Advisory summary
Citrix patches two NetScaler zero-days already exploited; CISA sets 30 September deadline

AI-generated editorial illustration by CyberShitty. Not a photograph or a document from the organisations named.
Citrix has fixed eight NetScaler ADC and Gateway flaws, two of them critical remote code execution bugs exploited for weeks before patches existed. CISA and CERT-In say they are under active attack; check for compromise before you patch.
01 / What happened
Citrix published security bulletin CTX697096 on 27 September 2026, addressing eight vulnerabilities in customer-managed NetScaler ADC and NetScaler Gateway appliances. Two of them, CVE-2026-88771 and CVE-2026-88772, were exploited as zero-days, according to Citrix as reported by BleepingComputer and Tenable. Both carry a CVSS v4 score of 9.5.
The same day, CISA issued an alert warning that threat actors are exploiting the flaws globally and added both CVEs to its Known Exploited Vulnerabilities (KEV) catalogue, with a remediation due date of 30 September 2026 for federal agencies. CISA revised the alert on 28 September. That day India's CERT-In issued vulnerability note CIVN-2026-0479, rated Critical, saying the two CVEs are being actively exploited in the wild and urging users to patch immediately.
Public disclosure followed several days of private warnings. The Dutch National Cyber Security Centre (NCSC-NL) sent a pre-notification to organisations in the Netherlands, and on 26 September the security firm watchTowr said publicly that it had credible information about unpatched NetScaler remote code execution flaws being exploited.
02 / Why it matters
CVE-2026-88771 is described as an improper input validation flaw that can let an unauthenticated attacker run arbitrary commands, and Tenable reports it affects all deployments, including default configurations. CVE-2026-88772 is a memory-bounds flaw that can lead to code execution or denial of service; it requires DTLS to be enabled, which is the default on VPN virtual servers.
Two unauthenticated remote code execution bugs on an internet-facing gateway leave defenders very little margin.
The window was not short. Security researcher Kevin Beaumont, quoted by Help Net Security on 28 September, says the attacks have been unfolding throughout September and that the actor is probably nation-state aligned and after espionage. Shadowserver counts about 23,000 internet-exposed NetScaler instances, nearly 22,000 of them ADC appliances, according to BleepingComputer; that is exposure, not confirmed vulnerability. The remaining six CVEs, CVE-2026-88773 to CVE-2026-88778, are rated between 7.0 and 9.3 according to Tenable and are not listed as exploited.
03 / Who is exposed
According to the Citrix bulletin, as summarised by Tenable, BleepingComputer and CERT-In, the following customer-managed builds are affected:
- NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
- NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
- NetScaler ADC FIPS before 14.1-73.37 FIPS, and FIPS and NDcPP builds before 13.1-37.279 (per CERT-In)
- Appliances with DTLS enabled on VPN virtual servers are additionally exposed to CVE-2026-88772
Operators of older branches not listed above should confirm their status against the bulletin itself rather than rely on third-party summaries.
04 / Confirmed vs. claimed
Confirmed: Citrix has fixed the eight CVEs and states that CVE-2026-88771 and CVE-2026-88772 have been exploited; CISA lists both in KEV (added 27 September, due 30 September) and says exploitation is occurring globally; CERT-In rates the flaws Critical and says both are exploited in the wild. Claimed / unconfirmed: the view that exploitation ran for weeks and is espionage-driven comes from an independent researcher; Citrix, CISA and CERT-In have not named an actor or said how many appliances have been compromised. Reports of administrators being advised to shut appliances down before the bulletin came from secondary sources and have not been independently verified by this desk.
05 / What to do now
- Check for compromise before you patch. CISA says that if you suspect compromise, preserve forensic evidence first, because updating can remove forensic visibility. Keep appliance logs before they rotate.
- Do not treat a clean indicator-of-compromise (IOC) scan as an all-clear. Citrix warns its IOCs may miss compromises because attackers change tools and infrastructure, and recommends experienced forensic investigators.
- Look for unexpected files such as webshells, unfamiliar accounts or configuration changes, and anomalous log entries, following Citrix and CISA guidance.
- Then upgrade to 14.1-73.37 or 13.1-64.23 or later (or the fixed FIPS/NDcPP build), per bulletin CTX697096. Follow Citrix article CTX694799 if compromise is suspected.
- Review exposure of management interfaces and gateway virtual servers to the internet.
Source log / 2026-0927-CN
- CISA — Critical zero-day vulnerabilities exploited in Citrix NetScaler ADC and Gateway (27 Sep 2026, revised 28 Sep) Primary
- CISA — Known Exploited Vulnerabilities catalogue entries for CVE-2026-88771 and CVE-2026-88772 (27 Sep 2026) Primary
- Citrix — Security bulletin CTX697096 (27 Sep 2026) Primary
- Tenable — Frequently asked questions about Citrix NetScaler zero-day vulnerabilities (Sep 2026) Secondary
- BleepingComputer — Citrix confirms two NetScaler RCE zero-days exploited in attacks (27 Sep 2026) Secondary
- CERT-In — Vulnerability Note CIVN-2026-0479: Multiple vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway (28 Sep 2026) Primary
- BleepingComputer — CISA orders feds to patch exploited Citrix flaws by Wednesday (28 Sep 2026) Secondary
- Help Net Security — Citrix NetScaler RCE zero-days exploited globally for weeks (28 Sep 2026) Secondary