Two exploited Citrix NetScaler flaws get fixes and a 30 September federal deadline
EditorialBy TrustList Editorial
Citrix confirmed on 27 September that CVE-2026-88771 and CVE-2026-88772 are being exploited on NetScaler ADC and Gateway. CISA set a 30 September deadline and asks for forensic triage. Customer-managed appliances need the fixed builds now.
About Two exploited Citrix NetScaler flaws get fixes and a 30 September federal deadline
Two exploited Citrix NetScaler flaws get fixes and a 30 September federal deadline
27 September 2026 — Citrix published security bulletin CTX697096 on Sunday 27 September 2026, covering eight vulnerabilities in NetScaler ADC and NetScaler Gateway. Two of them, CVE-2026-88771 and CVE-2026-88772, are already being used in attacks: in Citrix's words, "exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed." The same day, CISA added both to its Known Exploited Vulnerabilities catalogue with a due date of 30 September for US federal agencies, flagged them for forensic triage, and issued an alert saying partner threat intelligence confirms they are being exploited globally.
What the two flaws do
- CVE-2026-88771 (CVSS v4.0 9.5): improper input validation that lets an unauthenticated attacker run arbitrary commands. Citrix says it affects all NetScaler ADC and Gateway deployments, including the default configuration, with no extra feature needed.
- CVE-2026-88772 (CVSS v4.0 9.5): a memory overflow leading to remote code execution or denial of service, where DTLS is enabled. DTLS is on by default on VPN virtual servers unless explicitly switched off.
The bulletin also fixes CVE-2026-88773, an HTTP request smuggling flaw rated 9.3, and five further flaws rated 7.0 to 8.8. One of them, CVE-2026-88778 (TCP sequence-number prediction), needs a configuration change, enhanced ISN generation, as well as the update.
Fixed versions
Citrix lists 14.1-73.37 and later, 13.1-64.23 and later, 14.1-73.37 FIPS, and 13.1-37.279 for 13.1-FIPS and 13.1-NDcPP. Secure Private Access hybrid deployments that use NetScaler instances are affected too. The bulletin covers customer-managed appliances only; Citrix says it is upgrading the cloud services and Adaptive Authentication it manages itself.
Before the bulletin
BleepingComputer and SecurityWeek report that over the weekend administrators were told by IT suppliers, CERTs and managed security providers to take NetScalers offline, some of it traced to a pre-notification from the Dutch National Cyber Security Centre. That notice is known only from copies posted online; the press reports it said exploitation had been seen at multiple Citrix customers worldwide.
Who is affected
Any organisation running its own NetScaler ADC or Gateway, usually as the internet-facing front door for remote access, VPN or published applications. Because these appliances sit at the network edge, a compromise can give an attacker a foothold inside without touching a laptop first. Managed service providers that run NetScalers for clients are in scope.
What to do
- List every customer-managed NetScaler ADC and Gateway, including those behind Secure Private Access hybrid deployments, and note the build.
- Check for signs of compromise first. CISA advises preserving forensic evidence before updating, because an update can remove it; Citrix provides indicators of compromise through NetScaler Console and a guide for suspected compromise.
- Install the fixed build for your release line, then apply the enhanced ISN setting for CVE-2026-88778.
- If you cannot patch at once, restrict exposure of the management and gateway interfaces and plan the downtime now; the federal deadline is Wednesday 30 September.
- If a supplier runs NetScalers for you, ask in writing when they were patched and whether a compromise check was done first.
Sources
- Citrix: NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778 (CTX697096) — 27 September 2026
- CISA: Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway — 27 September 2026
- CISA: Known Exploited Vulnerabilities Catalog (CVE-2026-88771, CVE-2026-88772 added 27 September, due 30 September) — 27 September 2026
- BleepingComputer: Citrix confirms two NetScaler RCE zero-days exploited in attacks — 27 September 2026
- SecurityWeek: Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug — 28 September 2026
- The Register: Certainties in life: Death, taxes, and critical Citrix vulns under attack — 28 September 2026
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.