
Executive Summary
Citrix has confirmed that two NetScaler ADC and NetScaler Gateway zero-day vulnerabilities — CVE-2026-88771 and CVE-2026-88772 — are being exploited in the wild.
Both are rated CVSS 9.5, and CISA has added them to the Known Exploited Vulnerabilities (KEV) Catalog.
The vulnerabilities can lead to remote code execution, making exposed NetScaler appliances a high-priority security concern. Citrix has released fixed builds, while security teams should also assess potentially exposed appliances for signs of prior compromise.
The key concern is no longer just vulnerability exposure, but whether an attacker already gained access before the fixes became available.
What happened?
The issue came to light in late September 2026, with security researchers reporting exploitation of vulnerable NetScaler appliances.
Citrix subsequently released its security bulletin on September 27 and confirmed that both vulnerabilities had been exploited against unmitigated NetScaler deployments.
That changes the situation completely.
We are no longer dealing with a theoretical vulnerability.
There is confirmed exploitation.
CVE-2026-88771
CVE-2026-88771 is an improper input validation vulnerability that can allow an unauthenticated remote attacker to execute arbitrary commands on the NetScaler appliance.
One important detail is that the vulnerability affects the default configuration.
An additional feature does not need to be enabled for the vulnerability to be relevant.
CVE-2026-88772
CVE-2026-88772 is a memory-overflow vulnerability that can result in remote code execution or denial of service.
It requires DTLS to be enabled.
The concern is that DTLS is enabled by default for VPN virtual servers, making the vulnerability particularly relevant to NetScaler Gateway deployments used for remote access.
Why NetScaler makes this different
NetScaler commonly sits directly at the network edge and handles:
- VPN and remote access
- Authentication
- Application delivery
- Load balancing
- Traffic management
A successful compromise therefore puts a security-sensitive perimeter appliance under attacker control.
That makes the compromise-assessment piece particularly important.
The patch is available
Citrix has released fixed builds for the affected versions.
NetScaler ADC / Gateway 14.1
Fixed: 14.1-73.37 and later
NetScaler ADC / Gateway 13.1
Fixed: 13.1-64.23 and later
For FIPS and NDcPP deployments, Citrix has separate fixed builds, including 13.1-37.279.
Organizations should verify the exact running build against Citrix’s security advisory.
One important detail is that appliances previously updated for CVE-2026-19490 may still be vulnerable to these new issues.
IOC situation
This is where I would be careful.
At the time of writing, public reporting does not provide a complete and reliable list of attacker IP addresses, domains, file hashes or other traditional IOCs that can be treated as a comprehensive detection set.
Citrix has made an IOC-scanning capability available through NetScaler Console Security Advisory, which can help organizations identify indicators associated with the exploitation.
But an IOC scan should not be treated as proof that an appliance was never compromised.
For defenders, the available detection approach should include:
- Run the NetScaler Console Security Advisory IOC scan
- Review NetScaler authentication and access logs
- Review VPN and AAA activity
- Look for unusual administrative activity
- Check for unexpected configuration changes
- Investigate unexpected processes or files
- Review outbound connections from the appliance
- Preserve relevant support bundles and logs
- Correlate NetScaler activity with SIEM telemetry
I would also avoid treating random IP addresses or hashes circulating online as confirmed IOCs unless they can be tied back to a trusted investigation.
What security teams should look for
The first step is understanding the actual exposure.
NetScaler inventory
Don’t rely only on the CMDB.
Check:
- Internet-facing IP ranges
- External DNS
- VPN infrastructure
- Load balancers
- Remote-access infrastructure
- Cloud deployments
- Disaster-recovery environments
- Business-unit owned appliances
Build and configuration
Verify the exact NetScaler build and determine whether DTLS is enabled, particularly on VPN virtual servers.
Signs of compromise
Review:
- Authentication activity
- Administrative actions
- Configuration changes
- Unexpected processes or files
- Outbound connections
- VPN and AAA activity
- Relevant SIEM alerts
Correlate the activity across:
NetScaler → Firewall → VPN → Identity → Endpoint → SIEM
If compromise is confirmed or strongly suspected, review credentials, certificates, tokens and other secrets that may have been accessible from the appliance.
Other vulnerabilities in the same bulletin
Citrix’s September 27 security bulletin covers more than the two exploited zero-days.
It also addresses:
- CVE-2026-88773 — HTTP request smuggling
- CVE-2026-88774 — security-policy related vulnerability
- CVE-2026-88775 — memory overflow
- CVE-2026-88776 — memory overflow
- CVE-2026-88777 — memory overflow
- CVE-2026-88778 — predictable TCP initial sequence numbers
The exploitation confirmation currently applies to CVE-2026-88771 and CVE-2026-88772.
The bigger takeaway
This incident is less about another high-CVSS vulnerability and more about the combination of:
Internet-facing appliance + zero-day + active exploitation + remote code execution + CISA KEV
For security teams, the immediate focus should be understanding exposure and potential compromise, alongside the vendor’s remediation requirements.
PK


