---
schema: 1
kind: vulnerability
title: "CVE-2026-88771 / CVE-2026-88772, Citrix NetScaler ADC and Gateway: unauthenticated pre-auth RCE zero-days exploited before a patch existed (CVSS 4.0 9.5)"
headline: "Citrix confirms in-the-wild exploitation of two default-configuration NetScaler zero-days; CISA gives a three-day KEV deadline"
summary: >
  Citrix's CTX697096 bulletin (2026-09-27) fixes eight NetScaler ADC/Gateway flaws, two of which, CVE-2026-88771
  (unauthenticated command execution, every default deployment) and CVE-2026-88772 (memory overflow to RCE/DoS,
  reachable wherever DTLS is enabled, the VPN-vServer default), were already being exploited in the wild before any
  fix existed. CISA added both to KEV the same day with a three-day remediation deadline; no workaround exists.
discovered_at: "2026-09-28T04:04:46Z"
updated_at: null
event_date: "2026-09-27"
run_id: 2026-09-28T0404Z-intel
priority: critical
immediate_action:
  title: "Patch every internet-facing NetScaler ADC/Gateway now: no workaround exists"
  action: >
    Citrix confirms CVE-2026-88771 and CVE-2026-88772 are being exploited against unmitigated NetScaler ADC and
    NetScaler Gateway appliances right now. CVE-2026-88771 requires no configuration at all: every default
    deployment is reachable by an unauthenticated attacker; CVE-2026-88772 is reachable wherever DTLS is enabled,
    which Citrix states is the default on any VPN virtual server. There is no mitigation short of upgrading: capture
    forensic evidence (logs, a configuration snapshot, a support bundle, a core dump) from each exposed appliance
    before patching, since the upgrade itself can destroy evidence of prior compromise, then upgrade to 14.1-73.37+
    or 13.1-64.23+ (run `show ns variable` first on 13.1; if it returns any variables, install 13.1-64.24 instead
    to avoid a known reboot loop) and run a compromise assessment on every appliance that was internet-facing.
tags: [vulnerabilities, rce, pre-auth, default-config, actively-exploited, cisa-kev, zero-day]
regions: [global, europe, switzerland]
sectors: [public-sector]
entities: [product:citrix-netscaler]
techniques: [T1190]
affected_products: ["Citrix NetScaler ADC", "Citrix NetScaler Gateway"]
cves:
  - id: CVE-2026-88771
    cvss: "9.5"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status: [exploited, cisa-kev, patch-available]
    affected: "All NetScaler ADC/Gateway releases before the fixed builds (default configuration, no feature required)"
    fixed: "14.1-73.37; 13.1-64.23 (13.1-64.24 if `show ns variable` returns entries); 14.1-73.37 FIPS; 13.1-37.279 FIPS/NDcPP"
  - id: CVE-2026-88772
    cvss: "9.5"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status: [exploited, cisa-kev, patch-available]
    affected: "Releases with DTLS enabled (default state on any VPN virtual server) before the fixed builds"
    fixed: "14.1-73.37; 13.1-64.23; 14.1-73.37 FIPS; 13.1-37.279 FIPS/NDcPP"
  - id: CVE-2026-88773
    cvss: "9.3"
    epss: null
    type: logic-flaw
    vector: zero-click
    auth: pre-auth
    status: [patch-available]
    affected: "Releases with HTTP configuration enabled before the fixed builds; not reported exploited"
    fixed: "14.1-73.37; 13.1-64.23; 14.1-73.37 FIPS; 13.1-37.279 FIPS/NDcPP"
  - id: CVE-2026-88774
    cvss: "7.0"
    epss: null
    type: logic-flaw
    vector: zero-click
    auth: pre-auth
    status: [patch-available]
    affected: "Any policy expression configured with an HTTP URL-based expression; not reported exploited"
    fixed: "14.1-73.37; 13.1-64.23; 14.1-73.37 FIPS; 13.1-37.279 FIPS/NDcPP"
  - id: CVE-2026-88775
    cvss: "8.8"
    epss: null
    type: memory-corruption
    vector: zero-click
    auth: pre-auth
    status: [patch-available]
    affected: "Configured as Gateway (SSL VPN/ICA Proxy/CVPN/RDP Proxy) or an AAA virtual server; not reported exploited"
    fixed: "14.1-73.37; 13.1-64.23; 14.1-73.37 FIPS; 13.1-37.279 FIPS/NDcPP"
  - id: CVE-2026-88776
    cvss: "8.8"
    epss: null
    type: memory-corruption
    vector: zero-click
    auth: pre-auth
    status: [patch-available]
    affected: "Configured as an Oracle-type load-balancing virtual server; not reported exploited"
    fixed: "14.1-73.37; 13.1-64.23; 14.1-73.37 FIPS; 13.1-37.279 FIPS/NDcPP"
  - id: CVE-2026-88777
    cvss: "8.8"
    epss: null
    type: memory-corruption
    vector: zero-click
    auth: pre-auth
    status: [patch-available]
    affected: "Configured as an LB/CS or CGNAT-LSN/NAT64 device with a non-HTTP L7 protocol feature enabled; not reported exploited"
    fixed: "14.1-73.37; 13.1-64.23; 14.1-73.37 FIPS; 13.1-37.279 FIPS/NDcPP"
  - id: CVE-2026-88778
    cvss: "8.8"
    epss: null
    type: logic-flaw
    vector: zero-click
    auth: pre-auth
    status: [patch-available]
    affected: "TCP configuration enabled, predictable TCP Initial Sequence Number; not reported exploited"
    fixed: "14.1-73.37; 13.1-64.23; 14.1-73.37 FIPS; 13.1-37.279 FIPS/NDcPP (also requires enabling Enhanced ISN Generation; the version upgrade alone does not remediate this one)"
sources:
  - url: "https://support.citrix.com/external/article/CTX697096/citrix-netscaler-adc-and-citrix-netscale.html"
    publisher: "Citrix (Cloud Software Group)"
    date: "2026-09-27"
    role: primary
  - url: "https://cert.europa.eu/publications/security-advisories/2026-014/"
    publisher: "CERT-EU"
    date: "2026-09-27"
    role: primary
  - url: "https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json"
    publisher: "CISA Known Exploited Vulnerabilities Catalog"
    date: "2026-09-27"
    role: primary
  - url: "https://advisories.ncsc.nl/advisory?id=NCSC-2026-0394"
    publisher: "NCSC-NL"
    date: "2026-09-27"
    role: corroborating
  - url: "https://www.cert.at/de/warnungen/2026/9/kritische-sicherheitslucken-in-citrix-netscaler-adc-und-netscaler-gateway-aktiv-ausgenutzt-updates-verfugbar"
    publisher: "CERT.at"
    date: "2026-09-27"
    role: corroborating
  - url: "https://watchtowr.com/intelligence/citrix-netscaler-zero-day-vulnerabilities-faq/"
    publisher: "watchTowr"
    date: "2026-09-27"
    role: corroborating
  - url: "https://www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/"
    publisher: "BleepingComputer"
    date: "2026-09-27"
    role: corroborating
closed_sources: []
evidence:
  - quote: "Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed."
    publisher: "Citrix (Cloud Software Group)"
  - quote: "A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands"
    publisher: "Citrix (Cloud Software Group)"
  - quote: "Citrix has confirmed active exploitation of these 2 critical vulnerabilities in the wild."
    publisher: "CERT-EU"
  - quote: "No attribution has been made public."
    publisher: "watchTowr"
verification: multi-source
sourcing_note: null
confidence: high
references:
  - "2026-08-20/cve-2026-19490-netscaler-gateway-aaa-auth-bypass"
  - "2026-07-01/cve-2026-8451-citrix-netscaler-adc-gateway-pre-auth-saml-mem"
deep_dive: true
deep_dive_category: firewall-vpn-rce
org_triage: null
classification:
  reliability: A
  credibility: 1
watchlist_hit: false
actions:
  - "Upgrade every internet-facing NetScaler ADC/Gateway to 14.1-73.37+ (14.1-FIPS 14.1-73.37 FIPS+) or 13.1-64.23+ (13.1-FIPS/NDcPP 13.1-37.279+) now; on a 13.1-branch appliance run `show ns variable` first; if it returns any variables, install 13.1-64.24 instead to avoid a known reboot loop. Capture logs, a configuration snapshot, a support bundle and a core dump from each exposed appliance BEFORE patching, since the upgrade removes forensic evidence of prior exploitation, then run a compromise assessment."
updates: []
migrated_from: null
---

Citrix's security bulletin CTX697096, published 2026-09-27, fixes eight NetScaler ADC / NetScaler Gateway
vulnerabilities, two of which were already being exploited as zero-days before any fix existed
([Citrix, 2026-09-27](https://support.citrix.com/external/article/CTX697096/citrix-netscaler-adc-and-citrix-netscale.html)).
CVE-2026-88771 (CWE-20, improper input validation, CVSS 4.0 9.5) lets an unauthenticated remote attacker execute
arbitrary commands on every NetScaler ADC/Gateway deployment in its default configuration; no feature needs to be
enabled first. CVE-2026-88772 (CWE-119, memory overflow to RCE or DoS, CVSS 4.0 9.5) is reachable wherever DTLS is
enabled, which Citrix states is the default on any VPN virtual server, so most VPN-fronting Gateway deployments meet
the precondition unless DTLS was explicitly disabled. Citrix's own bulletin states plainly: "Exploits of CVE-2026-88771
and CVE-2026-88772 on unmitigated NetScaler deployments have been observed"
([Citrix, 2026-09-27](https://support.citrix.com/external/article/CTX697096/citrix-netscaler-adc-and-citrix-netscale.html)).
CISA added both to its Known Exploited Vulnerabilities catalog on 2026-09-27 with a 2026-09-30 remediation due date,
requiring compliance with BOD 26-04 forensic-triage guidance
([CISA Known Exploited Vulnerabilities Catalog, 2026-09-27](https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json)),
and CERT-EU's advisory the same day states "Citrix has confirmed active exploitation of these 2 critical
vulnerabilities in the wild" and recommends a compromise assessment on every internet-facing appliance
([CERT-EU, 2026-09-27](https://cert.europa.eu/publications/security-advisories/2026-014/)).

The disclosure path itself is a defender-relevant data point. NetScaler administrators reported being told by IT
suppliers and security teams to shut appliances down over the weekend of 26-27 September, before any CVE identifier
or vendor advisory existed, tracing to a pre-notification NCSC-NL reportedly sent to its constituency; NCSC-NL declined
to confirm the leaked notice's contents to BleepingComputer ([BleepingComputer, 2026-09-27](https://www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/))
but published its own public advisory NCSC-2026-0394 the same day once Citrix's bulletin shipped
([NCSC-NL, 2026-09-27](https://advisories.ncsc.nl/advisory?id=NCSC-2026-0394)).
watchTowr independently and publicly flagged credible rumors of unpatched, in-the-wild NetScaler RCEs on 2026-09-26,
a day ahead of Citrix's own bulletin. No public attribution of the exploiting activity exists; watchTowr's FAQ states
"No attribution has been made public," while noting NetScaler perimeter appliances have historically been targeted by
both state-sponsored and ransomware-affiliated actors, consistent with the CitrixBleed (CVE-2023-4966) and
CitrixBleed 2 (CVE-2025-5777) history on the same product line
([watchTowr, 2026-09-27](https://watchtowr.com/intelligence/citrix-netscaler-zero-day-vulnerabilities-faq/)).

The same bulletin fixes six configuration-dependent companion flaws not reported exploited: an HTTP request-smuggling
flaw (CVE-2026-88773, CVSS 9.3), a policy-bypass flaw via HTTP URL-based expressions (CVE-2026-88774, CVSS 7.0),
three further memory-overflow conditions gated respectively on a Gateway/AAA virtual server, an Oracle-type
load-balancing virtual server, or a non-HTTP Layer-7 protocol on an LB/CS/CGNAT-LSN/NAT64 device
(CVE-2026-88775/88776/88777, each CVSS 8.8), and a predictable-TCP-ISN weakness (CVE-2026-88778, CVSS 8.8) whose
remediation is not covered by the version upgrade alone: it additionally requires enabling Enhanced ISN Generation.
This is a distinct CVE family from CVE-2026-19490 and from the CitrixBleed/CitrixBleed 2 lineage named above;
watchTowr states directly that appliances already patched for CVE-2026-19490 remain vulnerable to
CVE-2026-88771/88772 unless running one of the new fixed builds
([watchTowr, 2026-09-27](https://watchtowr.com/intelligence/citrix-netscaler-zero-day-vulnerabilities-faq/)). Fixed
builds
are 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS and 13.1-37.279 (FIPS/NDcPP); watchTowr flags an upgrade caveat on the
13.1 branch: run `show ns variable` first, and if it returns any variables, install 13.1-64.24 instead to avoid a
known reboot loop during the upgrade.

**Detection and hunting.** No workaround exists for the two exploited flaws, so the priority is upgrading, not
mitigating in place. Before patching, capture logs, a configuration snapshot, a support bundle and a core dump from
every appliance that has been internet-facing, since the upgrade can overwrite forensic evidence of prior compromise;
CISA's guidance under BOD 26-04 recommends the same sequence
([CISA Known Exploited Vulnerabilities Catalog, 2026-09-27](https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json)).
A limited IOC scan is available from 14.1-73.36+ with telemetry enabled via the NetScaler Console Security Advisory
page or through Citrix Support, but Citrix itself cautions the indicators do not cover every exploitation technique
([watchTowr, 2026-09-27](https://watchtowr.com/intelligence/citrix-netscaler-zero-day-vulnerabilities-faq/)), so a
clean scan is not proof an appliance was not already compromised before patching; a compromise assessment
(authentication logs for anomalous sessions, unexpected
configuration changes, unfamiliar scheduled tasks or processes on the management plane) is the only way to build that
confidence.

**Triage:** the discriminator for CVE-2026-88771 is that no legitimate administrative or user path reaches the
vulnerable input-validation code path without a valid session: any successful, unauthenticated command execution on
the appliance is the signal, not a benign lookalike to rule out. For CVE-2026-88772, DTLS handling anomalies (crashes,
unexpected restarts, or malformed-record errors in VPN vServer logs) on an appliance where DTLS was not deliberately
disabled are the discriminator worth hunting for, since legitimate DTLS traffic does not trigger the memory-overflow
condition.

**Defender takeaway:** every internet-facing NetScaler ADC/Gateway deployment needs the patch now regardless of
whether DTLS is knowingly enabled: Citrix states it is the VPN vServer default, so an administrator who never
explicitly configured DTLS may still be exposed to CVE-2026-88772. NCSC-CH's own Cyber Security Hub had not yet
published an advisory on this pair as of 2026-09-27, though NetScaler Gateway is a widely deployed perimeter VPN and
remote-access layer across European public-sector networks and CERT-EU, NCSC-NL and CERT.at each issued same-day
advisories.
