CTIPilot

Citrix NetScaler ADC/Gateway predictable TCP ISN, CTX697096, not reported exploited, CVSS4.0 8.8

cve · CVE-2026-88778

Coverage timeline
1
first 2026-09-28 → last 2026-09-28
Peak priority
critical
1 critical
Sources cited
7
7 hosts
Sections touched
1
deep-dive
Co-occurring entities
8
see Co-occurring entities below
ATT&CK techniques
1
pinned v19.2 · see below

ATT&CK techniques

1 technique observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-09-28/cve-2026-88771-citrix-netscaler-preauth-rce-zero-day-kev · ATT&CK page ↗

Story timeline

  1. 2026-09-28CVE-2026-88771 / CVE-2026-88772, Citrix NetScaler ADC and Gateway: unauthenticated pre-auth RCE zero-days exploited before a patch existed (CVSS 4.0 9.5)
    deep-diveCitrix confirms in-the-wild exploitation of two default-configuration NetScaler zero-days; CISA gives a three-day KEV deadline

Where this entity is cited

  • deep-dive1

Source distribution

  • advisories.ncsc.nl1 (14%)
  • bleepingcomputer.com1 (14%)
  • cert.at1 (14%)
  • cert.europa.eu1 (14%)
  • cisa.gov1 (14%)
  • support.citrix.com1 (14%)
  • watchtowr.com1 (14%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Citrix NetScaler ADC/Gateway predictable TCP ISN, CTX697096, not reported exploited, CVSS4.0 8.8 (1)

2026-09-28 · view entry permalink →

CRITICALCVE-2026-88771 +7exploitedNATOA1

CVE-2026-88771 / CVE-2026-88772, Citrix NetScaler ADC and Gateway: unauthenticated pre-auth RCE zero-days exploited before a patch existed (CVSS 4.0 9.5)

Citrix's security bulletin CTX697096, published 2026-09-27, fixes eight NetScaler ADC / NetScaler Gateway vulnerabilities, two of which were already being exploited as zero-days before any fix existed (Citrix, 2026-09-27). CVE-2026-88771 (CWE-20, improper input validation, CVSS 4.0 9.5) lets an unauthenticated remote attacker execute arbitrary commands on every NetScaler ADC/Gateway deployment in its default configuration; no feature needs to be enabled first. CVE-2026-88772 (CWE-119, memory overflow to RCE or DoS, CVSS 4.0 9.5) is reachable wherever DTLS is enabled, which Citrix states is the default on any VPN virtual server, so most VPN-fronting Gateway deployments meet the precondition unless DTLS was explicitly disabled. Citrix's own bulletin states plainly: "Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed" (Citrix, 2026-09-27). CISA added both to its Known Exploited Vulnerabilities catalog on 2026-09-27 with a 2026-09-30 remediation due date, requiring compliance with BOD 26-04 forensic-triage guidance (CISA Known Exploited Vulnerabilities Catalog, 2026-09-27), and CERT-EU's advisory the same day states "Citrix has confirmed active exploitation of these 2 critical vulnerabilities in the wild" and recommends a compromise assessment on every internet-facing appliance (CERT-EU, 2026-09-27).

The disclosure path itself is a defender-relevant data point. NetScaler administrators reported being told by IT suppliers and security teams to shut appliances down over the weekend of 26-27 September, before any CVE identifier or vendor advisory existed, tracing to a pre-notification NCSC-NL reportedly sent to its constituency; NCSC-NL declined to confirm the leaked notice's contents to BleepingComputer (BleepingComputer, 2026-09-27) but published its own public advisory NCSC-2026-0394 the same day once Citrix's bulletin shipped (NCSC-NL, 2026-09-27). watchTowr independently and publicly flagged credible rumors of unpatched, in-the-wild NetScaler RCEs on 2026-09-26, a day ahead of Citrix's own bulletin. No public attribution of the exploiting activity exists; watchTowr's FAQ states "No attribution has been made public," while noting NetScaler perimeter appliances have historically been targeted by both state-sponsored and ransomware-affiliated actors, consistent with the CitrixBleed (CVE-2023-4966) and CitrixBleed 2 (CVE-2025-5777) history on the same product line (watchTowr, 2026-09-27).

The same bulletin fixes six configuration-dependent companion flaws not reported exploited: an HTTP request-smuggling flaw (CVE-2026-88773, CVSS 9.3), a policy-bypass flaw via HTTP URL-based expressions (CVE-2026-88774, CVSS 7.0), three further memory-overflow conditions gated respectively on a Gateway/AAA virtual server, an Oracle-type load-balancing virtual server, or a non-HTTP Layer-7 protocol on an LB/CS/CGNAT-LSN/NAT64 device (CVE-2026-88775/88776/88777, each CVSS 8.8), and a predictable-TCP-ISN weakness (CVE-2026-88778, CVSS 8.8) whose remediation is not covered by the version upgrade alone: it additionally requires enabling Enhanced ISN Generation. This is a distinct CVE family from CVE-2026-19490 and from the CitrixBleed/CitrixBleed 2 lineage named above; watchTowr states directly that appliances already patched for CVE-2026-19490 remain vulnerable to CVE-2026-88771/88772 unless running one of the new fixed builds (watchTowr, 2026-09-27). Fixed builds are 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS and 13.1-37.279 (FIPS/NDcPP); watchTowr flags an upgrade caveat on the 13.1 branch: run show ns variable first, and if it returns any variables, install 13.1-64.24 instead to avoid a known reboot loop during the upgrade.

Detection and hunting. No workaround exists for the two exploited flaws, so the priority is upgrading, not mitigating in place. Before patching, capture logs, a configuration snapshot, a support bundle and a core dump from every appliance that has been internet-facing, since the upgrade can overwrite forensic evidence of prior compromise; CISA's guidance under BOD 26-04 recommends the same sequence (CISA Known Exploited Vulnerabilities Catalog, 2026-09-27). A limited IOC scan is available from 14.1-73.36+ with telemetry enabled via the NetScaler Console Security Advisory page or through Citrix Support, but Citrix itself cautions the indicators do not cover every exploitation technique (watchTowr, 2026-09-27), so a clean scan is not proof an appliance was not already compromised before patching; a compromise assessment (authentication logs for anomalous sessions, unexpected configuration changes, unfamiliar scheduled tasks or processes on the management plane) is the only way to build that confidence.

Triage: the discriminator for CVE-2026-88771 is that no legitimate administrative or user path reaches the vulnerable input-validation code path without a valid session: any successful, unauthenticated command execution on the appliance is the signal, not a benign lookalike to rule out. For CVE-2026-88772, DTLS handling anomalies (crashes, unexpected restarts, or malformed-record errors in VPN vServer logs) on an appliance where DTLS was not deliberately disabled are the discriminator worth hunting for, since legitimate DTLS traffic does not trigger the memory-overflow condition.

Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed.

A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands

Citrix (Cloud Software Group) 2026-09-27

Citrix has confirmed active exploitation of these 2 critical vulnerabilities in the wild.

CERT-EU 2026-09-27

No attribution has been made public.

watchTowr 2026-09-27

Builds on: 2026-08-20/cve-2026-19490-netscaler-gateway-aaa-auth-bypass · 2026-07-01/cve-2026-8451-citrix-netscaler-adc-gateway-pre-auth-saml-mem

vulnerability28 Sep 04:04Zmulti-sourceOpen finding ↗