Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
Citrix disclosed eight vulnerabilities in NetScaler ADC and NetScaler Gateway on September 27, 2026, including two critical zero-days under confirmed active exploitation worldwide. The release of advisory CTX697096 came more than 36 hours after the first unofficial reports, forcing administrators and security teams to operate without official guidance. Both flaws, CVE-2026-88771 and CVE-2026-88772, carry CVSS v4.0 scores of 9.5 and allow unauthenticated remote code execution.
- CVE-2026-88771 and CVE-2026-88772 are zero-days with confirmed active exploitation: the first affects all deployments in default configuration, the second requires DTLS enabled on VPN vServer
- CISA added both to the KEV catalog on September 27 with a September 30 patch deadline for U.S. federal agencies
- Palo Alto Networks estimates over 50,000 publicly exposed instances, potentially vulnerable
- The 13.1 branch, for which a patched version is available, reached End of Maintenance on September 15, 2026
Technical Mechanics of the Two Zero-Days
CVE-2026-88771 exploits an input validation flaw (CWE-20) that leads to command injection. According to the Citrix advisory, the vulnerability affects all deployments of NetScaler ADC and NetScaler Gateway in default configuration, with no need to enable additional features. The attack vector is network-based, low complexity, requires no privileges and no user interaction: AV:N/AC:L/AT:P/PR:N/UI:N in the CVSS:4.0 framework.
CVE-2026-88772 stems from a memory overflow (CWE-119) in DTLS processing. Unlike the first, this requires the DTLS protocol to be enabled: a condition met by default on VPN vServers, but not on all deployments. Attack complexity is high (AC:H), yielding a vector of AV:N/AC:H/AT:N/PR:N/UI:N. Both flaws allow remote code execution with full impact on confidentiality, integrity, and availability.
The dossier does not specify whether a public proof-of-concept exists for CVE-2026-88772.
Timeline of Silence: From September 24 to Official Disclosure
The first known exploitation attempt dates to September 24, 2026, according to GreyNoise data cited by CyberScoop. On September 26, security vendor watchTowr published a post anticipating the existence of the vulnerabilities absent official confirmation. The Dutch NCSC sent private pre-notification to selected parties before public disclosure.
Citrix made advisory CTX697096 available on September 27, with CISA immediately adding both CVEs to the KEV catalog. The interval between the first unofficial reports and the vendor's public acknowledgment exceeded 36 hours.
"The information vacuum was most striking. Customers were receiving warnings through unofficial channels while Citrix remained publicly silent" — Ben Harris, CEO watchTowr
The same source adds: "When active exploitation is underway, hours matter." According to Harris, Citrix could have warned customers of active exploitation and provided immediate defensive guidance without revealing technical details useful to attackers.
The Stakes: Over 50,000 Exposed Instances
NetScaler ADC and Gateway are edge appliances for secure remote access and application load balancing. Their perimeter position makes them prime targets for initial access to corporate networks. Palo Alto Networks identified over 50,000 publicly exposed instances potentially vulnerable.
The risk does not end with patching. CISA and historical NCSC sources indicate the need for forensic activity to verify prior compromise, even after patches are applied. Citrix made generic indicators of compromise available via NetScaler Console; the dossier does not document the effectiveness of these indicators in detecting all exploitation variants.
No infrastructure overlaps linking the actor to specific groups have emerged at this stage. The exact scale of compromises and the number of confirmed victims remain unknown.
Immediate Actions
Priority actions derive directly from primary sources:
Patch by September 30 for U.S. federal agencies: CISA imposed this binding deadline for CVE-2026-88771 and CVE-2026-88772. Fixed versions are 14.1-73.37 and later, 13.1-64.23 and later, with specific builds for FIPS/NDcPP variants.
Evaluate upgrade from the 13.1 branch: On September 15, 2026, the branch reached End of Maintenance. Organizations remaining on it must plan migration to 14.1 even after applying the emergency patch.
Conduct pre-patch or post-patch forensic verification: CISA and the NCSC-NL context explicitly signal that patching alone does not remove the risk of prior compromise.
Consult Citrix indicators on NetScaler Console: The primary source identifies these as a detection tool, without however quantifying their coverage.
A Recurring Pattern and a Question on Disclosure
Citrix zero-days are not new: the vendor has faced similar episodes in the recent past, with documented large-scale consequences. What distinguishes this case is the communication dynamic, not just the technical severity. The delay between rumors and official confirmation left defenders without authority to base emergency decisions on, pushing some administrators to shut down critical appliances to contain risk.
The question the dossier raises but does not resolve is whether Citrix's responsible disclosure program has reached sufficient maturity to handle active exploitation in real time. The watchTowr quotes describe an operational gap, not merely a public relations one: the absence of pre-disclosure guidance translated uncertainty into unplanned downtime.
The brief does not document specific corrective measures by Citrix on its own communication practices.
Information verified against cited sources and current as of publication.
Sources
- https://www.infosecurity-magazine.com/news/citrix-patches-critical-zero-days/
- https://thehackernews.com/2026/09/warning-two-unpatched-citrix-netscaler.html
- https://www.rapid7.com/blog/post/etr-zero-day-exploitation-of-citrix-netscaler-adc-and-gateway-cve-2026-88771-and-cve-2026-88772
- https://www.cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway
- https://www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/
- https://cyberscoop.com/citrix-zero-days-delayed-disclosure/
- https://www.helpnetsecurity.com/2026/09/28/citrix-netscaler-rce-zero-days-exploited-for-weeks-cve-2026-88771-cve-2026-88772/
- https://www.cve.org/CVERecord?id=CVE-2026-88771
- https://nvd.nist.gov/vuln/detail/cve-2026-88771
- https://nvd.nist.gov/vuln/detail/cve-2026-88772
- https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096&articleURL=Citrix_NetScaler_ADC_and_Citrix_NetScaler_Gateway_Security_Bulletin_for_CVE_2026_88771_CVE_2026_88772_CVE_2026_88773_CVE_2026_88774_CVE_2026_88775_CVE_2026_88776_CVE_2026_88777_and_CVE_2026_88778&ref=thestack.technology
- https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.