Citrix Patches Eight NetScaler Flaws, Two Exploited for Remote Code Execution
Security / news
Citrix Patches Eight NetScaler Flaws, Two Exploited for Remote Code Execution
CVE-2026-88771 and CVE-2026-88772 are both rated 9.5, and a researcher warning preceded Citrix's own bulletin by a day.

Citrix said on Sept. 27 that attackers have exploited two remote code execution flaws in NetScaler ADC and NetScaler Gateway, CVE-2026-88771 and CVE-2026-88772, each rated 9.5. The fix is an upgrade to build 14.1-73.37 or 13.1-64.23, and the researchers who published the first warning say there is no workaround.
Citrix's bulletin, CTX697096, covers eight CVEs, CVE-2026-88771 through CVE-2026-88778. Its wording on exploitation is narrow: "Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed." CISA added both to its Known Exploited Vulnerabilities catalog the same day and wrote that "threat actors are actively exploiting these vulnerabilities globally."

What an attacker needs for CVE-2026-88771 and CVE-2026-88772
CVE-2026-88771 is an improper input validation flaw. watchTowr describes it as letting an unauthenticated attacker run arbitrary commands, and says it affects default configurations with no optional feature switched on.
CVE-2026-88772 is a memory overflow that leads to remote code execution or denial of service when DTLS is enabled. watchTowr says DTLS is on by default for VPN virtual servers, so most Gateway deployments meet the condition unless an administrator disabled it.
The other six flaws depend on configuration. Citrix's bulletin ties them to conditions such as HTTP virtual servers and Oracle load-balancing virtual servers, and none of the six is listed as exploited.
| CVE | Flaw | CVSS |
|---|---|---|
| CVE-2026-88771 | Improper input validation, remote code execution | 9.5 |
| CVE-2026-88772 | Memory overflow with DTLS enabled | 9.5 |
| CVE-2026-88773 | HTTP request smuggling | 9.3 |
| CVE-2026-88774 | Policy bypass with HTTP URL expressions | 7.0 |
| CVE-2026-88775 to CVE-2026-88777 | Memory overflow, one entry each | 8.8 |
| CVE-2026-88778 | TCP initial sequence number prediction | 8.8 |
- CVE-2026-887719.5 CVSS
- CVE-2026-887729.5 CVSS
- CVE-2026-887739.3 CVSS
- CVE-2026-887758.8 CVSS
- CVE-2026-887788.8 CVSS
- CVE-2026-887747 CVSS
Source: Citrix bulletin CTX697096, accessed 2026-09-29
The score does little work here. For CVE-2026-88771 the conditions are a reachable appliance and a default configuration, so the 9.5 describes the exposure about as well as the preconditions do.
Timeline from Sept. 26 to Sept. 27
- Sept. 26: watchTowr said it told clients about their NetScaler exposure "before Citrix's bulletin and CVE IDs existed" and publicly warned of unpatched remote code execution being exploited.
- Sept. 27: Citrix published CTX697096 with the fixed builds, and CISA added CVE-2026-88771 and CVE-2026-88772 to the catalog.
That ordering means an operator watching only vendor advisories learned of exploitation after a research firm already had.
Which NetScaler builds to install
Vulnerable builds are NetScaler 14.1 before 14.1-73.37 and 13.1 before 13.1-64.23. The FIPS lines have their own floors: 14.1-FIPS before 14.1-73.37 FIPS and 13.1-FIPS and NDcPP before 13.1-37.279.
Both CISA and watchTowr say to preserve evidence before upgrading. watchTowr lists logs, snapshots, support bundles and core dumps, and CISA warns that patching may affect forensic visibility. Citrix offers an indicator-of-compromise scan through NetScaler Console, available on 14.1-73.36 or later with telemetry enabled, and warns that a clean result is not proof an appliance was not compromised.
CVE-2026-88778 needs a separate step. Citrix tells customers to check the Enhanced ISN Generation TCP parameter and enable it, so an upgrade alone does not close that one.
The edge-appliance list on this desk keeps growing: Check Point patched two 9.8-rated flaws under attack, and F5's BIG-IP APM zero-day was exploited before its hotfix shipped.
Citrix's bulletin gives no count of compromised appliances, and watchTowr's FAQ gives no count of exposed ones. Neither figure has been published as of Sept. 29.
Sources
More in Security
- 01Fortinet FortiMail Path-Traversal Flaw Exploited Before Fixes ShipCVE-2026-104286 lets an unauthenticated attacker write files to a FortiMail appliance, and one analyst reading of Fortinet's advisory says the patched builds may not be downloadable yet.
- 02Citrix Confirms Two NetScaler Zero-Days Exploited Since Early SeptemberPalo Alto Networks' Unit 42 traces exploitation of CVE-2026-88771 and CVE-2026-88772 to Sept. 4, 23 days before Citrix published its bulletin, and says patching will not evict an attacker who is already inside.
- 03Cisco SD-WAN Manager Auth Bypass Exploited, With No WorkaroundCVE-2026-76504 gives an unauthenticated attacker admin access to the Catalyst SD-WAN Manager API, and Cisco's only advice besides patching is to keep the interface off untrusted networks.
- 04Three Exploited Edge Flaws Test CISA's Three-Day Patch DeadlineCitrix, Cisco and Fortinet appliances landed in the Known Exploited Vulnerabilities catalog within five days, and BOD 26-04 asks agencies to collect evidence before they patch any of them.