If your organisation runs a Citrix NetScaler, this one’s for you. Attackers have been breaking into these boxes through two brand-new holes, and they started before Citrix had a fix out. That’s what people mean by a zero-day: a flaw the bad guys are using before the maker has had a single day to patch it.
The two holes are CVE-2026-88771 and CVE-2026-88772. A CVE is just the ID number the security world gives each known flaw. On 27 September 2026, the US cyber agency CISA put both on its Known Exploited Vulnerabilities catalog, the KEV. That’s CISA’s list of flaws it knows attackers are really using. Both entries carry a due date of 30 September 2026, under a rule called Binding Operational Directive 26-04. That’s Wednesday.

Citrix confirmed that same weekend that both holes were being used against unprotected machines. So this isn’t a gentle heads-up. It’s a box at the edge of the network, real attacks under way, eight flaws in one security notice, and a Wednesday deadline for US federal civilian agencies. I’ll walk you through it without turning it into a break-in guide.
If you’ve only got time for one pass before your next maintenance window, remember this order. Find every NetScaler ADC and Gateway your organisation runs itself. Check each one’s version against Citrix’s fixed list. If a box faced the internet while it was vulnerable, save the evidence first. Then upgrade. Everything else here is background.
What a NetScaler does at the edge
Citrix NetScaler ADC and Citrix NetScaler Gateway sit right where remote users meet a company’s apps. ADC stands for application delivery controller. That’s a fancy name for a box that shares traffic out across servers, which is called load balancing. The Gateway side runs the VPN, the secure tunnel staff use to get in from home, and it checks the logins of people who aren’t on the office network. When it’s been broken into, the attacker is already past the front door.
That’s why these edge boxes keep turning up on CISA’s KEV. Everything behind them is within reach. watchTowr, a security firm, says it plainly in its FAQ: a compromised NetScaler gives an attacker a foothold at the edge of the network and a path to the systems inside. Adam Marre, the chief information security officer at the security company Arctic Wolf, gave Cybersecurity Dive the government angle. He said these are exactly the kind of flaws that “keep government security leaders up at night because they target the systems agencies depend on to connect users, provide services and secure access.” The box matters because of where it sits.
This story covers what the companies and agencies published over the weekend. It’s not about how to copy an attack. If you came here for a recipe, you’re in the wrong place. Read Citrix’s notice, CTX697096, and check your own settings instead.
How the weekend played out
On Saturday 26 September 2026, before the flaws had public ID numbers, watchTowr warned that unpatched NetScaler flaws were being used in the wild to run attackers’ code remotely. Security people call that remote code execution, or RCE. watchTowr said the information was credible, that it came from forensic investigations, and that Citrix patches were expected early the following week.
Cybersecurity Dive reports that on that Saturday, security teams got urgent phone calls telling them to disconnect their servers straight away, before Citrix or any government had said anything in public. BleepingComputer tells the same story. It says national cyber agencies, IT suppliers and security teams were privately telling Citrix customers to shut their NetScalers down.
Yordan Ganchev, a principal threat intelligence specialist at watchTowr, told Cybersecurity Dive where the panic came from. “The urgency stemmed from the discovery that two previously unknown vulnerabilities were being actively exploited in the wild,” he said. “At the time, it was unclear whether they were being chained together, but the technical details now indicate they are independent of each other.” So an attacker doesn’t need both. That fits how Citrix and CISA later described CVE-2026-88771 and CVE-2026-88772. Each one can lead to remote code execution on its own.
There was also a warning from the Dutch National Cyber Security Centre, known as NCSC-NL. BleepingComputer reports it sent a private early notice to organisations in the Netherlands. That notice isn’t on a public webpage that outsiders can check. When BleepingComputer asked about it in a 27 September story, the centre said, “As you’re not part of our constituency, we cannot disclose any further information at this time.” So treat the Dutch part as reported, not as a document you can click on and read yourself. The public trail you can pin to named pages starts with watchTowr’s warning on 26 September and Citrix’s notice on 27 September.
On Sunday 27 September, Citrix published security bulletin CTX697096. It covers eight flaws, CVE-2026-88771 through CVE-2026-88778. The company said it had seen CVE-2026-88771 and CVE-2026-88772 being exploited on unprotected NetScalers, and it urged customers to install the fixed versions as soon as possible. The bulletin’s change log shows it first went up that day, with a second update the same day adding a link to a NetScaler blog post with more context.
The same day, CISA backed up the warning. It said it had received reports and partner threat intelligence confirming that attackers were actively exploiting those two flaws around the world, and it added both to the KEV. CISA revised its alert on 28 September. Sergiu Gatlan’s BleepingComputer story that day is the easiest place to see the KEV listing tied to the Wednesday federal deadline, if you don’t read the catalog’s raw data feed.
For readers here in Adelaide, the clock shifts. CISA’s catalog feed shows its 27 September update going out at 21:30 UTC, which was 7am on Monday 28 September in Adelaide. So the US Sunday news landed on Monday morning here.

The two flaws on the KEV, and the six that came with them
Start with the two that made CISA’s list. They’re the ones with the Wednesday deadline. The other six came in the same Citrix notice. Don’t mix up “in the bulletin” with “on the KEV.”
Quick decoder: CVSS scores how bad a flaw is, from 0 to 10, and 9 or above counts as critical. CWE is a category number for the type of coding mistake.
CVE-2026-88771 is an input-checking mistake. The box doesn’t properly check what it’s being sent, and that can let an attacker run their own commands without logging in. Citrix’s condition for this one is the scary part: all NetScaler ADC and NetScaler Gateway setups, straight out of the box, no extra feature needed. Citrix files it as CWE-20. It scores 9.5 on version 4.0 of CVSS.
CVE-2026-88772 is a memory overflow, where the software writes past the edge of the memory it’s meant to use. That can lead to remote code execution, or to a denial of service, which means knocking the box over. It only applies when DTLS is switched on, and Citrix says DTLS is on by default on VPN virtual servers. It’s CWE-119, and it also scores 9.5. Citrix and CISA both say an attacker can use either flaw alone.
CISA’s short KEV descriptions split them the same way. It calls 88771 an improper input validation flaw that could let an unauthenticated attacker run arbitrary commands. It calls 88772 an improper restriction of operations within the bounds of a memory buffer, which could allow remote code execution or denial of service. Both entries list ransomware use as “Unknown” and forensic triage as “Yes.”
Citrix calls 88771 a CWE-20 flaw, but CISA’s KEV feed lists it as CWE-119, and I’ve gone with Citrix. Separately, the KEV feed’s notes for 88771 include a link to the NVD, the US government’s flaw database, that points at CVE-2026-88772 instead. That looks like a typo in the feed, not a sign the two are the same bug.
One more thing. None of the sources I checked says whether attackers land with “root” access, the top-level admin control of the box. What they do say is that attackers can run their own commands or code on it. That’s bad enough.
The same bulletin fixes six more flaws. Here are Citrix’s scores and conditions, in short:
- CVE-2026-88773: HTTP request smuggling, a trick where confusingly built web requests slip past checks. Applies when HTTP is set up on the ADC or Gateway. CVSS 9.3. CWE-444. None of the sources I read report it being exploited.
- CVE-2026-88774: a way around policy rules that are written using web addresses. CVSS 7.0. It only matters if you’ve set up those rules.
- CVE-2026-88775: a memory overflow that can knock the box over, on Gateway or AAA virtual server setups. AAA is the part that checks logins. CVSS 8.8.
- CVE-2026-88776: a memory overflow when a load-balancing virtual server of the Oracle type is set up. CVSS 8.8.
- CVE-2026-88777: a memory overflow on certain setups that handle non-web traffic, like FTP, or the carrier-style address sharing known as CGNAT. CVSS 8.8.
- CVE-2026-88778: TCP initial sequence number prediction. In plain words, an attacker could guess the numbers the box uses to keep network connections straight. CVSS 8.8. Citrix says to fix it with a TCP setting change called Enhanced ISN Generation. watchTowr adds that the upgrade alone doesn’t close it.
In everything I checked, only 88771 and 88772 are described as exploited, and only those two are on the KEV. The other six still matter when you plan patches and review settings. They just aren’t on the Wednesday list. If your change board only signed off on “the KEV ones,” make sure somebody still owns the 88778 setting and the memory issues that depend on how the box is set up.
Who’s affected, and the versions that fix it
Citrix’s list of affected versions, for the releases it still supports, is clear:
- NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
- NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
- NetScaler ADC FIPS before 14.1-73.37 FIPS
- NetScaler ADC FIPS and NDcPP before 13.1-37.279
FIPS and NDcPP are special editions certified against government security standards. Here are the fixed versions Citrix lists:
- 14.1-73.37 and later
- 13.1-64.23 and later releases of 13.1
- 14.1-73.37 FIPS and later of 14.1-FIPS
- 13.1-37.279 and later of 13.1-FIPS and 13.1-NDcPP
Secure Private Access hybrid setups that use NetScalers the customer runs are covered too, and those NetScalers need upgrading.
Versions 12.1 and 13.0 are end-of-life, which means Citrix no longer supports them. BleepingComputer reports Citrix’s advice is to move those boxes to a supported version. They don’t get security updates anymore. If your organisation still has a 12.1 Gateway because “it still works,” this weekend is one more reason that’s not a plan.
One practical tip comes from watchTowr’s FAQ, not from Citrix’s own table. On 13.1, if the command show ns variable returns any variables, watchTowr says to use 13.1-64.24 to avoid a known reboot loop during the upgrade. That’s watchTowr’s advice on top of Citrix’s 13.1-64.23 minimum, so check with your support channel before you treat 64.24 as a must. The minimum in CTX697096 is still 13.1-64.23 and later.

The DTLS catch, and why 88772 doesn’t hit everyone the same way
CVE-2026-88771 doesn’t need any special feature turned on. A box set up the default way is exposed. If the box runs an affected version, you’re exposed to 88771 even if you never ticked a single optional box.
CVE-2026-88772 does have a condition. Citrix says DTLS has to be switched on for the ADC or Gateway, and it notes DTLS is on by default for VPN virtual servers unless someone turned it off. So Gateway and VPN boxes deserve a hard look, even if someone on your team swears the box is “just load balancing.” Check the settings it’s actually running.
So what’s DTLS? Cybersecurity Dive, citing a Huntress Labs blog post, describes it as a security protocol that keeps data safe while it travels across networks in small chunks called datagrams, so it stays private in real time. Handy background, but no reason to skip Citrix’s own condition text in CTX697096, which lists the setting patterns admins should look for. I’m not going to paste a how-to for testing DTLS from the open internet.
Check for a break-in before you patch
CISA’s alert is blunt. If you can, check for signs of a break-in before you patch. If you think you’ve been hit, save the forensic evidence before you apply updates, because updates can wipe the traces you need. Citrix has a separate article called “Steps to Take if NetScaler ADC is Suspected to be Compromised.” It’s CTX694799, and the KEV entries link to it. Citrix has also put indicators of compromise, or IoCs, into its NetScaler Console tool. IoCs are the telltale signs, like odd files or odd traffic, that suggest someone got in.
Citrix also warned, in words BleepingComputer quotes, that these general IoCs “might be of limited forensic value and might fail to identify actual compromises.” It advised customers “to retain the services of experienced forensic investigators.” watchTowr’s FAQ makes the same point. The IoCs don’t cover every technique, so a clean scan isn’t proof.
CIRCL, Luxembourg’s national computer emergency team, draws a line you’ll want in your change ticket. Patching stops new attacks through the fixed flaws. It doesn’t remove anything an attacker already left behind, like a hidden way back in, which experts call persistence. CIRCL lists the dull but necessary work. Save logs and evidence where you can. Review NetScaler logs and outside network logs. Look for unexpected changes to settings, files or running programs. Review admin and login activity. Watch for traffic from the box toward your internal systems. Use Citrix’s indicators. And follow your incident plan if you think you’ve been hit. CIRCL also strongly recommends sending NetScaler logs to a SIEM, a separate log-collecting system the box doesn’t control. That way the evidence survives even if the box can’t be trusted.
In the KEV data, both flaws have forensic triage set to “Yes,” and the entries point to CISA’s guidance for BOD 26-04. Forensic triage just means a first check for whether the box was broken into. So agencies aren’t being told to patch and forget. The check is part of the job, and private companies should copy that habit.
Exposure maps, and what Shadowserver’s numbers do and don’t show
BleepingComputer reports that the threat watchdog Shadowserver, which keeps an eye on devices exposed online, tracks over 23,000 IP addresses with NetScaler fingerprints online. That’s nearly 22,000 ADC appliances and just over 1,500 Gateway instances. Cybersecurity Dive gives Shadowserver’s figure as more than 20,000, so the two reports don’t quite match. Neither number counts boxes confirmed to be vulnerable. BleepingComputer adds that there’s no information on how many are honeypots, which are decoy machines set up to catch attackers, how many are already patched, or how many have vulnerable settings.
Cybersecurity Dive also reports researchers saying there have been compromises, but that the confirmed cases aren’t widespread. Citrix and CISA have both confirmed active attacks, and that’s reason enough to move. Use the map to see how much is exposed. Don’t use it as a count of victims. And don’t treat “not widespread” as permission to wait past Wednesday if you’re on the federal deadline.

BOD 26-04 and the Wednesday deadline
CISA’s 27 September KEV alert names BOD 26-04, “Prioritizing Security Updates Based on Risk,” as the federal rule that applies. A binding operational directive is an order US federal agencies have to follow. This one covers Federal Civilian Executive Branch agencies, the everyday non-military government departments. It tells them to fix KEV flaws fast on internet-facing systems where an attack gives “total control” of the system. It also sets out when they must check whether attackers got in before the patch went on. Lower-risk flaws can wait. These two didn’t go in the “wait” pile.
For these two flaws, the KEV feed itself sets the due date as 30 September 2026. That’s Wednesday, three days after they were added. The “required action” text on both entries tells agencies to follow Citrix’s fixes, BOD 26-04 and CISA’s forensic triage requirements. It also says each organisation is responsible for checking how exposed each of its systems is to the internet. CISA still encourages every other organisation to take the same risk-based approach, even though BOD 26-04 only legally binds federal civilian agencies.
For Adelaide readers, Wednesday 30 September 2026 is the US federal date on the notice. Your own change window still has to follow Citrix’s version list and the evidence-first advice. If you’re not a US federal agency, you’ve still got Citrix saying “as soon as possible” and CISA urging every organisation to put KEV flaws first. The federal deadline is just the loudest clock in the room.
European notes you can check, and one you mostly can’t
The CSSF, Luxembourg’s financial regulator, published a note on 28 September. It said it was aware of the eight flaws, that 88771 and 88772 are being exploited in the wild, and that the firms it supervises should take action. It pointed them to CIRCL’s public report, TR-100. The CSSF also reminded those firms that unauthenticated remote code execution counts as unauthorised malicious access. That makes it a major ICT-related incident, meaning a serious IT incident, and it has to be reported under one of two CSSF circulars, depending on the type of firm. That’s a legal rule, not a technical one, but it helps explain why some European teams moved fast.
CIRCL’s TR-100 matches Citrix on the fixed versions. It stresses checking internet-facing boxes for a break-in, and it says a successful upgrade doesn’t prove the box was clean beforehand. If you need a public European technical note that tracks Citrix’s table closely, TR-100 is the one you can cite with confidence.
BleepingComputer reports that CERT-EU, the cyber security service for the European Union’s own institutions, “strongly” advised EU organisations to “run a compromise assessment on any internet-facing appliance running an affected build.” But the public CERT-EU advisory numbered 2026-010 is about the earlier August NetScaler pair, CVE-2026-19489 and CVE-2026-19490, not this weekend’s eight. So for this bulletin, CERT-EU’s advice reaches us through BleepingComputer, unless CERT-EU posts a matching public advisory for 88771 and 88772. Don’t paste 2026-010 into a ticket as if it covered Sunday’s notice.
NetScaler’s track record on the KEV
BleepingComputer notes that since November 2021, CISA has flagged 26 actively exploited Citrix flaws, including six abused by ransomware gangs. The same story reminds readers that NetScaler flaws were already under attack earlier in 2026. In March, Citrix urged admins to patch CVE-2026-3055 and CVE-2026-4368, days before attackers started abusing them. Then in early September, attackers began exploiting CVE-2026-19490, a flaw that lets them get around the login check, which had been patched in mid-August.
watchTowr’s FAQ is clear that boxes patched for CVE-2026-19490 are still exposed to 88771 and 88772 unless they’re on this weekend’s fixed versions. Don’t assume last month’s emergency patch covered this one. CERT-EU’s August 2026-010 note is useful history for that earlier pair. It isn’t proof you’ve patched Sunday’s flaws.
Both new KEV entries list ransomware use as “Unknown.” That’s not an all-clear. It just means the catalog doesn’t have a confirmed ransomware campaign tied to these flaws yet. Read that field the way I always ask you to. No tag doesn’t mean no risk.
Cloud versus boxes you run yourself
Citrix’s notice draws a clear line. It only applies to NetScaler ADC and Gateway boxes that customers run themselves, and for those, the upgrade is on you. Citrix’s own cloud services and its Adaptive Authentication service are upgraded by its parent company, Cloud Software Group. So when someone asks, “Did the vendor already update us?” the answer for a box you run is no until you change the version. Secure Private Access hybrid setups still need their customer-run NetScalers moved to the recommended versions.
A single Slack message saying “Citrix said they patched cloud” doesn’t fix an on-site Gateway that’s been facing the internet all weekend. Two lists. Two owners.
What to do, in order
These aren’t attack steps. They’re the order of work, drawn from the public advice:
- Find every NetScaler ADC and Gateway you run yourself. That includes the forgotten pair in the DMZ, the buffer zone between the internet and your internal network, and any hybrid Secure Private Access instances.
- Check each version against CTX697096’s affected and fixed lists. If you’re on end-of-life 12.1 or 13.0, the answer is to move to a supported version, not to wait for a fix.
- If the box could be reached from the internet while it was vulnerable, save logs, snapshots, support bundles and anything else your incident plan calls for before you overwrite it.
- Use Citrix’s IoCs in NetScaler Console if you can, knowing Citrix itself says they’re limited.
- Install the fixed version for your release. On 13.1, keep watchTowr’s 64.24 tip in mind if variables are present, and confirm with support.
- For CVE-2026-88778, turn on Enhanced ISN Generation the way Citrix describes, because the upgrade alone doesn’t close that one.
- Change the passwords, secrets and certificates stored on or used through the box, as watchTowr advises, and keep the management screens off the public internet.
That list is my reading of Citrix, CISA, CIRCL and watchTowr, not a new procedure made up for this story.
What’s still missing
None of the public material I checked from Citrix, CISA, CIRCL, the CSSF or watchTowr names the attackers, and I’m not going to guess. watchTowr says no attribution has been made public.
I haven’t found a public proof-of-concept, which means working attack code, in any of the main sources. This story won’t supply one.
Primary sources
CISA, 27 September 2026 (revised 28 September). Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway. https://www.cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway
CISA, 27 September 2026. CISA Adds Two Known Exploited Vulnerabilities to Catalog. https://www.cisa.gov/news-events/alerts/2026/09/27/cisa-adds-two-known-exploited-vulnerabilities-catalog
CISA Known Exploited Vulnerabilities catalog data feed, catalog version 2026.09.27. Entries for CVE-2026-88771 and CVE-2026-88772, due date 2026-09-30, forensic triage Yes. https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Citrix / Cloud Software Group, CTX697096, first published 27 September 2026. Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778. https://support.citrix.com/external/article/CTX697096/citrix-netscaler-adc-and-citrix-netscale.html
BleepingComputer, Sergiu Gatlan, 28 September 2026. CISA orders feds to patch exploited Citrix flaws by Wednesday. https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-exploited-citrix-flaws-by-wednesday/
BleepingComputer, Lawrence Abrams, 27 September 2026. Citrix confirms two NetScaler RCE zero-days exploited in attacks. https://www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/
watchTowr, 27 September 2026. Citrix NetScaler Zero-Days FAQ: CVE-2026-88771 and CVE-2026-88772. https://watchtowr.com/intelligence/citrix-netscaler-zero-day-vulnerabilities-faq/
Cybersecurity Dive, David Jones, 28 September 2026. Citrix urges immediate upgrades of NetScaler amid widespread exploitation attempts. https://www.cybersecuritydive.com/news/citrix-upgrades-netscaler-exploitation/831502/
CSSF Luxembourg, 28 September 2026. Multiple Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway. https://www.cssf.lu/en/2026/09/multiple-critical-vulnerabilities-in-citrix-netscaler-adc-and-netscaler-gateway/
CIRCL, TR-100. Multiple Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway. https://www.circl.lu/pub/tr-100/
CISA, BOD 26-04: Prioritizing Security Updates Based on Risk. https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
Bottom line
Two critical holes in Citrix NetScaler, CVE-2026-88771 and CVE-2026-88772, were used by attackers as zero-days. Citrix confirmed that on 27 September, CISA backed it up the same day, and US federal agencies got a KEV due date of 30 September 2026. Six more flaws came in the same bulletin. The fixed versions start at 14.1-73.37 and 13.1-64.23, with matching FIPS and NDcPP versions. Boxes on end-of-life 12.1 and 13.0 need moving, not hoping. Save the evidence before you patch if you can. Treat a clean IoC scan in NetScaler Console as limited, not final. And keep the break-in details off this page. Citrix and the agencies have already published what admins need to close the holes.





The paper
Comments
No notes on this story yet.
Sign in to comment