Attackers Are Already Exploiting the NetScaler Flaws Citrix Just Patched
Citrix has released fixes for eight vulnerabilities in NetScaler ADC and NetScaler Gateway, and says attackers are already exploiting two of them on unmitigated systems. This is not a routine patch bundle. One of the exploited flaws gives an unauthenticated attacker a path to arbitrary command execution across every customer-managed deployment, including default configurations.
The critical issue is CVE-2026-88771, an improper input-validation vulnerability with a CVSS v4 score of 9.5. Citrix says no optional feature needs to be enabled. If the appliance is running an affected build, the precondition is met.
Citrix has also observed exploitation of CVE-2026-88772, another CVSS 9.5 flaw. It is a memory-overflow vulnerability that can lead to remote code execution or denial of service when DTLS is enabled. DTLS is enabled by default on VPN virtual servers unless administrators explicitly turn it off.
The patch window is already an incident-response window
Citrix’s CTX697096 security bulletin states plainly that exploits of CVE-2026-88771 and CVE-2026-88772 have been observed on unmitigated deployments.
Update, 29 September: intruders reached beyond the gateway
Google Threat Intelligence Group and Mandiant link successful intrusions to CVE-2026-88772 since at least early September. Likely impacts span North America and Europe, including government, finance, education and professional services. Google has no exploit code; its assessment of root-level compromise rests on telemetry.
Intruders deployed WHIPSHOT and SLAPSHOT. In at least one intrusion, a tunnel supported internal reconnaissance and credential theft. That does not establish every victim’s outcome.
Treat the upgrade and the compromise assessment as separate jobs. Patching closes the known vulnerable paths, but it cannot prove that an internet-facing appliance was clean before the upgrade. Organisations with exposed NetScaler gateways should run the upgrade and compromise assessment as parallel workstreams.
The urgency is amplified by where these products sit. NetScaler Gateway controls remote access and often fronts authentication, VPN and application traffic. An unauthenticated command-execution path at that boundary can turn a security control into an initial foothold.
Update, 4 October: targeted SAML attacks now have fixed builds
Citrix identifies CVE-2026-88779 as a CVSS v4.0 8.7 memory overflow. Citrix says targeted attacks against unmitigated deployments can cause denial of service and repeated unavailability; it has not identified customer-data integrity impact.
The precondition is a customer-managed Gateway or AAA deployment configured as a SAML SP with add authentication samlAction, or a SAML IdP with add authentication samlIdPProfile. Hybrid NetScaler instances are included; Citrix-managed services receive vendor updates.
Upgrade ADC and Gateway 14.1 to 14.1-73.41, ADC and Gateway 13.1 to 13.1-64.28, ADC 14.1 FIPS to 14.1-73.41 FIPS, or ADC 13.1 FIPS and NDcPP to 13.1-37.282, or later within each branch. Deployments already upgraded for CTX697096 must upgrade again when this SAML precondition applies. The vendor statement covers availability; it does not establish remote code execution, data theft or compromise.
Update, 4 October: CISA adds the flaw to KEV
CISA added CVE-2026-88779 to its Known Exploited Vulnerabilities catalogue on 4 October. The entry lists 7 October as its remediation due date, marks forensic triage Yes and lists ransomware use as Unknown.
For US Federal Civilian Executive Branch agencies, BOD 26-04 applies asset by asset and the agency makes the final exposure determination. The catalogue date is not a universal legal deadline. Other exposed operators can treat the KEV addition as a prioritisation signal: upgrade, preserve volatile evidence where practical and assess whether the environment was affected.
CISA’s implementation guidance recommends scoping affected assets, preserving relevant evidence before remediation where possible, then stabilising, containing, analysing and documenting the escalation decision. Its step-specific target times are recommended practices; the directive requires adequate forensic triage, not those exact intermediate timings.
Which CTX697096 builds were required on 27 September
Citrix lists the following customer-managed releases as affected:
| Product branch | Affected builds | Fixed build |
|---|---|---|
| NetScaler ADC and NetScaler Gateway 14.1 | Before 14.1-73.37 | 14.1-73.37 or later |
| NetScaler ADC and NetScaler Gateway 13.1 | Before 13.1-64.23 | 13.1-64.23 or later |
| NetScaler ADC 14.1 FIPS | Before 14.1-73.37 FIPS | 14.1-73.37 FIPS or later |
| NetScaler ADC 13.1 FIPS and NDcPP | Before 13.1-37.279 | 13.1-37.279 or later |
Secure Private Access Hybrid deployments that use NetScaler instances are also affected and require those instances to be upgraded. Citrix says its managed cloud services and managed Adaptive Authentication service are being upgraded by Cloud Software Group. Customers should not assume that statement covers appliances they manage themselves as part of a hybrid deployment.
Eight flaws, but the first two set the triage order
| Vulnerability | Impact | Precondition | CVSS v4 |
|---|---|---|---|
| CVE-2026-88771 | Unauthenticated arbitrary command execution through improper input validation | Every deployment, including the default configuration | 9.5 |
| CVE-2026-88772 | Memory overflow leading to remote code execution or denial of service | DTLS enabled, including by default on VPN virtual servers | 9.5 |
| CVE-2026-88773 | HTTP request smuggling | HTTP configuration enabled | 9.3 |
| CVE-2026-88774 | Feature-policy bypass caused by HTTP URL expression use | A policy uses an HTTP URL-based expression | 7.0 |
| CVE-2026-88775 | Memory overflow causing erroneous behaviour or denial of service | Gateway or AAA virtual-server configuration | 8.8 |
| CVE-2026-88776 | Memory overflow causing erroneous behaviour or denial of service | Oracle-type load-balancing virtual server | 8.8 |
| CVE-2026-88777 | Memory overflow causing erroneous behaviour or denial of service | Certain non-HTTP Layer 7 features on LB, CS, CGNAT-LSN or NAT64 configurations | 8.8 |
| CVE-2026-88778 | Predictable TCP initial sequence numbers | TCP configuration enabled and enhanced ISN generation disabled | 8.8 |
The table should not become a reason to patch only the two known-exploited flaws. The fixed builds address all eight. The preconditions are useful for exposure assessment and investigation, but upgrading remains the primary control.
What defenders should do now
- Identify every customer-managed appliance. Include high-availability peers, disaster-recovery systems, FIPS and NDcPP appliances, test systems with external reachability and NetScaler instances used by Secure Private Access Hybrid.
- Upgrade to the fixed build immediately. Do not wait for a normal monthly maintenance window when CVE-2026-88771 affects the default configuration and exploitation is already confirmed.
- Check DTLS exposure. Treat VPN virtual servers as meeting the CVE-2026-88772 precondition unless DTLS was explicitly disabled. Other DTLS virtual servers also require review. Disabling DTLS or blocking upstream UDP/443 reduces only CVE-2026-88772 exposure. It does not protect against CVE-2026-88771.
- Enable enhanced ISN generation where required. Citrix says deployments affected by CVE-2026-88778 must apply the documented TCP configuration change as well as moving to a fixed build.
- Preserve evidence before it disappears. Record current build numbers, running configuration, exposed services, administrative changes, authentication anomalies and available system and network logs. Take a forensic snapshot where operationally safe.
- Investigate, do not merely verify the reboot. Follow Google’s hunting guide. Prioritise unexpected NSPPE termination after DTLS failures, unauthorised PHP handlers,
.debor.sigPHP files,/tmp/.uxdport,/tmp/.uxdlock, suspicious Python and setuid/bin/sh. - Escalate suspected compromise. Citrix’s compromise-response guidance recommends removing a suspected appliance from the network, rebuilding from a trusted image and changing accounts that may have authenticated through it. On suspected compromise, isolate the node, pause HA synchronisation, assess both peers, terminate sessions and rotate appliance and integration secrets after patching.
Do not confuse this release with the August NetScaler warning
BlackTree previously covered active targeting of a separate NetScaler authentication-bypass vulnerability. The new bulletin is not a revision of that incident. It introduces eight different identifiers, different fixed builds and a broader default-configuration risk through CVE-2026-88771.
That distinction matters operationally. A team that patched the August release can still be vulnerable today. The correct question is not whether NetScaler was updated recently, but whether every customer-managed instance is now running one of the builds named in CTX697096.
What remains unknown
Attribution and precise scope remain unresolved despite the new evidence.
GreyNoise separately recorded an unsuccessful 24 September sensor attempt against CVE-2026-88771, which must not be merged with Mandiant’s successful-intrusion evidence for CVE-2026-88772.
Those gaps limit attribution and campaign analysis. They do not weaken the patching decision. When a vendor confirms exploitation of an unauthenticated command-execution flaw affecting default deployments, exposed appliances should be treated as urgent remediation and review targets.
Sources
- GTIG/Mandiant, NetScaler intrusion analysis and response guidance, 29 September 2026.
- GreyNoise, Swarming Against Citrix 0-Day Exploitation, dated 28 September 2026.
- Citrix, NetScaler ADC and NetScaler Gateway Security Bulletin CTX697096, initially published 27 September 2026 and last modified at 15:25 as displayed by Citrix.
- Citrix NetScaler documentation, enhanced initial sequence number generation.
- Citrix, Steps to Take if NetScaler ADC Is Suspected to Be Compromised.
- Citrix, CTX697174, changelog dated 3 October 2026 (PST); displayed created 10-04-2026 02:03 and modified 02:19, timezone not stated.
- Citrix, NetScaler SAML explanatory blog, last updated 3 October 2026 (Pacific Daylight Time); exact clock time not displayed.
- CISA, Known Exploited Vulnerabilities catalogue JSON, catalogue version 2026.10.04, released 4 October 2026 at 18:52:56 UTC and observed 4 October 2026 at 22:28 CEST.
- CISA, Binding Operational Directive 26-04, dated 10 June 2026.
- CISA, BOD 26-04 implementation guidance, updated 25 August 2026.


