Citrix NetScaler Zero-Days FAQ: CVE-2026-88771 & 88772
Citrix has released emergency security updates for eight vulnerabilities affecting customer-managed NetScaler ADC and NetScaler Gateway appliances, including two critical zero-days already exploited in the wild.
The actively exploited flaws, CVE-2026-88771 and CVE-2026-88772, can independently lead to Remote Code Execution (RCE) and carry CVSS v4.0 scores of 9.5. CVE-2026-88771 affects vulnerable deployments without requiring an additional feature, while CVE-2026-88772 requires DTLS, which Citrix says is enabled by default on VPN virtual servers.
CISA added both vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on September 27, citing reports and partner intelligence confirming global exploitation. The agency set a September 30, 2026 remediation due date for federal agencies covered by its requirements and urged organizations to check for compromise and preserve forensic evidence before updating where possible.
The following FAQ explains what changed over the weekend, which systems are affected, what Citrix and CISA have confirmed, and what defenders should do now.
1. What Happened With Citrix NetScaler Over the Weekend?
Before Citrix publicly disclosed the vulnerabilities, reports emerged that NetScaler administrators were receiving private warnings from security providers, CERTs, and other organizations advising urgent action.
Some administrators reported being told to temporarily shut down or isolate NetScaler appliances even though no public Citrix bulletin or patch was available at the time. Security firm watchTowr subsequently said it had credible information that multiple NetScaler RCE zero-days were being exploited in the wild.
On September 27, 2026, Citrix published its CTX697096 security bulletin, disclosing eight vulnerabilities and confirming that exploitation of CVE-2026-88771 and CVE-2026-88772 had been observed against unmitigated NetScaler deployments.
2. Was the Original Weekend Warning Real?
Yes. The central concern behind the warnings was subsequently confirmed.
Citrix confirmed two critical vulnerabilities capable of remote code execution and said exploitation of both had already been observed. CISA later described them as zero-day vulnerabilities and said threat actors were exploiting them globally.
That does not mean every claim circulating before disclosure was accurate. Early reports were necessarily incomplete, and details that were not later supported by Citrix, CISA, or other authoritative sources should still be treated cautiously.
3. Which NetScaler Products and Versions Are Affected?
Citrix identifies these affected supported branches and fixed builds:
| Product | Affected | Fixed Build |
|---|---|---|
| NetScaler ADC / Gateway 14.1 | Before 14.1-73.37 | 14.1-73.37 or later |
| NetScaler ADC / Gateway 13.1 | Before 13.1-64.23 | 13.1-64.23 or later |
| NetScaler ADC 14.1-FIPS | Before 14.1-73.37 FIPS | 14.1-73.37 FIPS or later |
| NetScaler ADC 13.1-FIPS / NDcPP | Before 13.1-37.279 | 13.1-37.279 or later |
Secure Private Access Hybrid deployments using customer-managed NetScaler instances are also affected and require those appliances to be upgraded.
The bulletin applies to customer-managed NetScaler ADC and NetScaler Gateway appliances. Citrix says Cloud Software Group is handling updates for Citrix-managed cloud services and Citrix-managed Adaptive Authentication.
4. How Many Vulnerabilities Did Citrix Disclose?
Citrix disclosed eight vulnerabilities in CTX697096. They have different impacts and configuration requirements.
| CVE | CVSS v4.0 | Description |
|---|---|---|
| CVE-2026-88771 | 9.5 | Unauthenticated arbitrary command execution caused by improper input validation |
| CVE-2026-88772 | 9.5 | Memory overflow leading to RCE or DoS when DTLS is enabled |
| CVE-2026-88773 | 9.3 | HTTP request smuggling under affected HTTP configurations |
| CVE-2026-88774 | 7.0 | Policy bypass involving HTTP URL-based policy expressions |
| CVE-2026-88775 | 8.8 | Memory overflow affecting Gateway or AAA configurations |
| CVE-2026-88776 | 8.8 | Memory overflow involving Oracle load-balancing virtual servers |
| CVE-2026-88777 | 8.8 | Memory overflow affecting certain non-HTTP Layer 7 configurations |
| CVE-2026-88778 | 8.8 | TCP Initial Sequence Number predictability under affected TCP configurations |
Only CVE-2026-88771 and CVE-2026-88772 are currently identified by Citrix as having observed exploitation.
CVE-2026-88778 also requires separate attention: Citrix directs affected customers to enable Enhanced ISN Generation, meaning upgrading alone is not the complete remediation for that specific flaw.
5. Which Vulnerabilities Require the Most Immediate Attention?
CVE-2026-88771 and CVE-2026-88772 require immediate attention because both are critical RCE vulnerabilities with confirmed exploitation.
This changes the response from ordinary vulnerability management to vulnerability management plus potential incident response. Organizations that operated exposed vulnerable appliances should consider whether exploitation occurred before the patches were installed.
CVE-2026-88773 is also rated Critical at 9.3, but Citrix has not stated that it is being exploited in the wild.
6. What Is CVE-2026-88771?
CVE-2026-88771 is an improper input validation vulnerability, classified as CWE-20.
Citrix says an unauthenticated attacker can exploit the flaw remotely to execute arbitrary commands on an affected NetScaler system. It carries a CVSS v4.0 score of 9.5.
Its CVSS vector also reflects an attack requirement, but Citrix does not publicly provide the full exploit chain or trigger in its bulletin.

Details of CVE-2026-88771 (SOCRadar Vulnerability Intelligence)
7. Does CVE-2026-88771 Require Authentication?
No. Citrix describes CVE-2026-88771 as allowing an unauthenticated attacker to execute arbitrary commands. No valid NetScaler account is required.
That makes exposed edge appliances particularly important to identify and remediate.
8. Does CVE-2026-88771 Require a Special Configuration?
No additional feature or optional configuration is required.
Citrix states that all affected-version NetScaler ADC and NetScaler Gateway deployments meet the vulnerability precondition, including systems using the default configuration.
This should not be interpreted as meaning fixed versions are vulnerable. The statement applies to appliances running one of the affected builds.
9. What Is CVE-2026-88772?
CVE-2026-88772 is a memory overflow vulnerability, classified as CWE-119.
It can lead to remote code execution or denial of service when DTLS is enabled on an affected NetScaler ADC or Gateway appliance. Citrix also assigned it a CVSS v4.0 score of 9.5.
Unlike CVE-2026-88771, this flaw has a specific configuration precondition.

Details of CVE-2026-88772 (SOCRadar Vulnerability Intelligence)
10. What Is DTLS, and Does Disabling It Solve the Problem?
DTLS, or Datagram Transport Layer Security, provides TLS-like security for datagram-based communications.
It matters here because CVE-2026-88772 requires DTLS. Citrix says DTLS is enabled by default on VPN virtual servers unless it has been explicitly disabled. Other virtual servers may also meet the precondition if they are configured to use DTLS.
Administrators can therefore review their NetScaler configuration to determine whether DTLS is active.
Disabling DTLS can remove the stated precondition for CVE-2026-88772, but it does not address CVE-2026-88771. It should not be treated as a replacement for upgrading to a fixed build.
11. Which Vulnerabilities Have Confirmed Active Exploitation?
Citrix has explicitly confirmed observed exploitation of:
- CVE-2026-88771
- CVE-2026-88772
Citrix has not said that all eight vulnerabilities in the September bulletin are being exploited.
CISA added the same two CVEs to KEV and said it had received reports and partner threat intelligence confirming that threat actors were actively exploiting them globally.
12. Are CVE-2026-88771 and CVE-2026-88772 Zero-Days?
Yes. CISA explicitly refers to both vulnerabilities as critical zero-day vulnerabilities, and Citrix confirmed that exploitation had occurred against unmitigated systems when the fixes were disclosed.
In practical terms, attackers were exploiting the vulnerabilities before customers had publicly available patches.
13. Which Threat Actor Is Behind the Attacks?
No reliable public attribution has been established.
Citrix has not named a ransomware group, criminal organization, or state-sponsored actor responsible for exploiting either vulnerability. CISA similarly refers broadly to threat actors and global exploitation without identifying a specific group.
Previous ransomware and state-sponsored campaigns involving other NetScaler vulnerabilities should not be used as attribution for these attacks.
14. What Has CISA Said About the NetScaler Zero-Days?
CISA issued an alert on the exploited NetScaler vulnerabilities on September 27 and added CVE-2026-88771 and CVE-2026-88772 to its KEV catalog.
The agency says both vulnerabilities can independently enable RCE and that reports and partner intelligence confirm exploitation globally. CISA also encourages organizations to check for indications of compromise before patching where possible and to preserve forensic evidence if compromise is suspected.
Both KEV entries carry a September 30, 2026 due date for federal agencies subject to CISA’s remediation requirements.
Private-sector organizations are not automatically subject to that federal deadline, but the three-day remediation window is a strong indicator of the urgency CISA assigns to these actively exploited flaws.
15. If We Recently Patched NetScaler, Are We Protected?
Not necessarily. The relevant question is the exact running build, not whether the appliance recently received an update.
For example, an appliance patched for an earlier NetScaler vulnerability may still be vulnerable to CVE-2026-88771 and CVE-2026-88772 if it has not reached the builds listed in CTX697096.
Organizations should verify the currently running release against Citrix’s fixed NetScaler builds in CTX697096 rather than assuming a recent maintenance update is sufficient.
16. Is Installing the Update Enough?
The update is necessary, but it may not be the end of the response.
Because exploitation occurred before public patches were available, an internet-facing appliance could have been compromised while still vulnerable. Installing the fixed build prevents exploitation of the patched flaws going forward, but it does not automatically undo earlier attacker activity.
CISA therefore recommends checking for compromise before patching where practical and warns that applying an update can reduce forensic visibility.
For exposed systems, organizations should treat remediation and compromise assessment as separate tasks.
17. Should Patched Systems Still Be Investigated?
Yes, when they were exposed while running a vulnerable build.
The Dutch NCSC has advised organizations to account for possible previous compromise on systems that were exposed before security updates were installed. It also recommends preserving relevant logging and memory evidence where practical before remediation.
The level of investigation should reflect exposure, business importance, available evidence, and the organization’s incident-response process.
18. Should Teams Collect a Memory Dump Before Upgrading?
For systems where compromise is suspected, memory preservation can be valuable, but it should be handled as part of an incident-response process rather than as a blanket requirement for every appliance.
Citrix’s compromise-response guidance recommends preserving evidence and, for suspected compromised appliances, provides instructions for generating a Packet Engine core file, which can capture memory useful for later analysis. Citrix notes that this process causes a warm restart.
CISA’s broader guidance is to preserve forensic evidence before applying updates when compromise is suspected because remediation may reduce visibility.
Evidence collection should therefore be balanced against the need to close an actively exploited attack surface quickly.
19. Does Citrix Provide Indicators of Compromise?
Yes. CISA says Citrix has made Indicators of Compromise available through NetScaler Console to support compromise assessment.
NetScaler Console’s IoC detection feature can run compromise-detection scans against managed appliances. Citrix notes that the feature requires product usage telemetry and that its detection logic can be updated as new indicators become available.
Organizations unable to use the available Console functionality can work through Citrix Support as appropriate.
20. Does a Clean Citrix IoC Scan Prove the Appliance Was Not Compromised?
No. Citrix explicitly warns that its IoC information does not cover every technique, tactic, procedure, or attacker infrastructure component. Threat actors can also change their behavior and infrastructure over time.
A result showing no detected compromise is useful evidence, but it should not be treated as definitive proof that an exposed appliance was never exploited.
Organizations with a reasonable suspicion of compromise should use broader forensic investigation rather than relying on a single indicator scan.
21. What Other Evidence Should Security Teams Preserve?
For potentially compromised NetScaler appliances, relevant evidence can include:
- Local and externally forwarded NetScaler logs.
- NetScaler Console data.
- SIEM and perimeter telemetry.
- Authentication and VPN activity.
- Appliance configuration information.
- Virtual-machine snapshots for VPX systems.
- Technical support bundles.
- Packet Engine core files where appropriate.
- Network connections to systems behind the appliance.
Citrix specifically advises preserving remote syslog and NetScaler Console logs in addition to local logs when a compromise is suspected. Its guidance also recommends documenting system time, timezone, and NTP settings before isolation.
NetScaler Console’s File Integrity Monitoring can provide another signal by identifying modified or newly added files, although Citrix warns that such monitoring cannot detect every attacker technique.
22. Is There a Public Proof of Concept?
As of September 28, 2026, there are no credible, independently verified fully weaponized public exploit for CVE-2026-88771 or CVE-2026-88772.
Public scanners, version checks, detection material, or tools that identify DTLS exposure should not automatically be described as proof-of-concept exploits. A scanner that determines whether a target appears vulnerable is different from code that actually triggers the underlying command-execution or memory-corruption flaw.
Current public vulnerability tracking similarly does not identify established public exploit material for the two CVEs.
That distinction does not reduce the urgency: Citrix and CISA have already confirmed real-world exploitation, meaning attackers did not need a public PoC to weaponize the flaws.
23. Should Organizations Shut Down Their NetScaler Appliances?
Before patches became public, some organizations were reportedly advised to shut down or isolate vulnerable appliances because exploitation was suspected and there was no available fix.
The situation has changed now that fixed builds are available.
The primary response is to preserve evidence where necessary, assess for compromise, and upgrade to the applicable fixed release. If immediate remediation is impossible, reducing external exposure or temporarily isolating affected systems may be appropriate depending on operational requirements.
A full shutdown can have significant availability consequences and should not be treated as the default response for every environment.
24. Are Citrix-Managed Cloud Customers Affected?
CTX697096 specifically applies to customer-managed NetScaler ADC and NetScaler Gateway deployments.
Citrix says Cloud Software Group is applying necessary software updates to Citrix-managed cloud services and Citrix-managed Adaptive Authentication.
Organizations should still inventory their environments carefully because they may operate customer-managed NetScaler appliances alongside Citrix-managed services.
25. Are Secure Private Access Hybrid Deployments Affected?
Yes, where they use affected customer-managed NetScaler instances.
Citrix specifically states that Secure Private Access Hybrid deployments using NetScaler instances are affected and that those appliances must be upgraded to recommended builds.
26. How Can SOCRadar Help Track NetScaler Exposure?
With active exploitation already confirmed, organizations need to know both which vulnerabilities matter and where affected technology is externally exposed.
SOCRadar can support that process through:
- Attack Surface Management: Helps identify externally visible NetScaler ADC and Gateway assets and prioritize internet-facing systems for investigation and remediation.
- Cyber Threat Intelligence: Tracks CVE severity, exploitation developments, KEV status, remediation information, and changes in public vulnerability intelligence.

SOCRadar’s Vulnerability Intelligence, Cyber Threat Intelligence module
Combining external asset visibility with vulnerability intelligence can help security teams identify exposed NetScaler systems quickly while patching and compromise assessment proceed.
27. What Should Organizations Do Right Now?
Start by identifying every customer-managed NetScaler ADC and Gateway instance and verifying its exact running build.
Upgrade affected systems to the fixed versions in Citrix’s CTX697096 security bulletin:
- 14.1: 14.1-73.37 or later
- 13.1: 13.1-64.23 or later
- 14.1-FIPS: 14.1-73.37 FIPS or later
- 13.1-FIPS / NDcPP: 13.1-37.279 or later
Prioritize internet-facing VPN, Gateway, AAA, and other externally reachable appliances, but do not ignore internally reachable deployments. CVE-2026-88771 does not require an optional feature or special configuration on an affected build.
For appliances that were exposed before remediation, determine whether a compromise assessment is necessary. Where practical and appropriate, preserve relevant forensic evidence before disruptive changes, then review Citrix IoCs, logs, NetScaler Console data, network telemetry, authentication activity, and file-integrity information.
If compromise is identified or strongly suspected, Citrix recommends isolating the appliance, investigating connected systems, revoking potentially exposed credentials and secrets, and rebuilding or restoring from a known-good state according to the appliance type and the organization’s incident-response requirements.
For CVE-2026-88772, confirm whether DTLS was enabled, but do not treat disabling DTLS as complete remediation because CVE-2026-88771 remains independently exploitable.
CISA’s KEV due date is September 30, 2026 for covered federal agencies. Regardless of whether that deadline formally applies to an organization, confirmed exploitation means teams should not wait for public exploit code, attacker attribution, or additional technical disclosure before acting.

