Key Facts
- CVE: CVE-2026-88771
- CVSS: 9.5 Critical (CVSS 4.0)
- Exploited in the wild: Yes, reported by CISA KEV (added September 27, 2026) and watchTowr
- Fix available: Yes
- Last updated: September 28, 2026
What Are CVE-2026-88771 and CVE-2026-88772?
CVE-2026-88771 and CVE-2026-88772 are remote code execution vulnerabilities in Citrix NetScaler ADC and Citrix NetScaler Gateway that attackers exploited as zero-days, before a fix existed. Citrix confirmed both and released fixed builds on September 27, 2026 in security bulletin CTX697096.
- CVE-2026-88771 is an improper input validation vulnerability that lets an unauthenticated attacker run arbitrary commands on the appliance. It affects every NetScaler ADC and NetScaler Gateway deployment on an affected version, including the default configuration. No special feature needs to be enabled.
- CVE-2026-88772 is a memory overflow that can lead to remote code execution or denial of service when DTLS is enabled. DTLS is on by default for VPN virtual servers, so most NetScaler Gateway deployments meet the precondition unless DTLS has been explicitly disabled.
The same bulletin fixes six further NetScaler vulnerabilities (CVE-2026-88773 to CVE-2026-88778) that depend on specific configurations, including HTTP request smuggling and denial of service issues. Our NetScaler zero-day FAQ covers all eight.
| CVE | Description | CVSS 4.0 | Exploited in the wild |
|---|---|---|---|
| CVE-2026-88771 | Improper input validation that lets an unauthenticated attacker run arbitrary commands. Affects the default configuration. | 9.5 Critical | Yes |
| CVE-2026-88772 | Memory overflow that can lead to remote code execution or denial of service when DTLS is enabled (the default for VPN virtual servers). | 9.5 Critical | Yes |
| CVE-2026-88773 | HTTP request smuggling (inconsistent interpretation of HTTP requests). Depends on specific configurations. | 9.3 Critical | Not reported |
| CVE-2026-88774 | NetScaler ADC and NetScaler Gateway vulnerability. Depends on specific configurations. | 7.0 High | Not reported |
| CVE-2026-88775 | Memory overflow. Depends on specific configurations. | 8.8 High | Not reported |
| CVE-2026-88776 | Memory overflow. Depends on specific configurations. | 8.8 High | Not reported |
| CVE-2026-88777 | Memory overflow. Depends on specific configurations. | 8.8 High | Not reported |
| CVE-2026-88778 | Predictable value from previous values. Fixed by enabling Enhanced ISN Generation, not by the upgrade alone. | 8.8 High | Not reported |
Prioritize every NetScaler Gateway, VPN and AAA virtual server reachable from the internet. The vulnerabilities require only network access, not a valid account.
Are CVE-2026-88771 and CVE-2026-88772 Being Exploited?
CVE-2026-88771 is being exploited in the wild, as reported by CISA, which added it to its Known Exploited Vulnerabilities catalog on September 27, 2026 and watchTowr.
The zero-days first surfaced on September 26, 2026, when NetScaler administrators reported being told by suppliers and security teams to shut their appliances down, following a private pre-notification from the Dutch National Cyber Security Centre (NCSC-NL). On September 26, watchTowr publicly warned that multiple unpatched NetScaler remote code execution vulnerabilities were circulating in the wild. It said the information was credible, that the vulnerabilities had been found during forensic investigations, and that Citrix patches were expected early the following week. Citrix published its bulletin the next day.
What Is Citrix NetScaler ADC & Citrix NetScaler Gateway?
Citrix NetScaler ADC and Citrix NetScaler Gateway sit at the edge of enterprise networks, where they handle VPN and remote access, load balancing, and user authentication for staff and customers connecting to internal applications. A compromised appliance gives an attacker a foothold at the perimeter and a path to internal systems.
Which Citrix NetScaler ADC & Citrix NetScaler Gateway Versions Are Affected?
| Product | Affected Versions | Fixed Version |
|---|---|---|
| Citrix NetScaler ADC and NetScaler Gateway (14.1) | before 14.1-73.37 | 14.1-73.37 and later releases |
| Citrix NetScaler ADC and NetScaler Gateway (13.1) | before 13.1-64.23 | 13.1-64.23 and later releases of 13.1 |
| Citrix NetScaler ADC 14.1-FIPS | before 14.1-73.37 FIPS | 14.1-73.37 FIPS and later releases |
| Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP | before 13.1-37.279 | 13.1-37.279 and later releases |
Secure Private Access hybrid deployments that use NetScaler instances are also affected. The bulletin applies to customer-managed appliances; Citrix updates its own managed cloud services. Appliances patched for the earlier CVE-2026-19490 remain vulnerable unless they run one of the fixed builds above.
How to Fix CVE-2026-88771 and CVE-2026-88772
Update every Citrix NetScaler ADC and Citrix NetScaler Gateway appliance to the fixed build for its branch. Citrix has not published a workaround for either vulnerability, so upgrading is the only fix. CISA advises checking for compromise and preserving forensic evidence before updating, because an update can remove the evidence.
- Capture logs, a snapshot, a support bundle and a core dump from each exposed appliance before updating.
- Check for compromise with the IOC scan on the NetScaler Console Security Advisory page (version 14.1-73.36 or later, telemetry enabled), or ask Citrix Support for the IOCs (see the NetScaler blog). Citrix warns that the IOCs do not cover every technique, so a clean result is not proof.
- Install the fixed build. On 13.1, run
show ns variablefirst: if it returns any variables, use 13.1-64.24 to avoid a known reboot loop during the upgrade. - Enable Enhanced ISN Generation to close CVE-2026-88778, which is fixed by configuration rather than the upgrade alone.
- Rotate passwords, secrets and certificates stored on or used through the appliance, and forward NetScaler logs to your SIEM.
- Keep management interfaces off the public internet.
How watchTowr Is Helping Clients
The watchTowr Platform delivers Preemptive Exposure Management, identifying, validating, and mitigating external exposure across enterprise environments.
- Rapid Reaction identified NetScaler exposure across the watchTowr client base, and clients were made aware of their exposure on September 26, 2026, before Citrix’s bulletin and CVE IDs existed.
- Attacker Eye, our global honeypot network, is monitoring for exploitation activity as it emerges.
Request a demo to see how Rapid Reaction identifies exposure to emerging threats like CVE-2026-88771 and CVE-2026-88772.
Updates
- September 28, 2026: CISA added CVE-2026-88771 to its Known Exploited Vulnerabilities catalog.
