hackingDNA
← Insights

Research

Citrix NetScaler Zero-Days CVE-2026-88771 and CVE-2026-88772: A Defender's Response Guide

  • vulnerability-management
  • citrix
  • netscaler
  • incident-response
  • cve

Two unauthenticated RCE flaws in NetScaler ADC and Gateway are under active exploitation, with a CISA deadline of September 30. What is affected, fixed versions, and the order to respond in.

If you run an internet-facing NetScaler, check for compromise before you patch. Updating first can wipe the evidence you need.

On September 27, 2026, Citrix confirmed active exploitation of two critical NetScaler vulnerabilities, CVE-2026-88771 and CVE-2026-88772. Both allow unauthenticated remote code execution on NetScaler ADC and NetScaler Gateway. CISA added both to its Known Exploited Vulnerabilities (KEV) catalog the same day and gave US federal agencies until September 30 to secure affected appliances (BleepingComputer).

This guide is for defenders and learners. It explains the risk, the fixed versions, and a response order that keeps your forensic options open. It contains no exploitation details.

What is affected

According to Citrix's advisory, as reported by BleepingComputer:

  • CVE-2026-88771 affects all NetScaler ADC and NetScaler Gateway deployments in default configuration.
  • CVE-2026-88772 requires DTLS to be enabled. DTLS is on by default for VPN virtual servers, so most Gateway deployments are in scope.

The wider advisory also lists issues that can cause denial of service, HTTP request smuggling, policy bypass, and TCP initial sequence number prediction under specific configurations.

Before the CVEs were published, national CERTs, including the Dutch NCSC, reportedly contacted organizations privately and advised them to take appliances offline. Treat this as an incident, not routine patching.

Fixed versions

Upgrade to these releases or later:

  • NetScaler ADC and Gateway 14.1: 14.1-73.37
  • NetScaler ADC and Gateway 13.1: 13.1-64.23
  • NetScaler ADC 14.1-FIPS: 14.1-73.37 FIPS
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP: 13.1.37.279

Versions 12.1 and 13.0 are end-of-life and will not receive fixes. Appliances running those versions have to move to a supported release. There is no patch path for them.

Always confirm version numbers against Citrix's official security bulletin before you change anything.

Why this matters: the scale

Shadowserver tracks more than 23,000 internet-exposed IPs with NetScaler fingerprints. That includes about 22,000 ADC appliances and more than 1,500 Gateway instances. Some are honeypots or already patched, but the attack surface is large.

It is also part of a pattern. NetScaler flaws have been exploited repeatedly in 2026:

  • March: CVE-2026-3055 and CVE-2026-4368, exploited days after disclosure.
  • Early September: CVE-2026-19490, an authentication bypass patched in mid-August.
  • Late September: CVE-2026-88771 and CVE-2026-88772, exploited as zero-days.

Since November 2021, CISA has flagged 26 actively exploited Citrix vulnerabilities. Six were used by ransomware groups.

The response order

The key decision is timing. CISA says: "Should your organization suspect compromise, it is important to preserve forensic evidence prior to applying updates, as updates may result in loss of forensic visibility."

Follow this order.

1. Inventory

List every NetScaler ADC and Gateway you own, including labs, disaster recovery sites, and appliances a vendor manages for you. For each one, record:

  • Build version
  • Whether it is internet-facing
  • Whether DTLS is enabled on any VPN virtual server
  • Whether it is on an end-of-life branch (12.1 or 13.0)

Exposure scanners you control, and your own attack-surface records, are the source of truth here. Internet-wide scan data only helps you cross-check.

2. Reduce exposure now

If you can't assess and patch within hours, reduce exposure first. Restrict management interfaces to trusted networks, and think about temporarily limiting access to Gateway services while you work. Weigh this against business impact. Many national CERTs advised taking appliances offline outright.

3. Assess for compromise before patching

  • Run the indicators of compromise Citrix published through NetScaler Console. Citrix says these generic IoCs "might be of limited forensic value and might fail to identify actual compromises," so a clean result does not prove the appliance is clean.
  • Capture evidence before you change anything: running configuration, logs, and a disk and memory image if your process allows it.
  • Look for signs that someone was on the appliance after the exploitation window began: unfamiliar files in web-served directories, unexpected processes, new admin accounts, configuration changes you can't explain, and outbound connections from the appliance.
  • CERT-EU advises running a compromise assessment on any internet-facing appliance running an affected build. Follow that bar.

If you find anything suspicious, bring in experienced incident responders. Citrix explicitly recommends this.

4. Patch

Upgrade to the fixed builds above. Move end-of-life appliances to a supported release.

5. Assume credentials were exposed

A compromised edge appliance sees sessions and credentials pass through it. If there is any sign of compromise:

  • Rotate credentials for service accounts and LDAP bind accounts the appliance uses.
  • Kill active sessions so stolen session tokens stop working.
  • Review identity provider logs for sign-ins that came through the appliance during the exposure window.
  • Hunt for lateral movement from the appliance's internal IP addresses.

6. Verify and monitor

Confirm every appliance reports a fixed build. Keep extra monitoring on NetScaler logs and on internal traffic from the appliances for several weeks. Attackers who got in before the patch may have left persistence that survives the upgrade.

The broader lesson: edge devices are a primary target

VPNs, gateways, and load balancers sit on the internet, handle authentication, and often run with limited logging and no EDR. That makes them attractive first targets. Treat them as critical assets:

  • Keep a live inventory with version and exposure data.
  • Plan for emergency patching of edge devices within days, not quarters.
  • Forward appliance logs to your SIEM, where an intruder can't delete them.
  • Have a written "suspected edge compromise" playbook ready before you need it.
  • Track the CISA KEV catalog as a priority signal, alongside CVSS scores.

Keep learning

All testing should stay within systems you own or are explicitly authorized to assess.

Sources

Patching closes the hole. It does not tell you whether someone already got in, so check that first.