CVE-2026-88771 & CVE-2026-88772: Citrix NetScaler Zero-Days

Citrix confirmed active exploitation of two NetScaler zero-days, CVE-2026-88771 and CVE-2026-88772, after a weekend of quiet shutdown warnings and NCSC pre-notifications. Here's the mechanism, who's affected, and the September 30 deadline.

CVE-2026-88771 & CVE-2026-88772: Citrix NetScaler Zero-Days

The weekend before Citrix confirmed anything, some administrators already knew something was wrong, without being told what. One posted that their IT supplier's security team called and advised shutting down their NetScalers immediately, no details given. The Dutch national cybersecurity agency, NCSC-NL, was sending private pre-notifications to affected organizations before any public disclosure. On September 26, watchTowr went public with what it called rapid reaction to rumors: multiple unpatched NetScaler remote code execution vulnerabilities already being exploited in the wild, with no CVE identifiers yet assigned because Citrix had not released any.

Citrix caught up the next day. On September 27, the company published security bulletin CTX697096 with official identifiers, CVE-2026-88771 and CVE-2026-88772, fixed builds, and direct confirmation: exploits of both on unmitigated NetScaler deployments have been observed. CISA added both to KEV the same day. The gap between quiet warnings and an actual fix was short, but it was long enough that watchTowr's guidance to clients was explicit about order of operations: preserve evidence before you patch, not after.

How They Work

CVE-2026-88771 is an improper input validation flaw, CWE-20. An unauthenticated attacker sends a crafted request and executes arbitrary commands remotely. What makes it unusually broad is scope: every NetScaler ADC and Gateway deployment is exposed, including default configurations, with no optional feature or specific setup required to be at risk. CVSS v4.0 score: 9.5 Critical.

CVE-2026-88772 is a memory overflow, CWE-119, leading to remote code execution or denial of service. It requires DTLS to be enabled, which sounds like a narrower condition until you know that DTLS is on by default on VPN virtual servers, meaning most Gateway deployments handling remote access are exposed without anyone having deliberately turned anything on. Also CVSS v4.0 9.5 Critical.

Both need only network access. No credentials, no user interaction.

Who Is Affected

NetScaler ADC before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; NetScaler Gateway before 14.1-73.37 and before 13.1-64.23. Fixed builds are 14.1-73.37 and 13.1-64.23 for standard deployments, with 13.1-37.279 covering FIPS and NDcPP configurations.

This CVE pair is fresh enough that NVD has not yet published CPE entries for either one, so the structured affected-platform data you'd normally see is still pending on the official side. Treat the version ranges above, straight from Citrix's own bulletin, as the authoritative source for now.

One operational detail worth knowing before you upgrade: a deployment running 13.1-6423 may enter a reboot loop during the update if NetScaler variables are configured. Run show ns variable first. If it returns results, plan for 13.1-6424 instead. The NetScaler Console may also temporarily misstate a 13.1-6423 build as still vulnerable after you've patched, which is worth knowing so you don't chase a false positive.

Why NetScaler Specifically

NetScaler ADC and Gateway sit at the network edge and typically carry VPN and remote access, authentication, application delivery, load balancing, and traffic management all on the same appliance. A successful compromise there does not hand an attacker one function, it hands them the junction point for several at once, which is exactly why the shutdown advice some organizations received over that weekend was not an overreaction. An edge device wearing that many hats is a stronghold for lateral movement and credential theft the moment it's compromised, not a peripheral system you get to later.

Citrix's bulletin actually covers eight CVEs in total, not two. CVE-2026-88773 through CVE-2026-88778 round out the disclosure: an HTTP request smuggling issue (CVSS 9.3), an HTTP URL policy bypass (7.0), three separate memory overflow conditions tied to Gateway services, Oracle-protocol load balancing, and non-HTTP Layer 7 deployments respectively (8.8 each), and a predictable TCP sequence number issue (8.8). None of the six have been reported as exploited, unlike -88771 and -88772. Worth patching all eight in the same maintenance window regardless, since the fixed builds are the same and the unexploited six today don't necessarily stay that way.

Reading These on VulnTracker

Both CVEs carry the Actively Exploited banner with Added-to-KEV and Remediation-Due dates side by side, currently September 27 and September 30. Each page's CVSS panel breaks out the individual vector components (attack vector, complexity, privileges, user interaction) rather than just the composite score, worth checking directly since CVE-2026-88771 scores low complexity while CVE-2026-88772 scores high complexity despite both landing at 9.5 overall. The CWE tags (CWE-20 for -88771, CWE-119 for -88772) and the Newsroom tab, which is actively collecting coverage as this story keeps developing, round out the picture. Track both to get notified once NVD publishes the CPE data that's currently still pending.

What to Do

watchTowr's guidance is specific about order, and it's worth following exactly as given rather than jumping straight to the patch: preserve forensic evidence first, meaning logs, snapshots, support bundles, and core dumps, before you touch anything. Then check for signs of compromise. Only then install the fixed build, 14.1-73.37 or 13.1-64.23 depending on your branch, or the FIPS/NDcPP equivalents. Rotate credentials after that. Patching first can overwrite the evidence you'd need to know whether you were already compromised before you got to it.

Run the IOC scan through NetScaler Console's Security Advisory workflow if you have version 14.1-73.36 or later with the telemetry it requires, or request indicators directly from Citrix Support if you don't. Citrix itself cautions these checks cannot cover every attacker technique, so forward logs to an external SIEM and use File Integrity Monitoring to catch unauthorized changes the generic IOCs might miss. Watch for the 13.1-6423 reboot loop if that's your current build, and patch all eight CVEs in the bulletin in the same pass rather than just the two currently reported as exploited.

The Takeaway

By the time most organizations had a CVE number to search for, this one had already been circulating as an unconfirmed rumor serious enough for national cybersecurity agencies to start making quiet phone calls. That gap between private warning and public confirmation is exactly where evidence gets overwritten if you patch on reflex instead of checking first. CVE-2026-88771 and CVE-2026-88772 are patched now, but the six other CVEs in the same bulletin, and the question of what already happened on your appliance before September 27, are still open.

Track CVE-2026-88771 and CVE-2026-88772 on VulnTracker to get notified as NVD finishes its analysis, as exploitation reports develop, or if any of the other six CVEs in the same bulletin get their own confirmed-exploited status.

References

Citrix Security Bulletin CTX697096 (September 27, 2026); NVD/CVE.org (CVE-2026-88771, CVE-2026-88772); CISA Known Exploited Vulnerabilities Catalog additions, September 27, 2026; watchTowr Intelligence, "Citrix NetScaler Zero-Day RCE FAQ: CVE-2026-88771 and CVE-2026-88772"; BleepingComputer, "Citrix admins warned to shut down NetScalers over 2 exploited zero-days."