Citrix Patches Two NetScaler Zero-Days After Attackers Breach Unmitigated Systems
Citrix patched CVE-2026-88771 and CVE-2026-88772 (CVSS 9.5) in NetScaler ADC/Gateway after active exploitation. Learn affected versions and fixed builds.
Illustrative image generated with AI
Citrix has confirmed active exploitation of two critical vulnerabilities affecting NetScaler ADC and NetScaler Gateway. The company released security updates on September 27, 2026, after attacks compromised deployments where mitigations had not been applied.
The newly identified flaws, CVE-2026-88771 and CVE-2026-88772, are each reported with a CVSS score of 9.5. Both can lead to code or command execution, although they arise from different technical weaknesses and have different configuration requirements.
Citrix has not disclosed the number of affected organizations, the identity of the attackers, or when exploitation began.
Two critical flaws with different attack conditions
CVE-2026-88771 is an improper input-validation vulnerability that can allow an unauthenticated attacker to execute arbitrary commands. It affects vulnerable NetScaler ADC and NetScaler Gateway deployments without requiring administrators to enable an additional feature.
The precise affected-version ranges, CVSS vector, and CWE classification have not been disclosed. That limits organizations’ ability to determine exposure from the CVE description alone, making installed build numbers and Citrix’s fixed-release guidance the more useful references.
CVE-2026-88772 is a memory-overflow vulnerability capable of causing remote code execution or denial of service. Unlike CVE-2026-88771, exploitation depends on Datagram Transport Layer Security, or DTLS, being enabled.
DTLS is enabled by default on NetScaler Gateway VPN virtual servers unless an administrator has explicitly disabled it. Operators should therefore verify the actual configuration rather than assuming the feature is inactive.
An earlier warning said one of the vulnerabilities could be used to inject shellcode directly into memory. It did not identify which of the two CVEs supports that technique.
Citrix’s broader security advisory also covers six other issues. Depending on the flaw, enabled features, and appliance configuration, the possible consequences across the advisory include remote code execution, denial of service, HTTP request smuggling, policy bypass, and TCP initial-sequence-number prediction under specific conditions.
Fixed builds replace updates released for earlier flaws
The affected product families are Citrix NetScaler ADC and NetScaler Gateway. Citrix has made fixes available in the following releases:
- 14.1-73.37 and later
- 13.1-64.23 and later
- Updated 14.1-FIPS, 13.1-FIPS, and 13.1-NDcPP branches
Exact fixed build numbers have not been provided for the FIPS and NDcPP branches. Customers using those editions should obtain the applicable release directly through Citrix’s update channels or support.
Previously deployed builds 14.1-73.32 and 13.1-63.21 are not sufficient. Those releases addressed an earlier authentication-bypass vulnerability, CVE-2026-19490, but do not contain fixes for CVE-2026-88771 or CVE-2026-88772.
This distinction is operationally significant because an appliance may appear current against the August issue while remaining exposed to the newly exploited zero-days.
The NetScaler 13.1 branch reached End of Maintenance on September 15, 2026. A security fix is nevertheless available, but organizations should factor the branch’s maintenance status into migration and upgrade planning rather than treating the emergency update as a long-term solution.
Private warnings preceded Citrix’s confirmation
On September 26, 2026, administrators reported that IT providers and security teams were privately advising customers to take NetScaler systems offline. In some cases, those recommendations arrived without an explanation.
Security researchers at watchTowr assessed reports of multiple unpatched NetScaler remote-code-execution flaws as credible. They later said the vulnerabilities had been identified through forensic investigations. At that stage, operators faced an unverified NetScaler zero-day threat without patches or detection details.
The Dutch National Cyber Security Centre also sent pre-notifications to organizations in the Netherlands. Information shared by a European partner CERT described two critical NetScaler zero-days that could enable remote code execution.
Citrix subsequently confirmed exploitation and released updates. The company’s statement that attacks targeted unmitigated deployments establishes that these were not merely vulnerabilities discovered during internal testing.
NetScaler appliances commonly handle VPN access, authentication, load balancing, and other network-edge functions. Compromise at that position can give an attacker access to sensitive traffic or a foothold adjacent to internal services. However, no specific post-exploitation activity has been publicly attributed to these incidents.
New zero-days are separate from the August vulnerabilities
Citrix has emphasized that the newly exploited vulnerabilities are distinct from CVE-2026-19489 and CVE-2026-19490, which were disclosed in August.
CVE-2026-19489 is classified as CWE-120. Its recorded affected-version description covers NetScaler ADC and Gateway from 14.1 through 73.32 and from 13.1 through 63.21. No CVSS score, vector, or CISA Known Exploited Vulnerabilities status is available in the supplied record.
CVE-2026-19490 has a CVSS v3 score of 9.8 and the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. It is classified as CWE-288. Listed affected versions include NetScaler Application Delivery Controller before 13.1-37.277 and NetScaler Gateway before 13.1-63.21; the accompanying description also identifies ADC and Gateway ranges from 14.1 through 73.32 and from 13.1 through 63.21.
CISA added CVE-2026-19490 to its Known Exploited Vulnerabilities catalog on September 9, 2026, with a remediation deadline of September 12, 2026, for U.S. federal agencies. The required action was to apply vendor mitigations in line with BOD 26-04 and CISA’s forensic-triage requirements. Agencies were also directed to follow applicable cloud-service guidance or discontinue use where mitigations were unavailable.
No confirmed CISA KEV status is available for CVE-2026-88771 or CVE-2026-88772.
The Citrix exposure is not isolated within recent KEV activity. CVE-2026-8452, associated with the same vendor, entered the catalog on August 26, 2026.
Patching should be paired with compromise assessment
Administrators should first identify all NetScaler ADC and NetScaler Gateway appliances, including externally accessible systems, standby nodes, and devices managed by third parties. They should then compare installed builds against the fixed releases and update to 14.1-73.37, 13.1-64.23, or the applicable corrected FIPS or NDcPP build.
For CVE-2026-88772, teams should also determine whether DTLS is enabled. Disabling the feature may change exposure to that specific vulnerability, but it does not address CVE-2026-88771 and is not a substitute for installing the updates.
Citrix is providing generic indicators of compromise through NetScaler Console. Detection is available through the hosted NetScaler Console service and through on-premises deployments using Cloud Connect, beginning with version 14.1-73.36. The telemetry channel must be enabled.
Customers will be able to initiate checks from the Security Advisory page once Citrix releases the relevant IoC detection logic. Organizations without NetScaler Console can contact Citrix Support for access and assistance.
Those scans are not conclusive. Citrix warns that the indicators do not represent every attacker technique and may miss some compromises. Because exploitation occurred before patches became available, updating an appliance removes the known vulnerability but does not establish that the system was never breached.
Organizations with exposed or potentially affected devices should preserve relevant evidence and involve experienced forensic investigators where warranted. At present, comprehensive attacker indicators and a complete account of observed post-exploitation behavior are not known.
Sources
This article is an original reworking based on the sources below.
CVEs covered in this article
- CVE-2026-19490Critical9.8Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
- CVE-2026-19489Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
- CVE-2026-88771Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated a
- CVE-2026-88772Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service




