28 SEP 2026 — Citrix shipped fixes for eight flaws in NetScaler ADC and NetScaler Gateway on 27 September. Two were already being exploited before the patches existed, and the worst affects every NetScaler deployment, even a default one.
The United States cybersecurity agency added both exploited flaws to its catalogue on 27 September and gave federal agencies until 30 September. It also told organisations to look for signs of compromise before patching, not after.
The two flaws under attack
Citrix's security bulletin, CTX697096, published on 27 September, describes CVE-2026-88771 as a remote code execution flaw caused by improper input validation. It lets an attacker with no account run commands, and its precondition reads simply "all NetScaler ADC and NetScaler Gateway deployments". No feature needs to be switched on.
CVE-2026-88772 is a memory overflow that can lead to code execution or a crash. It needs DTLS, the datagram version of the encryption protocol used for VPN traffic, and Citrix notes that DTLS is on by default for a VPN virtual server. A NetScaler Gateway is exposed unless DTLS has been explicitly turned off.
Citrix scores both at 9.5 on version 4 of the severity scale. "Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed," the bulletin says.
Which versions fix it
The fixed releases are 14.1-73.37 and later, 13.1-64.23 and later for the 13.1 line, 14.1-73.37 FIPS, and 13.1-37.279 for the FIPS and NDcPP builds. Citrix says hybrid deployments of Secure Private Access that use NetScaler instances are affected too.
The bulletin covers customer-managed appliances. Citrix says it updates its own cloud services itself.
The other six flaws in the bulletin need particular configurations, such as HTTP load balancing or an Oracle-type virtual server. One, a predictable TCP sequence number, is fixed by a configuration change rather than a new build. None of the six is listed as exploited.
Check before patching
CISA's alert is explicit about the order of work: check for indications of compromise and preserve forensic evidence before patching, because updating can destroy what an investigator needs.
That runs against the usual instinct to patch first. Because the flaws were exploited before a fix was available, a patched appliance may still hold whatever an attacker left on it. Citrix publishes indicators of compromise for its NetScaler Console and a separate compromise-assessment guide, CTX694799.
CISA also warns that updating NetScaler can be complex and may need downtime, and advises planning for it. For a device that sits in front of remote access for a whole organisation, that is a cost worth paying this week.
A familiar pattern for NetScaler
These are the latest in a long run. CISA's catalogue lists earlier NetScaler entries this year in March, August and September, and in July we reported a CitrixBleed-class flaw exploited within a day of disclosure.
Gateways like NetScaler are attractive because they sit on the internet edge and handle logins for everything behind them. A flaw that needs no account and no special configuration is the most valuable kind an attacker can find.
Who found it
Citrix credits Michael Tucker, Chew Keong Tan and Alex Bernier of the JPMorgan Chase XOR team, and Maxim Suhanov. The bulletin does not say who was exploiting the flaws or how many appliances have been hit.