On September 27, 2026, Citrix published emergency security bulletin CTX697096 disclosing eight vulnerabilities in NetScaler ADC and NetScaler Gateway. Two of them, CVE-2026-88771 and CVE-2026-88772, are critical remote code execution flaws, both rated CVSS 9.5, that attackers had already been exploiting as zero-days before any patch existed. CISA added both to its Known Exploited Vulnerabilities catalog the same day. If your NetScaler appliance is running an affected build, upgrade to a fixed release immediately, and then hunt for signs of compromise, because patching alone will not remove backdoors an attacker may already have planted.
The two zero-days, in plain terms
Both flaws need only network access to the appliance. No credentials, no prior foothold inside the organization. That is what makes this disclosure one of the most serious edge-device security events of the year, and the latest in a rough stretch for network appliances after the F5 BIG-IP zero-day and the Cisco SD-WAN zero-day.
CVE-2026-88771: unauthenticated RCE on the default configuration
CVE-2026-88771 is an improper input validation flaw in the HTTP processing stack of NetScaler ADC and Gateway. Citrix rates the attack complexity as low, meaning reliable remote code execution is achievable against virtually any vulnerable appliance on the internet. No special features need to be enabled, and it works against the default configuration.
Security researchers at watchTowr published a root-cause analysis of this flaw. By their account, attacker-controlled request data gets written into the appliance logs, and the ns_monuploadd_err.pl error-handling script later interpolates that data into a shell command. The injected command then runs with root privileges when the script executes, which watchTowr reports can be up to 24 hours after the malicious request. In effect, the attacker poisons the logs and waits for the appliance to execute its own log data as commands.
CVE-2026-88772: RCE through DTLS, before any login
CVE-2026-88772 is a memory overflow in the Datagram Transport Layer Security (DTLS) implementation inside NetScaler’s Packet Processing Engine (NSPPE). During the pre-authentication cryptographic handshake, malformed or fragmented DTLS record headers corrupt heap memory, which can redirect execution to attacker-controlled shellcode running with root privileges on the underlying FreeBSD system. All of this happens before any session or credential check.
This flaw requires DTLS to be enabled. The catch: DTLS is enabled by default on VPN virtual servers, so most NetScaler Gateway deployments meet the precondition unless an administrator explicitly disabled it. Citrix rates the attack complexity for this one higher, meaning reliable remote code execution takes more effort, but a denial of service is much easier to trigger.
It is not just two bugs: all eight CVEs in the bulletin
The emergency Citrix bulletin covers eight CVEs in total, and the fixed releases address all of them, so patching only the two zero-days is not enough:
- CVE-2026-88771, remote code execution, CVSS 9.5, exploited as a zero-day
- CVE-2026-88772, RCE or denial of service, CVSS 9.5, exploited as a zero-day
- CVE-2026-88773, HTTP request smuggling, CVSS 9.3
- CVE-2026-88774, feature policy bypass, CVSS 7.0
- CVE-2026-88775, memory overflow / denial of service, CVSS 8.8
- CVE-2026-88776, memory overflow / denial of service, CVSS 8.8
- CVE-2026-88777, memory overflow / denial of service, CVSS 8.8
- CVE-2026-88778, TCP ISN prediction, CVSS 8.8
Only the two critical RCE flaws were reported as exploited in the wild; the other six depend on specific configurations. Still, if you are upgrading, you get all eight fixes together, and there is no reason to run a partial patch.
Which versions are affected
Citrix lists these vulnerable ranges and fixed builds for customer-managed appliances:
- NetScaler ADC / Gateway 14.1: affected before build 14.1-73.37; upgrade to 14.1-73.37 or later
- NetScaler ADC / Gateway 13.1: affected before build 13.1-64.23; upgrade to 13.1-64.23 or later
- FIPS and NDcPP editions: Citrix specifies separate fixed builds, including 14.1-73.37 FIPS and 13.1.37.279 respectively
Two things to watch: appliances on 12.1 or 13.0 get no fix at all, so those need to be replaced rather than patched. And NetScaler Console may temporarily flag a patched 13.1-64.23 appliance as vulnerable; Citrix says that flag is temporary and clears on its own.
Unlike some earlier NetScaler vulnerabilities that required the appliance to be configured as a Gateway or AAA virtual server, CVE-2026-88771 affects all deployments regardless of configuration. The Dutch National Cyber Security Centre (NCSC-NL) highlighted this specifically: there is no configuration check that makes this one someone else’s problem.
Why patching alone is not enough
Citrix confirmed in its advisory that exploits of both zero-days on unmitigated deployments were observed before the bulletin went out. The flaws were weaponized for weeks before patches existed, and mass exploitation is now underway rather than being a future risk. This is the same hard lesson enterprise teams learned from earlier edge-device campaigns, and it is the reason this incident is being compared to the Cisco SD-WAN Manager compromise pattern.
The uncomfortable reality: an appliance that was compromised before you patched it stays compromised after you patch it. Attackers who gain root on a network appliance typically plant persistence mechanisms such as web shells or modified binaries that survive an upgrade. Treat every internet-facing NetScaler on an affected build as potentially compromised until you have evidence otherwise. That means checking appliance logs and configurations for unexpected files, accounts, scheduled tasks, and outbound connections, and comparing against known-good baselines. If you find anything you cannot explain, isolate the appliance and bring in experienced forensic investigators before you rebuild from a known-good image. Citrix has echoed that recommendation, and it is the right call for an appliance that sits at the edge of your network with full visibility into your traffic.
What to do right now
- Inventory your NetScaler appliances and check the build number. Match every ADC and Gateway against the affected ranges above, including FIPS and NDcPP editions.
- Upgrade affected appliances to the fixed releases as soon as possible. Do not assume an older security update covered these flaws; it did not. There is no workaround, only the upgrade.
- Check whether DTLS is enabled on your VPN virtual servers to understand your exposure to CVE-2026-88772, using the configuration patterns Citrix provides in the bulletin.
- Hunt for signs of prior compromise on every internet-facing appliance on an affected build, even the ones you have already patched.
- Rotate credentials, keys, and certificates that passed through any appliance you cannot clear, and rebuild from a known-good image if indicators of compromise turn up.
Frequently asked questions
What is the Citrix NetScaler zero-day?
It refers to two critical vulnerabilities, CVE-2026-88771 and CVE-2026-88772, in Citrix NetScaler ADC and Gateway that attackers exploited before patches existed. Citrix disclosed them in emergency bulletin CTX697096 on September 27, 2026, and CISA added both to its Known Exploited Vulnerabilities catalog the same day.
Which NetScaler versions are vulnerable to CVE-2026-88771 and CVE-2026-88772?
NetScaler ADC and Gateway 14.1 builds before 14.1-73.37 and 13.1 builds before 13.1-64.23, with separate fixed builds for FIPS and NDcPP editions. Versions 12.1 and 13.0 will not receive fixes and must be replaced.
Can the Citrix NetScaler zero-day be exploited without a password?
Yes. Both CVE-2026-88771 and CVE-2026-88772 are unauthenticated remote code execution flaws. CVE-2026-88771 works against the default configuration with low attack complexity; CVE-2026-88772 requires DTLS to be enabled, which is the default on VPN virtual servers.
Were the Citrix NetScaler zero-days exploited before the patch?
Yes. Citrix confirmed that exploits of both vulnerabilities on unmitigated deployments had been observed, and multiple national CERTs issued alerts. This is why security teams are treating every internet-facing NetScaler on an affected build as potentially compromised.
I already patched my NetScaler. Am I safe now?
Not necessarily. Patching closes the vulnerabilities, but it does not remove persistence an attacker may have planted before you patched. Hunt for signs of compromise across your appliances, rotate credentials and certificates that passed through them, and investigate anything unexpected before closing the incident.

1 thought on “Citrix NetScaler Zero-Day (CVE-2026-88771, CVE-2026-88772): What Happened and What to Do Right Now”