Proactive Threat Intelligence from the team that finds the vulnerabilities. We publish what is being exploited right now, who is doing it, and whether it reaches you. No vendor summaries written a week late.

Updated Sep 27, 2026

Citrix NetScaler Zero-Day RCE FAQ: CVE-2026-88771 and CVE-2026-88772

CVE-2026-88771 and CVE-2026-88772 are Citrix NetScaler remote code execution zero-days, exploited in the wild and fixed in CTX697096. What is affected, how to fix it, how to check for compromise, and how watchTowr Rapid Reaction flagged exposure before the CVEs existed.

Status

CVE

CVE-2026-88771, CVE-2026-88772

CVSS

9.5 (v4.0)

Exploitation

In The Wild

CISA KEV

Listed

Vendor patch

Available

Questions

Updates

Key takeaways

What are the Citrix NetScaler zero-day vulnerabilities?

CVE-2026-88771 and CVE-2026-88772 are critical remote code execution (RCE) vulnerabilities in Citrix NetScaler ADC and Citrix NetScaler Gateway that attackers exploited as zero-days, before any fix existed. Citrix confirmed both and released fixed builds on September 27, 2026 in security bulletin CTX697096. Both are rated 9.5 Critical under CVSS 4.0. The same bulletin fixes six more NetScaler CVEs, all listed below.

CVEDescriptionCVSS 4.0Exploited in the wild
CVE-2026-88771Improper input validation that lets an unauthenticated attacker run arbitrary commands. Affects the default configuration.9.5 CriticalYes
CVE-2026-88772Memory overflow that can lead to remote code execution or denial of service when DTLS is enabled (the default for VPN virtual servers).9.5 CriticalYes
CVE-2026-88773HTTP request smuggling (inconsistent interpretation of HTTP requests). Depends on specific configurations.9.3 CriticalNot reported
CVE-2026-88774NetScaler ADC and NetScaler Gateway vulnerability. Depends on specific configurations.7.0 HighNot reported
CVE-2026-88775Memory overflow. Depends on specific configurations.8.8 HighNot reported
CVE-2026-88776Memory overflow. Depends on specific configurations.8.8 HighNot reported
CVE-2026-88777Memory overflow. Depends on specific configurations.8.8 HighNot reported
CVE-2026-88778Predictable value from previous values. Fixed by enabling Enhanced ISN Generation, not by the upgrade alone.8.8 HighNot reported

Are CVE-2026-88771 and CVE-2026-88772 being exploited in the wild?

Yes. Citrix states it has observed exploitation of both vulnerabilities on unmitigated NetScaler deployments, and CISA reports that threat actors are exploiting them globally. CISA added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) catalog on September 27, 2026.

How did the NetScaler zero-days come to light?

Before Citrix published anything, NetScaler administrators reported being told by suppliers and security teams to shut their appliances down, following a private pre-notification from the Dutch National Cyber Security Centre (NCSC-NL). On September 26, 2026, watchTowr publicly warned that multiple unpatched NetScaler remote code execution vulnerabilities were being exploited in the wild, that the information was credible and came from forensic investigations, and that Citrix patches were expected early the following week. Citrix published bulletin CTX697096 the next day.

How is watchTowr helping NetScaler customers?

watchTowr Rapid Reaction identified NetScaler exposure across the watchTowr client base, and clients were made aware of their exposure on September 26, 2026, before Citrix’s bulletin and CVE IDs existed. Attacker Eye, our global honeypot network, is monitoring for exploitation activity as it emerges.

This is what Preemptive Exposure Management means in practice: knowing which of your systems an attacker can reach, and acting on it, while a vulnerability is still a zero-day. Request a demo to see how Rapid Reaction answers “are we affected?” within hours of an emerging threat.

What is Citrix NetScaler ADC and NetScaler Gateway?

Citrix NetScaler ADC and Citrix NetScaler Gateway sit at the edge of enterprise networks, where they handle VPN and remote access, load balancing, and user authentication for staff and customers connecting to internal applications. A compromised appliance gives an attacker a foothold at the perimeter and a path to internal systems, which is why NetScaler vulnerabilities are prized by ransomware groups and state-sponsored attackers alike.

Which NetScaler versions are affected?

ProductAffected versionsFixed version
NetScaler ADC and NetScaler Gateway 14.1Before 14.1-73.3714.1-73.37 and later
NetScaler ADC and NetScaler Gateway 13.1Before 13.1-64.2313.1-64.23 and later releases of 13.1
NetScaler ADC 14.1-FIPSBefore 14.1-73.37 FIPS14.1-73.37 FIPS and later
NetScaler ADC 13.1-FIPS and 13.1-NDcPPBefore 13.1-37.27913.1-37.279 and later

Secure Private Access hybrid deployments that use NetScaler instances are also affected. The bulletin applies to customer-managed appliances; Citrix updates its own managed cloud services. Prioritize every NetScaler Gateway, VPN and AAA virtual server reachable from the internet: the vulnerabilities need only network access, not a valid account.

How do I fix CVE-2026-88771 and CVE-2026-88772?

Update every NetScaler ADC and NetScaler Gateway appliance to the fixed build for its branch. Citrix has not published a workaround for either vulnerability, so upgrading is the only fix. CISA advises checking for compromise and preserving forensic evidence first, because an update can remove the evidence.

  1. Capture logs, a snapshot, a support bundle and a core dump from each exposed appliance.
  2. Check for compromise (see the next question).
  3. Install the fixed build. On 13.1, run show ns variable first: if it returns any variables, use 13.1-64.24 to avoid a known reboot loop during the upgrade.
  4. Rotate passwords, secrets and certificates stored on or used through the appliance, and forward NetScaler logs to your SIEM.
  5. Keep management interfaces off the public internet.

How do I check a NetScaler appliance for compromise?

Run the IOC scan on the NetScaler Console Security Advisory page (version 14.1-73.36 or later, with telemetry enabled), or ask Citrix Support for the indicators of compromise (IOCs), as described on the NetScaler blog. Citrix warns that the IOCs do not cover every technique, so a clean result is not proof that an appliance was not compromised.

What other NetScaler vulnerabilities does CTX697096 fix?

The same bulletin fixes six further NetScaler vulnerabilities, CVE-2026-88773 to CVE-2026-88778, that depend on specific configurations, including HTTP request smuggling and denial of service issues. CVE-2026-88778 is closed by configuration: enable Enhanced ISN Generation, because the upgrade alone does not fix it.

Are they related to CVE-2026-19490?

No. CVE-2026-19490 is an earlier NetScaler vulnerability that CISA added to the KEV catalog on September 9, 2026. Appliances patched for CVE-2026-19490 remain vulnerable to CVE-2026-88771 and CVE-2026-88772 unless they run one of the fixed builds above.

Which threat actors are exploiting them?

No attribution has been made public. Historically, NetScaler vulnerabilities have been exploited by both state-sponsored groups and ransomware operators.

Have there been similar NetScaler vulnerabilities before?

Yes. These earlier NetScaler vulnerabilities were added to the CISA KEV catalog after exploitation in the wild:

CVEDescriptionAdded to KEV
CVE-2026-19490NetScaler ADC and NetScaler Gateway vulnerabilitySeptember 9, 2026
CVE-2026-8452NetScaler ADC and NetScaler Gateway buffer overflowAugust 26, 2026
CVE-2026-3055NetScaler out-of-bounds readMarch 30, 2026
CVE-2025-7775NetScaler memory overflowAugust 26, 2025
CVE-2025-5777NetScaler ADC and Gateway out-of-bounds read (“CitrixBleed 2”), analyzed by watchTowr LabsJuly 10, 2025
CVE-2025-6543NetScaler ADC and Gateway buffer overflowJune 30, 2025
CVE-2023-4966NetScaler ADC and Gateway buffer overflow (“CitrixBleed”)October 18, 2023
CVE-2023-3519NetScaler ADC and Gateway code injectionJuly 19, 2023

If you are a watchTowr client

watchTowr Rapid Reaction made clients aware of their NetScaler exposure on September 26, 2026, before Citrix’s bulletin and the CVE IDs existed. Contact your watchTowr team with any questions.

Want to know if this reaches you, before the next one?

watchTowr validates exposure and mitigates at the edge in under an hour.

Attackers Don't Give Up. Neither Should Your Security Testing.

Zero install. No infrastructure changes. Uplift your security posture within hours of onboarding the watchTowr Platform.

Find Out What an Attacker Can Reach Before They Do.

Point us at a domain. We reconstruct your real external estate and come back with validated exposure, not a theoretical CVE list.

Disclosure to Exploitation Is Four Hours. Patching Is Not.

The watchTowr Platform validates your exposure to an emerging threat and mitigates it at the edge while the vendor patch is still in testing.

We Find the Vulnerabilities. You Hear It From Us First.

watchTowr Labs publishes what is being exploited right now and whether it touches your estate, not vendor summaries written a week late.

Your Exposure Changes Weekly. Annual Testing Cannot Describe It.

Continuous, fully external validation of what an attacker can actually exploit against your estate, at a 0.01% false-positive rate.

See the Estate You Own, Including What No Asset List Holds.

Subsidiaries, forgotten infrastructure, shadow IT. We rebuild your external surface from a single domain, then validate what is exposed.