Yaamlabs

Vulnerabilities

Two NetScaler zero-days exploited: patch and check today

Citrix NetScaler ADC and Gateway flaws CVE-2026-88771 and CVE-2026-88772 (CVSS 9.5) are under attack. Fixed builds, what to check and what to rotate.

Attackers are exploiting two remote code execution flaws in Citrix NetScaler ADC and NetScaler Gateway, and they started before any fix existed. Citrix confirmed them on September 27 as CVE-2026-88771 and CVE-2026-88772, both rated 9.5 on CVSS v4.0, and shipped fixed builds the same day. CISA added both to its Known Exploited Vulnerabilities (KEV) catalog on September 27 and gave US federal agencies until September 30 to act.

If you run a customer-managed NetScaler on 14.1 before 14.1-73.37 or 13.1 before 13.1-64.23, you are affected. CVE-2026-88771 needs no login and works on the default configuration, so exposure alone is enough. The August builds that fixed earlier NetScaler flaws (14.1-73.32 and 13.1-63.21) are still vulnerable. Citrix-managed cloud services are updated by Citrix.

How it works

A NetScaler sits at the edge of the network. It terminates VPN and remote access sessions, load-balances traffic to internal applications and handles user authentication, so it has to parse requests from anyone on the internet before it knows who they are. Both flaws live in that pre-authentication parsing.

CVE-2026-88771, CVSS 9.5 (CWE-20, improper input validation). Citrix says an unauthenticated attacker can send input the appliance fails to validate and run arbitrary commands on it. It affects every deployment on a vulnerable build, including the default configuration; no extra feature has to be switched on. Citrix has not published which request or field is involved.

CVE-2026-88772, CVSS 9.5 (CWE-119, memory overflow). This one needs DTLS enabled. DTLS (Datagram TLS) is TLS carried over UDP, which the Gateway uses to speed up VPN traffic, and it is on by default on VPN virtual servers. Citrix describes a memory overflow that can crash the appliance or give the attacker code execution, but has not said which input triggers it. The Dutch National Cyber Security Centre (NCSC-NL), in a pre-notification that circulated before the bulletin, said one of the flaws let attackers place shellcode directly into memory.

Code running on the appliance itself is worse than a breach of one server behind it. The NetScaler holds TLS private keys, session tokens for logged-in users and the credentials it uses for LDAP or RADIUS authentication, and it can reach internal networks that the internet cannot.

The same bulletin, CTX697096, fixes six more flaws: CVE-2026-88773 to CVE-2026-88778, rated 7.0 to 9.3. None of them is reported as exploited. Some early reporting put CVE-2026-88778 against this attack campaign, but Citrix lists it as a separate TCP initial sequence number prediction flaw (CVSS 8.8). The exploited pair is CVE-2026-88771 and CVE-2026-88772, and Citrix, CISA and watchTowr all agree on that.

What attackers are doing

The first public signs appeared on September 26, when NetScaler administrators posted on Reddit that suppliers and security teams were telling them to shut their appliances down. NCSC-NL had sent a pre-notification to Dutch organisations, based on information from a European partner CERT, about two flaws that could each lead to remote code execution. watchTowr said the same day that the reports of in-the-wild exploitation were credible. Citrix published fixes the next day.

Citrix says it has seen exploitation of both flaws on unmitigated appliances, and CISA says threat actors are exploiting them globally. Nobody has published attribution, a victim count or the date exploitation began. With no start date, any appliance that was reachable before you patched has to be treated as possibly compromised, which is also NCSC-NL's advice.

This is the third NetScaler flaw to reach the KEV catalog in two months: CVE-2026-8452, a heap overflow in SAML signature handling, was listed in August, and the authentication bypass CVE-2026-19490 in September. All three are reachable before login, on a device whose job is to face the internet, and each needed an emergency upgrade on short notice.

What to do

Citrix lists no workaround for CVE-2026-88771, so patching is the only real fix. Work in this order:

  1. Preserve evidence first. Before upgrading, collect logs, a VM snapshot where you can, a support bundle and any core dumps. An upgrade and reboot can erase what an attacker left in memory, and CISA asks for this forensic triage before patching.
  2. Run Citrix's indicator scan. NetScaler Console 14.1-73.36 or later has an indicators of compromise (IOC) scan on its Security Advisory page, which needs the telemetry channel enabled. Without Console, ask Citrix Support for the indicators. Citrix warns the indicators do not cover every technique, so a clean result does not clear an appliance.
  3. Upgrade to a fixed build: 14.1-73.37 or later, 13.1-64.23 or later, 14.1-73.37 FIPS, or 13.1-37.279 for FIPS and NDcPP. Upgrade every node in a high availability (HA) pair or cluster.
  4. If you cannot upgrade today, take internet-facing appliances offline, as many admins did over the weekend. Turning DTLS off on VPN virtual servers (set vpn vserver VSERVER_NAME -dtls OFF) removes the precondition for CVE-2026-88772, at some cost to VPN performance. It does nothing for CVE-2026-88771.
  5. Fix CVE-2026-88778 separately, because its fix is a setting and not just a build. Check it with show ns tcpparam | grep "Enhanced ISN Generation" and enable it.
  6. Rotate after patching if the appliance was exposed on a vulnerable build. Replace TLS certificates and private keys on the appliance, change the LDAP and RADIUS bind passwords it uses, reset the default nsroot account and other admin passwords, and end all active sessions so stolen session tokens stop working. Citrix's standard commands from earlier NetScaler advisories are kill aaa session -all, kill icaconnection -all, kill rdp connection -all, kill pcoipConnection -all and clear lb persistentSessions.
  7. Keep management off the internet. The NSIP (the appliance's own management address) and any SNIP (subnet IP, the address it uses to talk to backend servers) with management access enabled should answer only to an internal admin network.

The upgrade also changes a SAML default: an appliance with samlRejectUnsignedAssertion set to OFF switches to the secure setting, so your identity provider must sign its SAML assertions. Check that before the upgrade window, or single sign-on may fail after it.

If you find a compromise, rebuild the appliance on a fixed build from a clean configuration instead of cleaning it in place, then review connections from its SNIP addresses to internal hosts for the whole period it was exposed. Anything other than its usual backend servers, LDAP and RADIUS is worth a closer look.

Plan for the next one

Three exploited NetScaler flaws since August means planning for a fourth. Write down now how you would take the Gateway offline for a day, who approves it, and how remote staff would work while it is down. Teams that had this ready could act on the first warnings on Saturday, a day before Citrix published a fix.

Knowing which edge appliances you run, and on which builds, is where our attack surface management work starts, and a network penetration test checks whether management interfaces can be reached from places they should not be. Open the chat and Yaali, our AI agent, will pass your question to the engineer who would do the work.


Sources: Citrix bulletin CTX697096, CISA alert, CISA KEV catalog, watchTowr FAQ, watchTowr on CVE-2026-88771, BleepingComputer, The Hacker News, Security Affairs, Cyber Kendra, watchTowr Labs on CVE-2026-8452, CERT-EU on NetScaler session cleanup.

Back to the blog, or read this post on the full site.