CVE / NVD / KEV
Vendor advisories
Citrix disclosed and patched two critical zero-day vulnerabilities in customer-managed NetScaler ADC and NetScaler Gateway appliances on September 27, 2026. Citrix confirmed observed exploitation of both flaws, CVE-2026-88771 and CVE-2026-88772, on unmitigated NetScaler deployments. CISA added both vulnerabilities to its Known Exploited Vulnerabilities Catalog the same day and reported receiving partner intelligence and incident reports confirming active exploitation globally.
The immediate concern is exposure at the network perimeter. NetScaler appliances can provide remote-access VPN, application-delivery, and authentication services. Compromise of a vulnerable appliance could therefore provide an attacker with a valuable foothold. Customer-managed, internet-facing NetScaler deployments running affected versions should be treated as emergency remediation and compromise-assessment priorities.
Two critical vulnerabilities, both exploited
Citrix's advisory CTX697096 addresses eight NetScaler vulnerabilities. Citrix has confirmed observed exploitation specifically for the following two critical issues:
- CVE-2026-88771 (CVSS v4.0 9.5): affects all NetScaler ADC and Gateway deployments, including default configurations, and allows unauthenticated execution of arbitrary commands.
- CVE-2026-88772 (CVSS v4.0 9.5): requires DTLS to be enabled, which is the default on VPN virtual servers unless explicitly disabled, and allows remote code execution or denial of service.
CVE-2026-88771 is an improper-input-validation vulnerability classified as CWE-20. Citrix states that it affects all NetScaler ADC and Gateway deployments, including appliances using the default configuration. No additional feature or setting is required for the documented precondition to be met.
CVE-2026-88772 is a memory-overflow vulnerability classified as CWE-119. Its documented precondition is DTLS being enabled. Citrix states that DTLS is enabled by default on VPN virtual servers unless it is explicitly disabled. Disabling DTLS removes the documented precondition for CVE-2026-88772, but it does not address CVE-2026-88771.
Scope of affected deployments
The Citrix bulletin applies to customer-managed NetScaler ADC and NetScaler Gateway deployments. Secure Private Access Hybrid environments using NetScaler instances are also affected and require upgrades. Citrix-managed cloud services and Citrix-managed Adaptive Authentication are updated by Citrix.
Affected supported versions include:
- NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
- NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
- NetScaler ADC FIPS 14.1 before 14.1-73.37 FIPS
- NetScaler ADC FIPS and NDcPP 13.1 before 13.1-37.279
Citrix recommends upgrading to the applicable fixed build, or a later release in the same supported branch:
- 14.1-73.37 for NetScaler ADC and Gateway 14.1
- 13.1-64.23 for NetScaler ADC and Gateway 13.1
- 14.1-73.37 FIPS for NetScaler ADC FIPS 14.1
- 13.1.37.279 for NetScaler ADC FIPS and NDcPP 13.1
See Citrix advisory CTX697096 for the applicable builds and deployment guidance.
Why patching alone may not be enough
The Canadian Centre for Cyber Security warns that successful exploitation could result in appliance compromise, unauthorized access to applications and services, credential theft, lateral movement, and further compromise of internal systems. These are potential post-compromise outcomes, not evidence that every vulnerable organization has experienced them.
CISA advises organizations, where possible, to check for indications of compromise before patching. It notes that applying updates can reduce forensic visibility and recommends preserving relevant evidence before making changes when compromise is suspected.
No authoritative public reporting reviewed for this article identifies a threat actor, malware family, victim list, or confirmed targeting in Saudi Arabia, the UAE, or Oman. The absence of public reporting is not evidence of no regional impact. CISA reports global active exploitation, while the Canadian Cyber Centre says activity has been observed across multiple Citrix customer environments worldwide, with the full extent still unknown.
Response priorities for NetScaler administrators
Identify and prioritize exposed appliances
Inventory every customer-managed NetScaler ADC, Gateway, and Secure Private Access Hybrid instance. Prioritize systems reachable from the internet, particularly Gateway, VPN, AAA, and authentication-facing virtual servers.
CVE-2026-88771 affects all NetScaler ADC and Gateway deployments regardless of enabled features. For CVE-2026-88772, validate whether DTLS is enabled. For a VPN virtual server, DTLS is enabled by default unless the configuration explicitly includes `-dtls OFF`.
Preserve evidence before making changes, where feasible
For appliances exposed before the September 27, 2026, fixes, preserve forensic evidence before shutdown, rebooting, patching, rebuilding, or configuration changes when operationally feasible. The Canadian Cyber Centre recommends preserving or collecting:
- Appliance, remote-syslog, and NetScaler Console logs
- Support bundles and other diagnostic information
- Running-process and active-network-connection information
- Startup scripts, scheduled tasks, web application directories, crash-dump locations, and configuration files
- Suspicious files and evidence of unauthorized modification
- Supporting firewall, DNS, authentication, endpoint, and network telemetry
Investigate unexpected outbound connections, unusual administrative access, and suspicious activity on systems connected to the appliance. If compromise is suspected, follow Citrix and incident-response procedures to isolate affected appliances, assess credential exposure, invalidate sessions, reset credentials, replace certificates where justified, and rebuild compromised systems from trusted software and known-good configurations. See the Canadian Cyber Centre advisory AL26-024 for its investigation and evidence-preservation guidance.
Apply fixed builds without delay
After evidence preservation and immediately necessary triage, deploy the Citrix fixed build appropriate to the appliance's supported branch. Do not treat disabling DTLS as complete remediation: it may remove the documented precondition for CVE-2026-88772, but CVE-2026-88771 affects all NetScaler ADC and Gateway deployments.
Administrators planning to update to 13.1-64.23 should account for a Citrix-documented operational issue that can cause cyclic rebooting in a specific configuration. Citrix advises running `show ns variable`; if the command returns configured variables, administrators should plan an upgrade to 13.1-64.24 to avoid the issue. See Citrix's security update guidance.
Hunt, monitor, and retain telemetry
Citrix has made generic indicators of compromise available through NetScaler Console and states that customers without NetScaler Console can request applicable indicators through Citrix Support. Citrix cautions that these indicators do not cover all attacker techniques and may fail to identify actual compromises. An IOC scan is therefore a triage aid, not evidence that an appliance is clean.
Forward NetScaler logs to an external logging or SIEM platform and use NetScaler Console File Integrity Monitoring where available. These measures can support centralized detection, preserve evidence, and help identify unexpected changes to monitored files during investigation and remediation. Citrix provides further detail in its security update guidance.
Defender takeaway
CVE-2026-88771 and CVE-2026-88772 are actively exploited critical vulnerabilities affecting customer-managed NetScaler perimeter infrastructure. Citrix and CISA have confirmed exploitation, and CISA has added both CVEs to the KEV Catalog. The appropriate response is rapid installation of the applicable fixed build combined with a focused compromise assessment of internet-exposed appliances that were vulnerable before remediation.
For a structured approach to vulnerability management, monitoring, and incident readiness, see our guide to Managed Cybersecurity for GCC SMBs.
Cyberactics Security Team
Managed Security Services
We help SMBs across Jordan, Saudi Arabia, Oman, and the UAE respond to active threats and validate exposure across their environments.
Talk to an incident response engineer
Book a 30-minute call and we'll walk through exposure assessment, patch validation, and post-remediation investigation for your environment.



