-88771

Improper input validation allowing an unauthenticated remote attacker to execute arbitrary commands. Affects default configurations.

Critical – 9.5

Observed in the wild

CVE-2026-88772

Memory overflow potentially resulting in remote code execution or denial of service when DTLS is enabled.

Critical – 9.5

Observed in the wild

Citrix's security bulletin also addresses six additional vulnerabilities, CVE-2026-88773 through CVE-2026-88778, affecting NetScaler appliances under various configuration conditions.

CISA reporting indicates that both CVE-2026-88771 and CVE-2026-88772 were added to the Known Exploited Vulnerabilities catalogue on 27 September 2026, following evidence of active exploitation.

Potential impact

Successful exploitation could provide an attacker with code or command execution on a network-edge appliance.

Because NetScaler appliances commonly provide VPN access, authentication, reverse proxying and application delivery services, compromise may expose organisations to risks including:

  • Unauthorised access to the NetScaler appliance
  • Execution of attacker-controlled commands
  • Credential or secret theft
  • Persistence on perimeter infrastructure
  • Access to internal applications and networks
  • Lateral movement
  • Interception or manipulation of traffic
  • Denial of service
  • Further compromise of systems accessible through the appliance

Applying the security update addresses the vulnerable software but does not by itself establish that an appliance was not previously compromised.

 

Affected and Fixed Versions

Product / Branch

Vulnerable

Fixed Version

NetScaler ADC / Gateway 14.1

Earlier than 14.1-73.37

14.1-73.37 or later

NetScaler ADC / Gateway 13.1

Earlier than 13.1-64.23

13.1-64.23 or later

NetScaler ADC 14.1-FIPS

Earlier than 14.1-73.37 FIPS

14.1-73.37 FIPS or later

NetScaler ADC 13.1-FIPS / 13.1-NDcPP

Earlier than 13.1-37.279

13.1-37.279 or later

Citrix Secure Private Access hybrid deployments that use affected NetScaler instances should also be reviewed. Citrix-managed cloud services are updated by Citrix; the advisory primarily concerns customer-managed appliances.

Required Actions

Organisations using NetScaler ADC or NetScaler Gateway should take the following actions immediately.

1. Identify exposed appliances

Inventory all NetScaler ADC and NetScaler Gateway systems and determine:

  • Software version and build
  • Internet accessibility
  • Whether the appliance provides Gateway/VPN services
  • Whether AAA virtual servers are exposed
  • Whether DTLS is enabled
  • Whether management interfaces are externally accessible

Priority should be given to all internet-facing NetScaler Gateway, VPN and AAA services.

2. Preserve forensic evidence before upgrading

Where operationally possible, preserve evidence from exposed appliances before installing the update. Recommended evidence includes:

  • NetScaler VPX snapshot
  • Local and remote syslog data
  • NetScaler Console logs
  • Technical support bundle
  • Packet Engine core dump
  • Relevant network telemetry

3. Hunt for evidence of compromise

Review affected appliances and associated infrastructure for indicators including:

  • Unexpected or unauthorised administrative sessions
  • Unusual command execution
  • Unexpected outbound network connections
  • New or modified files
  • Unexpected configuration changes
  • Unexplained gaps or clearing of logs
  • Authentication anomalies
  • Changes to certificates, accounts or authorisation settings
  • Connections from the appliance to unusual internal systems

Citrix-provided IOC capabilities should be used where available. However, absence of known indicators should not be considered conclusive evidence that exploitation has not occurred.

4. Update affected appliances

Upgrade all vulnerable appliances to the appropriate fixed release.

For NetScaler 13.1 deployments, administrators should check the appliance before upgrading using:

show ns variable

If variables are returned, Citrix-related guidance indicates that 13.1-64.24 should be used to avoid a known reboot-loop issue associated with the earlier build.

There is currently no equivalent configuration workaround that should be treated as a substitute for installing the fixed versions.

5. Address CVE-2026-88778 separately

The same Citrix bulletin includes CVE-2026-88778, relating to predictable values from previous values.

Organisations should enable Enhanced ISN Generation as recommended by Citrix. This issue requires a configuration change and should not be considered remediated solely by upgrading the software.

6. Rotate exposed credentials and secrets where compromise is suspected

If an appliance was internet-facing while vulnerable, and particularly if compromise indicators are identified, organizations should consider rotating credentials and security material accessible to or processed by the device, including:

  • Administrative passwords
  • Service-account credentials
  • API credentials and tokens
  • Authentication secrets
  • Certificates and associated private keys where exposure cannot be ruled out

Rotation should be coordinated with the incident-response investigation to preserve evidence.

7. Reduce external exposure

Organisations should additionally:

  • Remove NetScaler management interfaces from direct internet exposure
  • Restrict administrative access to trusted management networks
  • Forward appliance logs to a centralised SIEM or logging platform
  • Monitor outbound communication originating from NetScaler appliances
  • Review access controls between perimeter appliances and internal networks

Incident response considerations

Organisations should consider an internet-facing vulnerable appliance to have been potentially exposed during the zero-day window.

If suspicious activity is identified, affected organizations should initiate their incident-response process and investigate beyond the appliance itself. Particular attention should be given to:

  • Credential theft
  • Persistence
  • Lateral movement
  • Access to identity infrastructure
  • Connections to internal management services
  • Access to applications proxied by the NetScaler
  • Subsequent use of credentials handled by the appliance

Do not assume that patching removes attacker persistence or access established before remediation. Updating an appliance will not remove attacker access where persistence has already been established elsewhere in the compromised environment.

Exposure Context

Based on Cortex Xpanse telemetry as of 27 September 2026, more than 50,000 internet-exposed NetScaler instances were potentially vulnerable to the vulnerabilities.

Given the widespread deployment of NetScaler at enterprise network perimeters, active exploitation, unauthenticated attack path and availability of vendor fixes, organisations should prioritise remediation accordingly.

Recommended Priority

Priority 1 – Immediate

Internet-facing NetScaler ADC/Gateway appliances running affected builds, particularly systems providing:

  • VPN / NetScaler Gateway services
  • AAA services
  • External application delivery
  • DTLS-enabled services

Priority 2 – Urgent

Affected internally accessible appliances and appliances not directly exposed to the internet.

All vulnerable systems should ultimately be upgraded to a fixed build.

If you are worried about any of the threats outlined in this bulletin or need help in determining what steps you should take to protect yourself from the most material threats facing your organisation, please contact your account manager, or alternatively get in touch to find out how you can protect your organisation.