Skip to content
TrustList
News

Two exploited Citrix NetScaler flaws get fixes and a 30 September federal deadline

Editorial

By TrustList Editorial

Citrix confirmed on 27 September that CVE-2026-88771 and CVE-2026-88772 are being exploited on NetScaler ADC and Gateway. CISA set a 30 September deadline and asks for forensic triage. Customer-managed appliances need the fixed builds now.

About Two exploited Citrix NetScaler flaws get fixes and a 30 September federal deadline

Two exploited Citrix NetScaler flaws get fixes and a 30 September federal deadline

27 September 2026 — Citrix published security bulletin CTX697096 on Sunday 27 September 2026, covering eight vulnerabilities in NetScaler ADC and NetScaler Gateway. Two of them, CVE-2026-88771 and CVE-2026-88772, are already being used in attacks: in Citrix's words, "exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed." The same day, CISA added both to its Known Exploited Vulnerabilities catalogue with a due date of 30 September for US federal agencies, flagged them for forensic triage, and issued an alert saying partner threat intelligence confirms they are being exploited globally.

What the two flaws do

  • CVE-2026-88771 (CVSS v4.0 9.5): improper input validation that lets an unauthenticated attacker run arbitrary commands. Citrix says it affects all NetScaler ADC and Gateway deployments, including the default configuration, with no extra feature needed.
  • CVE-2026-88772 (CVSS v4.0 9.5): a memory overflow leading to remote code execution or denial of service, where DTLS is enabled. DTLS is on by default on VPN virtual servers unless explicitly switched off.

The bulletin also fixes CVE-2026-88773, an HTTP request smuggling flaw rated 9.3, and five further flaws rated 7.0 to 8.8. One of them, CVE-2026-88778 (TCP sequence-number prediction), needs a configuration change, enhanced ISN generation, as well as the update.

Fixed versions

Citrix lists 14.1-73.37 and later, 13.1-64.23 and later, 14.1-73.37 FIPS, and 13.1-37.279 for 13.1-FIPS and 13.1-NDcPP. Secure Private Access hybrid deployments that use NetScaler instances are affected too. The bulletin covers customer-managed appliances only; Citrix says it is upgrading the cloud services and Adaptive Authentication it manages itself.

Before the bulletin

BleepingComputer and SecurityWeek report that over the weekend administrators were told by IT suppliers, CERTs and managed security providers to take NetScalers offline, some of it traced to a pre-notification from the Dutch National Cyber Security Centre. That notice is known only from copies posted online; the press reports it said exploitation had been seen at multiple Citrix customers worldwide.

Who is affected

Any organisation running its own NetScaler ADC or Gateway, usually as the internet-facing front door for remote access, VPN or published applications. Because these appliances sit at the network edge, a compromise can give an attacker a foothold inside without touching a laptop first. Managed service providers that run NetScalers for clients are in scope.

What to do

  • List every customer-managed NetScaler ADC and Gateway, including those behind Secure Private Access hybrid deployments, and note the build.
  • Check for signs of compromise first. CISA advises preserving forensic evidence before updating, because an update can remove it; Citrix provides indicators of compromise through NetScaler Console and a guide for suspected compromise.
  • Install the fixed build for your release line, then apply the enhanced ISN setting for CVE-2026-88778.
  • If you cannot patch at once, restrict exposure of the management and gateway interfaces and plan the downtime now; the federal deadline is Wednesday 30 September.
  • If a supplier runs NetScalers for you, ask in writing when they were patched and whether a compromise check was done first.

Sources