Citrix Patches Two NetScaler RCE Zero-Days Exploited Worldwide

Citrix patched two NetScaler RCE zero-days exploited worldwide as CISA calls for rapid remediation and forensic checks.

Sep 27, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Citrix has patched two critical NetScaler RCE zero-days exploited before fixes were available. The Sept. 27 release addresses eight vulnerabilities in NetScaler ADC and NetScaler Gateway, led by CVE-2026-88771 and CVE-2026-88772, both rated 9.5 under CVSS 4.0.

CISA added both flaws to its Known Exploited Vulnerabilities catalog and said they are being exploited globally. Each can independently enable remote code execution, so organizations that exposed affected appliances before patching also need to assess possible compromise.

In a Sept. 27 security alert, CISA advised organizations to check for compromise before patching when possible. If intrusion is suspected, it recommends preserving forensic evidence first because updating can reduce forensic visibility.

Two NetScaler flaws allow unauthenticated RCE

CVE-2026-88771 is an improper input validation flaw that lets an unauthenticated remote attacker execute arbitrary commands. The Citrix security bulletin says all NetScaler ADC and Gateway deployments running vulnerable builds meet the precondition, including default configurations.

CVE-2026-88772 is a memory-overflow flaw that can cause remote code execution or denial of service when Datagram Transport Layer Security (DTLS) is enabled. DTLS is enabled by default on VPN virtual servers unless administrators explicitly disable it.

On Sept. 26, before Citrix published the CVEs or fixed builds, watchTowr warned that reports of an unpatched NetScaler RCE under active exploitation were credible. Benjamin Harris, founder and CEO of watchTowr, said the company had independently verified the reports with authoritative sources.

Harris urged organizations using NetScaler appliances to take them offline immediately while official guidance was still pending. “There should be no ambiguity here. This is a serious situation and should not be underestimated,” he said, warning administrators against waiting until the next workweek to respond.

At the time, Citrix had not publicly disclosed the flaws or released patches. Harris also pointed organizations to Citrix and their national CERTs for authoritative updates as the situation developed. Current guidance now centers on patching, preserving evidence, and investigating exposed appliances for compromise.

Advertisement

Citrix lists NetScaler ADC and Gateway 14.1 before 14.1-73.37 and 13.1 before 13.1-64.23 as affected, plus 14.1-FIPS before 14.1-73.37 FIPS and 13.1-FIPS/NDcPP before 13.1-37.279. Organizations that installed the Aug. 19 CVE-2026-19490 fix are not necessarily protected because those builds remain below the new fixed thresholds.

Patching does not rule out earlier compromise

The CISA KEV catalog sets a Sept. 30 remediation deadline for affected, in-scope assets at covered federal civilian agencies and requires forensic triage. Citrix's compromise-response guidance adds containment and recovery steps for suspected intrusions.

Similar incidents involving an F5 BIG-IP zero-day and Cisco FMC compromises reinforce the need to look beyond patch status when internet-facing security appliances have already been exploited.

  • Preserve evidence before making changes when feasible. Capture logs, memory, configuration data, and other forensic material before updates or restarts remove useful evidence.
  • Install the fixed builds. Upgrade to 14.1-73.37 or later, 13.1-64.23 or later, or the corresponding FIPS/NDcPP release. CVE-2026-88778 also requires Citrix's Enhanced Initial Sequence Number Generation configuration change.
  • Hunt for compromise. Use NetScaler Console IoCs with log and forensic analysis; Citrix warns that a clean scan cannot rule out intrusion. The Dutch NCSC advisory also recommends preserving logs and a memory dump.
  • Contain suspected intrusions and investigate connected systems. Isolate affected appliances and check authentication servers, management hosts, web systems, and other connected assets for follow-on activity.
  • Rotate exposed secrets and rebuild when necessary. Change relevant credentials, shared secrets, API keys, certificates, and cryptographic material; compromised appliances may require restoration from a known-good state.
  • Harden management access and test incident response plans. Keep NetScaler management services off the public internet and test procedures for evidence preservation, isolation, credential rotation, service restoration, and recovery.

A successful update does not show whether attackers reached an appliance before Sept. 27. Previously exposed systems still require compromise assessment after the vulnerability is closed.

Read more: Recent SonicWall SMA1000 zero-days show why remote-access appliances under active attack need both rapid patching and post-exploitation investigation.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.