Technology

CVE-2026-88771 CVE-2026-88772 NetScaler patch: fixed builds after active-exploitation alert

Citrix says two critical NetScaler flaws are exploited. Check affected customer-managed ADC and Gateway builds, DTLS exposure and pre-patch compromise guidance.

Original editorial illustration of a network appliance in a server rack with two red fault indicators and a blue defensive shield, without logos or people
Original editorial illustration of a network appliance in a server rack with two red fault indicators and a blue defensive shield, without logos or people. Illustration: Reddy News.
Key points
  • Citrix says exploits of CVE-2026-88771 and CVE-2026-88772 have been observed on unmitigated NetScaler deployments; CISA added both identifiers to its Known Exploited Vulnerabilities Catalog on 27 September.
  • CVE-2026-88771 affects every in-scope NetScaler ADC and Gateway deployment on an affected release, including the default configuration; CVE-2026-88772 requires DTLS, which is enabled by default on VPN virtual servers unless explicitly disabled.
  • The first fixed thresholds are 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS and 13.1-37.279 for the applicable FIPS or NDcPP line.
  • The bulletin applies to customer-managed NetScaler ADC and Gateway appliances, including NetScaler instances in Secure Private Access Hybrid deployments. Citrix says it is updating its managed cloud services and managed Adaptive Authentication.
  • A successful update remediates the documented software flaws but does not determine whether exploitation happened before the patch. CISA advises checking for indications of compromise and preserving forensic evidence where feasible before applying updates.

The immediate decision is to identify every customer-managed appliance

The CVE-2026-88771 CVE-2026-88772 NetScaler patch is an urgent inventory-and-update task for organisations that run customer-managed Citrix NetScaler ADC or NetScaler Gateway. Citrix published fixes on 27 September after saying exploits of both vulnerabilities had been observed on unmitigated deployments. CISA added both identifiers to its Known Exploited Vulnerabilities Catalog on the same date. That makes this more than a routine maintenance question: teams need to establish which appliances they own, the software release on each one and whether the relevant fixed build is installed.

The public evidence supports a focused conclusion, not a wider one. Citrix and CISA confirm exploitation, but the materials reviewed do not publicly identify an attacker, victims, an initial-access method, or the number or scale of incidents. No such claims should be inferred from the KEV listing, the critical severity rating or the fact that an appliance is internet-facing. An affected deployment is an exposure that requires priority handling; it is not proof that the deployment has been compromised.

The two flaws have different exposure conditions

Citrix rates CVE-2026-88771 at 9.5 under CVSS v4. It describes an improper-input-validation flaw that can allow an unauthenticated attacker to execute arbitrary commands remotely. The key scope point is unusually broad: Citrix says all NetScaler ADC and NetScaler Gateway deployments on an affected release meet the precondition, including a default deployment. No additional setting or feature has to be enabled for that condition. This is why a configuration check cannot remove the need to identify and update an affected appliance.

CVE-2026-88772 is also rated 9.5 under CVSS v4, but its precondition is narrower. Citrix describes a memory-overflow vulnerability that can lead to remote code execution or denial of service when DTLS is enabled. DTLS is enabled by default on VPN virtual servers, according to the vendor. Citrix says a NetScaler Gateway is vulnerable to this CVE if DTLS has not been explicitly disabled, while other virtual servers are in scope when they are configured for DTLS. This distinction is relevant to exposure assessment, but it does not reduce the importance of CVE-2026-88771 on an affected release.

Both CVEs appear in a Citrix bulletin that covers eight vulnerabilities. The article concerns the two that Citrix says have observed exploitation and that CISA added to KEV. The presence of other CVEs in the same bulletin is not evidence that those other issues are being exploited. Keeping the identifiers separate helps avoid turning a patch bulletin into a broader, unsupported claim about attacks.

Vendor fixed-build map for the affected NetScaler release lines

For standard NetScaler ADC and NetScaler Gateway 14.1, Citrix lists versions before 14.1-73.37 as affected. The first fixed threshold is 14.1-73.37; later releases in that 14.1 line are also listed by Citrix as updated versions.

For standard NetScaler ADC and NetScaler Gateway 13.1, versions before 13.1-64.23 are affected. Citrix lists 13.1-64.23 and later releases of 13.1 as the relevant updated releases.

For NetScaler ADC 14.1-FIPS, Citrix lists releases before 14.1-73.37 FIPS as affected. The fixed threshold is 14.1-73.37 FIPS, followed by later 14.1-FIPS releases.

For the Citrix line described as NetScaler ADC 13.1-FIPS and 13.1-NDcPP, releases before 13.1-37.279 are affected. Citrix lists 13.1-37.279 and later releases of the applicable 13.1-FIPS or 13.1-NDcPP line. Secure Private Access Hybrid deployments that use NetScaler instances are also affected, and Citrix says those instances need the recommended NetScaler builds. Teams should use the current Citrix bulletin and their approved compatibility process when mapping an appliance to a destination build.

Why investigation should run alongside patch planning

Patching is remediation for the vulnerability; it is not a retrospective test of whether an attacker used it before the update. CISA explicitly encourages organisations, where possible, to check for an indication of compromise before patching. It also says that if compromise is suspected, forensic evidence should be preserved before updates because updates may result in a loss of forensic visibility. That caution is especially important when an appliance is a central point for remote access or application delivery.

The appropriate sequence depends on the organisation's incident and change procedures, but the public guidance supports a clear order of thought. First establish appliance ownership, release and exposure. Retain relevant logs and other evidence where feasible. Assess possible compromise using current Citrix and CISA direction, then install the applicable fixed build and validate the appliance afterwards. A preservation step is not a reason to leave a known vulnerable appliance unaddressed indefinitely; rather, it recognises that an update can change or remove information needed for a later assessment.

Citrix's bulletin directs customers to its support channels for technical assistance and says customers should always view the latest bulletin because the company may update it. CISA likewise points readers to Citrix's advisories and its guidance for a suspected NetScaler compromise. Those sources are the right place for product-specific procedures, current indicators and any revised operational direction. This article does not publish exploit code or attempt to turn limited public information into a compromise finding.

A practical, bounded response checklist

Start with inventory rather than assumptions. Locate every customer-managed NetScaler ADC and Gateway, including any NetScaler instance supporting Secure Private Access Hybrid, and record its exact release. Confirm who owns the appliance and whether it is part of a managed Citrix service or a customer-managed deployment. That ownership distinction determines whether the administrator must carry out the update or whether Citrix has said it is handling the service update.

Next, compare each customer-managed appliance with the vendor's fixed-build thresholds. Treat CVE-2026-88771 as applicable to all affected ADC and Gateway deployments. For CVE-2026-88772, review whether DTLS is enabled, remembering Citrix's specific warning that it is enabled by default on VPN virtual servers unless explicitly disabled. This is an exposure check, not evidence of an attempted or successful attack.

Before an update where feasible, retain available records needed under the organisation's response process and consider Citrix and CISA guidance for assessing compromise. Then schedule and deploy the relevant fixed build using the organisation's approved maintenance and rollback arrangements. CISA notes that NetScaler updates can be complex and may require downtime, so a rushed unplanned change can carry operational consequences even when the security priority is clear.

Afterwards, verify that the appliance is on the intended release and that its expected service functions remain available. Keep the remediation record, assessment findings and evidence-preservation decisions together. A version check can establish that a fixed build is installed; it cannot, by itself, establish that no earlier intrusion occurred.

Customer-managed systems are in scope; Citrix-managed services are treated differently

Citrix says CTX697096 applies only to customer-managed NetScaler ADC and NetScaler Gateway products. It says Cloud Software Group upgrades Citrix-managed cloud services and Citrix-managed Adaptive Authentication with the necessary software updates. That statement is useful for dividing responsibilities, but it is not a reason to assume a particular business service has no customer-managed component. Organisations should establish their own deployment and support model before closing the issue.

The distinction also avoids an overbroad service-availability claim. Citrix's statement says it is handling updates for the managed offerings it names; it does not establish the status of every customer's configuration, connection or dependent service at a particular time. Customer-managed appliances remain the immediate patching focus described by the bulletin. Where an organisation is unsure which party manages a gateway or ADC, its service records and Citrix support arrangement are more reliable than a product name alone.

What the active-exploitation alert does—and does not—establish

Citrix's statement that exploits have been observed on unmitigated deployments establishes a serious current risk. CISA's addition of both vulnerabilities to its official Known Exploited Vulnerabilities Catalog reinforces the urgency. Independent reporting by BleepingComputer and The Hacker News also documented the disclosure, the broad default-condition exposure for CVE-2026-88771 and the DTLS condition for CVE-2026-88772. Together, those sources support acting promptly on the vendor's fixed-build guidance.

They do not establish who is responsible, which organisations were affected, whether any named organisation is a victim, how an intrusion began, or whether exploitation is widespread. They also do not provide a public basis to declare a particular deployment safe merely because its role is limited or its DTLS setting differs. The defensible conclusion is narrower: customer-managed NetScaler ADC and Gateway systems that fall below Citrix's fixed thresholds need priority assessment and updating, with the possibility of pre-patch compromise kept separate from the act of patching.

The update is essential, but it is not the end of the question

The most useful response to the 27 September alert is to avoid two opposite mistakes: treating it as an ordinary deferred update, or claiming every appliance has been breached. Citrix has supplied updated builds for the affected release lines, and CISA has treated both CVEs as known exploited vulnerabilities. Those facts support prompt, controlled remediation of in-scope customer-managed systems.

At the same time, a patch closes the disclosed software exposure going forward; it does not settle what happened before the patch. Keep version remediation, evidence preservation and any compromise assessment as related but distinct workstreams. Recheck the live Citrix bulletin before executing a maintenance change, since vendor advice can be updated. That approach preserves the urgency of an active-exploitation alert without inventing attackers, victims, outcomes or attack scope that the public sources do not establish.

Reader guide

Article questions, answered

Short answers to common reader questions based on the reporting above.

Which Citrix NetScaler releases need the CVE-2026-88771 and CVE-2026-88772 patch?

Citrix lists these affected thresholds: NetScaler ADC and Gateway 14.1 before 14.1-73.37; 13.1 before 13.1-64.23; NetScaler ADC 14.1-FIPS before 14.1-73.37 FIPS; and NetScaler ADC 13.1-FIPS and 13.1-NDcPP before 13.1-37.279. The corresponding listed fixed thresholds are 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS and 13.1-37.279. Confirm the current Citrix bulletin and release compatibility before scheduling the change.

Does CVE-2026-88772 affect every NetScaler appliance?

No. Citrix says CVE-2026-88772 requires DTLS to be enabled. It says DTLS is enabled by default on VPN virtual servers, so a NetScaler Gateway is vulnerable if DTLS has not been explicitly disabled; other virtual servers are in scope when configured for DTLS. CVE-2026-88771 is different: Citrix says every ADC and Gateway deployment on an affected release meets that CVE's precondition, including the default configuration.

Are Citrix-managed cloud services covered by the customer patch instruction?

Citrix says the bulletin applies to customer-managed NetScaler ADC and Gateway appliances. It says Cloud Software Group is upgrading Citrix-managed cloud services and Citrix-managed Adaptive Authentication with the necessary updates. An organisation should still verify its own deployment model, because a service arrangement can include customer-managed NetScaler components.

Does installing a fixed build prove that a NetScaler appliance was not compromised?

No. Installing the fixed build remediates the documented vulnerabilities but does not establish whether exploitation occurred before the update. CISA encourages organisations, if possible, to check for indications of compromise before patching and says to preserve forensic evidence before updates if compromise is suspected, because an update may reduce forensic visibility.

Sources and further reading

These references support the factual context used in this article. Links open the original publisher.

  1. Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778 (CTX697096)Citrix / Cloud Software Group · accessed 28 September 2026
  2. Known Exploited Vulnerabilities CatalogCybersecurity and Infrastructure Security Agency · accessed 28 September 2026
  3. Citrix confirms two NetScaler RCE zero-days exploited in attacksBleepingComputer · accessed 28 September 2026
  4. Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active ExploitationThe Hacker News · accessed 28 September 2026