Citrix has released emergency security updates addressing two critical remote code execution vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting customer-managed NetScaler ADC and NetScaler Gateway appliances.
Both vulnerabilities carry a CVSS v4.0 score of 9.5 and have been exploited in the wild. Citrix states that exploitation of both vulnerabilities has been observed against unmitigated NetScaler deployments.
CVE-2026-88771 is particularly significant because it can allow an unauthenticated remote attacker to execute arbitrary commands on vulnerable appliances and applies to affected NetScaler deployments in their default configuration. No additional feature needs to be enabled.
CVE-2026-88772 is a memory-overflow vulnerability that can result in remote code execution or denial of service when DTLS is enabled. DTLS is enabled by default on VPN virtual servers, making NetScaler Gateway deployments a priority for review.
Organisations operating internet-accessible NetScaler ADC or Gateway appliances should treat this as an urgent incident-response and remediation activity, rather than a routine patching exercise.
|
CVE |
Description |
Severity |
Exploitation |
|
CVE-2026-88771 |
Improper input validation allowing an unauthenticated remote attacker to execute arbitrary commands. Affects default configurations. |
Critical – 9.5 |
Observed in the wild |
|
CVE-2026-88772 |
Memory overflow potentially resulting in remote code execution or denial of service when DTLS is enabled. |
Critical – 9.5 |
Observed in the wild |
Citrix's security bulletin also addresses six additional vulnerabilities, CVE-2026-88773 through CVE-2026-88778, affecting NetScaler appliances under various configuration conditions.
CISA reporting indicates that both CVE-2026-88771 and CVE-2026-88772 were added to the Known Exploited Vulnerabilities catalogue on 27 September 2026, following evidence of active exploitation.
Successful exploitation could provide an attacker with code or command execution on a network-edge appliance.
Because NetScaler appliances commonly provide VPN access, authentication, reverse proxying and application delivery services, compromise may expose organisations to risks including:
Applying the security update addresses the vulnerable software but does not by itself establish that an appliance was not previously compromised.
Affected and Fixed Versions
|
Product / Branch |
Vulnerable |
Fixed Version |
|
NetScaler ADC / Gateway 14.1 |
Earlier than 14.1-73.37 |
14.1-73.37 or later |
|
NetScaler ADC / Gateway 13.1 |
Earlier than 13.1-64.23 |
13.1-64.23 or later |
|
NetScaler ADC 14.1-FIPS |
Earlier than 14.1-73.37 FIPS |
14.1-73.37 FIPS or later |
|
NetScaler ADC 13.1-FIPS / 13.1-NDcPP |
Earlier than 13.1-37.279 |
13.1-37.279 or later |
Citrix Secure Private Access hybrid deployments that use affected NetScaler instances should also be reviewed. Citrix-managed cloud services are updated by Citrix; the advisory primarily concerns customer-managed appliances.
Organisations using NetScaler ADC or NetScaler Gateway should take the following actions immediately.
1. Identify exposed appliances
Inventory all NetScaler ADC and NetScaler Gateway systems and determine:
Priority should be given to all internet-facing NetScaler Gateway, VPN and AAA services.
2. Preserve forensic evidence before upgrading
Where operationally possible, preserve evidence from exposed appliances before installing the update. Recommended evidence includes:
3. Hunt for evidence of compromise
Review affected appliances and associated infrastructure for indicators including:
Citrix-provided IOC capabilities should be used where available. However, absence of known indicators should not be considered conclusive evidence that exploitation has not occurred.
4. Update affected appliances
Upgrade all vulnerable appliances to the appropriate fixed release.
For NetScaler 13.1 deployments, administrators should check the appliance before upgrading using:
show ns variable
If variables are returned, Citrix-related guidance indicates that 13.1-64.24 should be used to avoid a known reboot-loop issue associated with the earlier build.
There is currently no equivalent configuration workaround that should be treated as a substitute for installing the fixed versions.
5. Address CVE-2026-88778 separately
The same Citrix bulletin includes CVE-2026-88778, relating to predictable values from previous values.
Organisations should enable Enhanced ISN Generation as recommended by Citrix. This issue requires a configuration change and should not be considered remediated solely by upgrading the software.
6. Rotate exposed credentials and secrets where compromise is suspected
If an appliance was internet-facing while vulnerable, and particularly if compromise indicators are identified, organizations should consider rotating credentials and security material accessible to or processed by the device, including:
Rotation should be coordinated with the incident-response investigation to preserve evidence.
7. Reduce external exposure
Organisations should additionally:
Organisations should consider an internet-facing vulnerable appliance to have been potentially exposed during the zero-day window.
If suspicious activity is identified, affected organizations should initiate their incident-response process and investigate beyond the appliance itself. Particular attention should be given to:
Do not assume that patching removes attacker persistence or access established before remediation. Updating an appliance will not remove attacker access where persistence has already been established elsewhere in the compromised environment.
Based on Cortex Xpanse telemetry as of 27 September 2026, more than 50,000 internet-exposed NetScaler instances were potentially vulnerable to the vulnerabilities.
Given the widespread deployment of NetScaler at enterprise network perimeters, active exploitation, unauthenticated attack path and availability of vendor fixes, organisations should prioritise remediation accordingly.
Priority 1 – Immediate
Internet-facing NetScaler ADC/Gateway appliances running affected builds, particularly systems providing:
Priority 2 – Urgent
Affected internally accessible appliances and appliances not directly exposed to the internet.
All vulnerable systems should ultimately be upgraded to a fixed build.
If you are worried about any of the threats outlined in this bulletin or need help in determining what steps you should take to protect yourself from the most material threats facing your organisation, please contact your account manager, or alternatively get in touch to find out how you can protect your organisation.