Cyber One Solutions logo.
Get Support

Security Advisory

CVE-2026-88771 and CVE-2026-88772: CISA Warns of Zero-Day Attacks on Citrix NetScaler, Three-Day Federal Patch Deadline

September 29, 2026 · Updated September 30, 2026 · Cyber One Solutions Security Team

Citrix disclosed eight NetScaler ADC and Gateway vulnerabilities on September 27, 2026, and confirmed two of them, both allowing remote code execution, were already being exploited as zero-days before a patch existed. CISA added both to its Known Exploited Vulnerabilities catalog the same day, giving federal civilian agencies a September 30 remediation deadline; every organization running NetScaler should treat the timeline as urgent regardless.

Citrix's parent company, Cloud Software Group, published security bulletin CTX697096 on September 27, 2026, disclosing eight vulnerabilities in NetScaler ADC and NetScaler Gateway. Two of them, CVE-2026-88771 and CVE-2026-88772, each carry a CVSS v4.0 score of 9.5 and were already under active exploitation when Citrix disclosed them, according to Citrix's own bulletin: "Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed." CISA added both to its Known Exploited Vulnerabilities (KEV) catalog that same day, and the same day published an alert stating that "threat actors are actively exploiting these vulnerabilities globally," according to CISA's alert and CISA's KEV catalog entry. The KEV catalog lists a September 30, 2026 due date for federal civilian agencies to remediate under Binding Operational Directive 26-04, giving organizations roughly three days' notice from disclosure.

What the Two Actively Exploited Flaws Are

CVE-2026-88771 is an improper input validation flaw that CISA describes as allowing an unauthenticated attacker to execute arbitrary commands. Citrix's bulletin states it affects NetScaler ADC and Gateway in their default configuration, with no additional feature or setting required for a deployment to be vulnerable. CVE-2026-88772 is a memory-overflow flaw that can lead to remote code execution or denial of service; it requires DTLS to be configured on the appliance, which Citrix's bulletin notes is enabled by default on VPN virtual servers, the configuration most commonly used for SSL VPN and remote-access gateways. The other six disclosed vulnerabilities in the same bulletin, ranging from a CVSS 9.3 HTTP request-smuggling flaw down to a CVSS 7.0 policy bypass, are not described by Citrix or CISA as currently exploited, but they affect the same builds and are fixed by the same update.

Affected and Fixed Versions

Citrix's bulletin lists NetScaler ADC and NetScaler Gateway 14.1 before build 14.1-73.37, and 13.1 before build 13.1-64.23, as affected, along with the corresponding FIPS build (before 14.1-73.37 FIPS) and FIPS/NDcPP build (before 13.1-37.279). Cloud Software Group's fixed releases are 14.1-73.37 and later, 13.1-64.23 and later, with matching FIPS and NDcPP builds. Confirm your appliance's exact build number against these thresholds rather than assuming a recent update already covers it; NetScaler version 12.1 and 13.0 are past end of life and not covered by this update, so any appliance still on those branches has no vendor fix available at all.

A Detail Worth Reading Before You Patch

CISA's alert includes guidance that is easy to miss in the rush to remediate: because these two flaws were being exploited before a patch existed, an appliance that has been running an affected build with an exposed Gateway or AAA virtual server may already be compromised, and applying the update alone will not remove an existing foothold. CISA recommends checking for indicators of compromise using the tooling in NetScaler Console before patching, and cautions that "updates may result in loss of forensic visibility," meaning evidence of a prior intrusion can be overwritten once the appliance is patched and restarted. Citrix has published a companion guide, referenced in CISA's alert, titled "Steps to Take if NetScaler ADC is Suspected to be Compromised."

Update, September 30, 2026: How Far Back the Compromise Window Goes

Threat-intelligence firm GreyNoise reported detecting exploitation attempts against a Citrix NetScaler Gateway as early as September 24, 2026, three days before Citrix's public disclosure, according to GreyNoise's own findings. That confirms these were exploited as genuine zero-days rather than flaws that only saw attacks after disclosure. September 24 is the earliest exploitation GreyNoise has publicly reported observing, not a hard boundary on when an intrusion could have happened; an attacker active before GreyNoise's sensors picked this activity up would not appear in that report. If a NetScaler Gateway or AAA virtual server has been internet-facing since before September 24, treat that date as confirmation the window extends at least that far back, not as the starting point for your compromise check: pull logs as far back as your retention allows and look for the same indicators CISA describes, rather than stopping at September 24. Separately, internet-scanning firm Censys counted approximately 42,735 NetScaler ADC and Gateway instances exposed to the internet worldwide as of September 28, 2026, according to Censys's own advisory, with the largest concentrations in the United States, Germany, the Netherlands, the United Kingdom, and Switzerland. NetScaler is not a niche appliance with limited exposure; confirming your own build number and exposure, rather than assuming this affects mostly other organizations, remains the priority.

What to Do Now

Identify every NetScaler ADC and NetScaler Gateway appliance your organization or your IT provider operates, and check its build number against the fixed releases above. CVE-2026-88771 affects every appliance on an affected build in its default configuration, so any appliance below the fixed builds needs the update applied immediately, regardless of how it is configured. Before you apply that update on an appliance that also has a Gateway or AAA virtual server (the configuration used for VPN, ICA proxy, or RDP proxy) reachable from the internet, take one extra step first: capture logs and run the available compromise indicators, since that combination is the specific path CISA says has already been exploited, and patching first can erase the evidence. If an appliance is still on NetScaler 12.1 or 13.0, plan an upgrade path immediately, since no fix exists on those branches. If your organization outsources network infrastructure to a managed service provider, ask directly for the build number and patch date of every NetScaler appliance in your environment and whether a compromise check was performed before patching, not a general assurance that "everything is up to date."

Why This Matters Beyond the Patch Itself

A remote-access gateway compromised before patching is the kind of incident that can sit undetected while an attacker moves further into a network, which is a materially different and more serious situation than simply being behind on an update. For businesses subject to the FTC Safeguards Rule or the HIPAA Security Rule, the same FTC Safeguards Rule guidance and HHS Office for Civil Rights guidance that applied to the NetScaler authentication-bypass flaw we covered earlier this month applies here too. The FTC Safeguards Rule requires nonbanking financial institutions to maintain a documented program that includes vulnerability monitoring under 16 CFR 314.4(d)(2), though institutions maintaining customer information on fewer than 5,000 consumers are exempt from that specific written risk-assessment and periodic vulnerability-testing requirement under 16 CFR 314.6. HHS Office for Civil Rights guidance is explicit that identifying and remediating known, actively exploited vulnerabilities in network infrastructure, including checking whether it was already exploited before the fix went in, is part of the HIPAA risk analysis obligation.

Cyber One Solutions can confirm your NetScaler build numbers, exposure, and patch status as part of our IT and security assessments. Our managed cybersecurity service continuously scans for and prioritizes vulnerabilities like these, tracks remediation to closure, and validates that a patch actually closed the gap; for appliances covered under a Managed IT agreement, that includes applying the patch itself.

Sources