Proactive Threat Intelligence from the team that finds the vulnerabilities. We publish what is being exploited right now, who is doing it, and whether it reaches you. No vendor summaries written a week late.

Citrix NetScaler ADC & Citrix NetScaler Gateway Remote Code Execution Zero-Day Vulnerabilities (CVE-2026-88771, CVE-2026-88772)

CVE-2026-88771 and CVE-2026-88772 are remote code execution zero-days in Citrix NetScaler ADC and Citrix NetScaler Gateway, exploited in the wild and now fixed. Preserve evidence, check for compromise, then update to the fixed builds.

Key Facts

  • CVE: CVE-2026-88771
  • CVSS: 9.5 Critical (CVSS 4.0)
  • Exploited in the wild: Yes, reported by CISA KEV (added September 27, 2026) and watchTowr
  • Fix available: Yes
  • Last updated: September 28, 2026

What Are CVE-2026-88771 and CVE-2026-88772?

CVE-2026-88771 and CVE-2026-88772 are remote code execution vulnerabilities in Citrix NetScaler ADC and Citrix NetScaler Gateway that attackers exploited as zero-days, before a fix existed. Citrix confirmed both and released fixed builds on September 27, 2026 in security bulletin CTX697096.

  • CVE-2026-88771 is an improper input validation vulnerability that lets an unauthenticated attacker run arbitrary commands on the appliance. It affects every NetScaler ADC and NetScaler Gateway deployment on an affected version, including the default configuration. No special feature needs to be enabled.
  • CVE-2026-88772 is a memory overflow that can lead to remote code execution or denial of service when DTLS is enabled. DTLS is on by default for VPN virtual servers, so most NetScaler Gateway deployments meet the precondition unless DTLS has been explicitly disabled.

The same bulletin fixes six further NetScaler vulnerabilities (CVE-2026-88773 to CVE-2026-88778) that depend on specific configurations, including HTTP request smuggling and denial of service issues. Our NetScaler zero-day FAQ covers all eight.

CVEDescriptionCVSS 4.0Exploited in the wild
CVE-2026-88771Improper input validation that lets an unauthenticated attacker run arbitrary commands. Affects the default configuration.9.5 CriticalYes
CVE-2026-88772Memory overflow that can lead to remote code execution or denial of service when DTLS is enabled (the default for VPN virtual servers).9.5 CriticalYes
CVE-2026-88773HTTP request smuggling (inconsistent interpretation of HTTP requests). Depends on specific configurations.9.3 CriticalNot reported
CVE-2026-88774NetScaler ADC and NetScaler Gateway vulnerability. Depends on specific configurations.7.0 HighNot reported
CVE-2026-88775Memory overflow. Depends on specific configurations.8.8 HighNot reported
CVE-2026-88776Memory overflow. Depends on specific configurations.8.8 HighNot reported
CVE-2026-88777Memory overflow. Depends on specific configurations.8.8 HighNot reported
CVE-2026-88778Predictable value from previous values. Fixed by enabling Enhanced ISN Generation, not by the upgrade alone.8.8 HighNot reported

Prioritize every NetScaler Gateway, VPN and AAA virtual server reachable from the internet. The vulnerabilities require only network access, not a valid account.

Are CVE-2026-88771 and CVE-2026-88772 Being Exploited?

CVE-2026-88771 is being exploited in the wild, as reported by CISA, which added it to its Known Exploited Vulnerabilities catalog on September 27, 2026 and watchTowr.

The zero-days first surfaced on September 26, 2026, when NetScaler administrators reported being told by suppliers and security teams to shut their appliances down, following a private pre-notification from the Dutch National Cyber Security Centre (NCSC-NL). On September 26, watchTowr publicly warned that multiple unpatched NetScaler remote code execution vulnerabilities were circulating in the wild. It said the information was credible, that the vulnerabilities had been found during forensic investigations, and that Citrix patches were expected early the following week. Citrix published its bulletin the next day.

What Is Citrix NetScaler ADC & Citrix NetScaler Gateway?

Citrix NetScaler ADC and Citrix NetScaler Gateway sit at the edge of enterprise networks, where they handle VPN and remote access, load balancing, and user authentication for staff and customers connecting to internal applications. A compromised appliance gives an attacker a foothold at the perimeter and a path to internal systems.

Which Citrix NetScaler ADC & Citrix NetScaler Gateway Versions Are Affected?

ProductAffected VersionsFixed Version
Citrix NetScaler ADC and NetScaler Gateway (14.1)before 14.1-73.3714.1-73.37 and later releases
Citrix NetScaler ADC and NetScaler Gateway (13.1)before 13.1-64.2313.1-64.23 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPSbefore 14.1-73.37 FIPS14.1-73.37 FIPS and later releases
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPPbefore 13.1-37.27913.1-37.279 and later releases

Secure Private Access hybrid deployments that use NetScaler instances are also affected. The bulletin applies to customer-managed appliances; Citrix updates its own managed cloud services. Appliances patched for the earlier CVE-2026-19490 remain vulnerable unless they run one of the fixed builds above.

How to Fix CVE-2026-88771 and CVE-2026-88772

Update every Citrix NetScaler ADC and Citrix NetScaler Gateway appliance to the fixed build for its branch. Citrix has not published a workaround for either vulnerability, so upgrading is the only fix. CISA advises checking for compromise and preserving forensic evidence before updating, because an update can remove the evidence.

  1. Capture logs, a snapshot, a support bundle and a core dump from each exposed appliance before updating.
  2. Check for compromise with the IOC scan on the NetScaler Console Security Advisory page (version 14.1-73.36 or later, telemetry enabled), or ask Citrix Support for the IOCs (see the NetScaler blog). Citrix warns that the IOCs do not cover every technique, so a clean result is not proof.
  3. Install the fixed build. On 13.1, run show ns variable first: if it returns any variables, use 13.1-64.24 to avoid a known reboot loop during the upgrade.
  4. Enable Enhanced ISN Generation to close CVE-2026-88778, which is fixed by configuration rather than the upgrade alone.
  5. Rotate passwords, secrets and certificates stored on or used through the appliance, and forward NetScaler logs to your SIEM.
  6. Keep management interfaces off the public internet.

How watchTowr Is Helping Clients

The watchTowr Platform delivers Preemptive Exposure Management, identifying, validating, and mitigating external exposure across enterprise environments.

  • Rapid Reaction identified NetScaler exposure across the watchTowr client base, and clients were made aware of their exposure on September 26, 2026, before Citrix’s bulletin and CVE IDs existed.
  • Attacker Eye, our global honeypot network, is monitoring for exploitation activity as it emerges.

Request a demo to see how Rapid Reaction identifies exposure to emerging threats like CVE-2026-88771 and CVE-2026-88772.

Updates

  • September 28, 2026: CISA added CVE-2026-88771 to its Known Exploited Vulnerabilities catalog.

If you are a watchTowr client

Want to know if this reaches you, before the next one?

watchTowr validates exposure and mitigates at the edge in under an hour.

On this page
Attackers Don't Give Up. Neither Should Your Security Testing.

Zero install. No infrastructure changes. Uplift your security posture within hours of onboarding the watchTowr Platform.

Find Out What an Attacker Can Reach Before They Do.

Point us at a domain. We reconstruct your real external estate and come back with validated exposure, not a theoretical CVE list.

Disclosure to Exploitation Is Four Hours. Patching Is Not.

The watchTowr Platform validates your exposure to an emerging threat and mitigates it at the edge while the vendor patch is still in testing.

We Find the Vulnerabilities. You Hear It From Us First.

watchTowr Labs publishes what is being exploited right now and whether it touches your estate, not vendor summaries written a week late.

Your Exposure Changes Weekly. Annual Testing Cannot Describe It.

Continuous, fully external validation of what an attacker can actually exploit against your estate, at a 0.01% false-positive rate.

See the Estate You Own, Including What No Asset List Holds.

Subsidiaries, forgotten infrastructure, shadow IT. We rebuild your external surface from a single domain, then validate what is exposed.

4757