On 27 September 2026 Citrix published bulletin CTX697096, fixing eight vulnerabilities in NetScaler ADC and NetScaler Gateway. Two of them, CVE-2026-88771 and CVE-2026-88772, carry a CVSS 4.0 score of 9.5 and had been exploited before the fixes existed. Citrix says it has observed exploitation against unmitigated deployments, and CISA added both flaws to its Known Exploited Vulnerabilities (KEV) catalogue the same day. There is no published workaround. That combination changes what patching means: upgrading closes the door, but it does not tell you whether someone has already walked through it.
Two bugs, both reachable without an account
According to watchTowr, a security firm that published a detailed FAQ, CVE-2026-88771 is an improper input validation flaw that allows unauthenticated command execution in the default configuration. CVE-2026-88772 is a memory overflow that can lead to remote code execution or denial of service when DTLS is enabled, which Citrix says is the default for VPN virtual servers. BleepingComputer reports the same two descriptions. Exploitation needs only network access to the appliance. watchTowr carries a caveat on its own page: it is a vendor that promotes related products, and readers are told to check details against the Citrix bulletin, NVD and CISA entries.
The same bulletin fixed six more flaws, CVE-2026-88773 to CVE-2026-88778. watchTowr lists 88773, an HTTP request smuggling bug rated 9.3, as not known to be exploited. It lists 88778, a predictable-value issue rated 8.8, as fixed by enabling Enhanced ISN Generation rather than by upgrading alone, so an administrator who upgrades and stops there leaves that one open.
The timeline: four days from warning to deadline
- Before 26 September: BleepingComputer reports that the Dutch NCSC-NL warned about two NetScaler zero-days that let attackers place shellcode directly into memory, and that national agencies and others privately urged customers to shut down appliances. The report says “reportedly”; we have not seen the NCSC-NL notice.
- 26 September (Saturday): watchTowr publicly warned of exploitation of unpatched NetScaler flaws and notified its clients the same day, before CVE identifiers existed.
- 27 September (Sunday): Citrix released fixes and confirmed exploitation; CISA added both CVEs to KEV.
- 30 September (Wednesday): the deadline for US federal civilian agencies, set under Binding Operational Directive 26-04, per BleepingComputer.
From public warning to federal deadline is four days; from KEV listing to deadline is three. The window between first exploitation and the warning is unknown, and that matters more than any of the other dates.
Why a VPN gateway is the target
A NetScaler Gateway sits on the internet-facing edge and terminates VPN and authentication traffic for the networks behind it. That position makes it attractive for reasons beyond the initial foothold. It handles credentials and session secrets, it often holds certificates, and it is reachable from anywhere. A pre-authentication code execution bug on such a device skips the usual step of stealing a password first. This is general mechanism rather than anything specific to the sources, but it is the reason edge appliances recur in the KEV catalogue.
NetScaler has a long record here. watchTowr lists CVE-2023-4966, known as CitrixBleed, added to KEV on 18 October 2023, and CVE-2025-5777, CitrixBleed 2, added on 10 July 2025. A separate NetScaler flaw, CVE-2026-19490, went into KEV on 9 September 2026; watchTowr says it is unrelated and that patching for it does not protect against these two.
Scale is not known. Shadowserver tracks more than 23,000 internet-exposed IP addresses fingerprinted as NetScaler, nearly 22,000 of them ADC and just over 1,500 Gateway, BleepingComputer reports. The article does not say how many are patched, honeypots or vulnerable, so the number counts exposure, not compromise.
Why upgrading alone does not settle it
Because exploitation preceded the fix, an appliance that was reachable and unpatched before 27 September may already have been compromised. Sophos notes that patching may not remove attacker access to an appliance compromised before remediation. Citrix released generic indicators of compromise through NetScaler Console, but cautioned that they might fail to identify actual compromises and recommended engaging forensic investigators. watchTowr likewise says a clean scan does not rule out compromise, because the indicators do not cover every technique.
watchTowr's recommended order is worth noting because the first step runs against instinct. It says to preserve evidence before updating: capture logs, a snapshot, a support bundle and a core dump, because updating can erase evidence. Then check for compromise, patch, enable Enhanced ISN Generation, rotate every password, secret and certificate stored on or used through the appliance, forward NetScaler logs to a SIEM, and keep management interfaces off the public internet. These are the vendor's recommendations; Citrix's own bulletin should be the reference.
Fixed versions, and the awkward details
- 14.1: fixed in 14.1-73.37 and later. 14.1-FIPS: fixed in 14.1-73.37 FIPS and later.
- 13.1: fixed in 13.1-64.23 and later 13.1 releases. 13.1-FIPS and 13.1-NDcPP: fixed in 13.1-37.279 and later.
- 12.1 and 13.0 have reached end of life, and Citrix advises migrating those appliances to supported releases (BleepingComputer).
- On 13.1, watchTowr advises running show ns variable before upgrading; if it returns variables, it says to use 13.1-64.24 to avoid a reboot loop. That detail comes from watchTowr alone.
Secure Private Access hybrid deployments that use NetScaler instances are also affected, per watchTowr, while Citrix says it updates its managed cloud services itself.
What nobody has said yet
No source we reviewed names a threat actor. None gives a start date for exploitation, a count of compromised appliances, or a way to tell a clean appliance from a quietly compromised one. The memory-based technique reported by NCSC-NL, if accurate, is exactly the kind that leaves little on disk, which is consistent with Citrix's caution about its own indicators. That is an inference from the reporting, not a finding.

