SecPod

Learn Search

Search across all Learn content

← Back to Security Research

Citrix Sounds the Alarm: Two Critical NetScaler Zero-Days Actively Exploited

Sep 28, 2026By Bapanapalli Prem Sai Siddhik

Summary

Citrix has published security updates for NetScaler ADC and NetScaler Gateway in bulletin CTX697096. Two critical issues—CVE-2026-88771 and CVE-2026-88772—can lead to remote code execution. Citrix states that exploits of both vulnerabilities on unmitigated NetScaler deployments have been observed and strongly urges affected customers to install the relevant updated versions as soon as possible.

The same bulletin also covers additional vulnerabilities: CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778. Descriptions and preconditions for those issues are in the official advisory.

Vulnerability Details

CVE ID CVSS Score Type
CVE-2026-88771 9.5 CWE-20: Improper Input Validation
CVE-2026-88772 9.5 CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer

Technical Information

Critical Zero-Day Unauthenticated No User Interaction Actively Exploited RCE

CVE-2026-88771 — Remote Code Execution due to Improper Input Validation

Citrix describes this as a remote code execution vulnerability caused by improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands.

The stated precondition is all NetScaler ADC and NetScaler Gateway deployments, including default configuration. No additional feature is required for a deployment to be affected.

Critical Zero-Day No User Interaction Actively Exploited RCE

CVE-2026-88772 — Memory Overflow Leading to Remote Code Execution or Denial of Service

Citrix describes this as a memory overflow vulnerability leading to remote code execution or denial of service.

The precondition is DTLS configuration enabled on NetScaler ADC or NetScaler Gateway. Citrix states that DTLS is enabled by default on VPN virtual servers. A NetScaler Gateway is vulnerable if DTLS is not explicitly disabled; other virtual servers are vulnerable if they are configured with type DTLS.

Impact

  • CVE-2026-88771
    An unauthenticated attacker can execute arbitrary commands on affected NetScaler ADC and NetScaler Gateway deployments, including those running a default configuration.
  • CVE-2026-88772
    When DTLS is enabled, the vulnerability can lead to remote code execution or denial of service.

Citrix reports that exploits of both vulnerabilities on unmitigated NetScaler deployments have been observed.

Affected and Fixed Versions

Per the Citrix bulletin, the following supported versions are affected:

  • Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 before 14.1-73.37
  • Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 before 13.1-64.23
  • Citrix NetScaler ADC FIPS before 14.1-73.37 FIPS
  • Citrix NetScaler ADC FIPS and NDcPP before 13.1-37.279

Secure Private Access Hybrid deployments using NetScaler instances are also affected. Those NetScaler instances should be upgraded to the recommended builds.

Recommended fixed builds:

  • Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later releases
  • Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
  • Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
  • Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.279 and later releases of 13.1-FIPS and 13.1-NDcPP

The bulletin applies only to customer-managed Citrix NetScaler ADC and Citrix NetScaler Gateway. Cloud Software Group upgrades Citrix-managed cloud services and Citrix-managed Adaptive Authentication with the necessary software updates.

MITRE ATT&CK Mapping

Technique ID Technique Name Tactic
T1190 Exploit Public-Facing Application Initial Access
T1499 Endpoint Denial of Service Impact

Mitigation and Recommendations

Cloud Software Group strongly urges affected customers of NetScaler ADC and NetScaler Gateway to install the relevant updated versions as soon as possible.

  • Upgrade customer-managed appliances to a fixed build listed above.
  • Upgrade NetScaler instances used in Secure Private Access Hybrid deployments to the recommended builds.
  • For CVE-2026-88772, determine whether DTLS is enabled—including the default state on VPN virtual servers—when assessing exposure.
  • Citrix also provides Indicators of Compromise through NetScaler Console to support initial assessment. Customers who do not use NetScaler Console should contact Citrix Support to request access to the applicable generic IoCs. Citrix notes that IoC information may not cover all techniques and may fail to identify actual compromises.

Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed. Install the fixed builds as soon as possible. Full configuration and product guidance is in CTX697096.

Instantly Fix Risks with Saner Patch Management

Saner patch management is a continuous, automated, and integrated solution that helps you quickly remediate risks, including critical network infrastructure updates. It supports Windows, Linux, macOS, and 550+ third-party applications.

You can stage patches in a safe testing environment before production deployment and roll back if needed.

Experience the fastest and most accurate patching software here.

Featured Posts

Open CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials
CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials

CVE Research

CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials

Sep 25, 2026

Open Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions
Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions

CVE Research

Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions

Two MikroTik RouterOS CVEs entered CISA KEV seven days after production fixes. Dated reporting places SSH-chain exploitation involving CVE-2026-86060 at least one calendar day before those releases; no comparable start date is established for CVE-2026-67277.

Sep 25, 2026

Open Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch
Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch

CVE Research

Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch

Four vulnerabilities added to CISA’s KEV catalog on September 9, 2026 show widely different timelines between public disclosure and formal exploitation-based prioritization, ranging from one day to 239 days.

Sep 24, 2026

Open TA412/APT31: Mapping Threat Actor Patterns to CVE Exploitation Chains

TA412/APT31: Mapping Threat Actor Patterns to CVE Exploitation Chains

CVE Research

TA412/APT31: Mapping Threat Actor Patterns to CVE Exploitation Chains

A chronological look at how a long-running China-nexus espionage cluster evolved from server-side exploitation to a chained Chrome/Windows zero-day kit — and what that shift signals.

Sep 24, 2026