Citrix NetScaler Zero-Days: Two Unpatched Edge RCE Flaws Exploited Before Fixes Shipped

Citrix NetScaler Zero-Days: Two Unpatched Edge RCE Flaws Exploited Before Fixes Shipped

Citrix NetScaler Zero-Days: Two Unpatched Edge RCE Flaws Exploited Before Fixes Shipped

Introduction

The appliances that terminate VPN connections and load-balance corporate applications just became the most attractive target on the internet. Citrix confirmed on September 27, 2026 that two critical remote code execution vulnerabilities in NetScaler ADC and NetScaler Gateway were being exploited in the wild, and that both were being used as zero-days before any public fix existed. The vendor's security bulletin, CTX697096, lists both flaws at CVSS v4 score 9.5, ships fixes for two of them, and discloses no workaround and no indicators of compromise.

That combination is the part administrators should sit with. There is no mitigation to deploy while you wait for a maintenance window, and there is nothing to grep for after the fact. Six additional vulnerabilities in the same bulletin share the same root cause of exposed infrastructure being under-defended, though only the two headline flaws carry confirmed exploitation.

The timeline is unusual. watchTowr publicly warned on September 26 that unpatched NetScaler remote code execution flaws were circulating, describing the intelligence as scarce but credible. The company's researchers said the bugs had been surfaced during forensic investigations, meaning someone was already digging into compromised appliances before the vendor had assigned a CVE. By the next day, CISA had issued a formal alert and added one of the flaws to its Known Exploited Vulnerabilities catalog, and the Dutch National Cyber Security Centre's private pre-notification — which reportedly triggered urgent phone calls to IT suppliers — had clearly already been in motion.

For anyone running NetScaler infrastructure as the front door to a corporate network, this is not a patch-when-convenient cycle. It is a preserve-evidence-then-patch cycle.

What Citrix Actually Disclosed

Citrix's advisory is unusually terse for a zero-day of this class. The vendor confirmed exploitation of two flaws, both rated 9.5 Critical under CVSS 4.0.

CVE-2026-88771 is an improper input validation vulnerability. The technical impact is stark: an unauthenticated remote attacker can execute arbitrary commands on the appliance. It affects every NetScaler ADC and NetScaler Gateway deployment on a vulnerable version, in the default configuration, with no optional feature to enable. This is the worst-case shape a perimeter flaw can take — reachable, unauthenticated, and universal.

CVE-2026-88772 is a memory overflow that can lead to remote code execution or denial of service. It requires DTLS to be enabled, but DTLS is on by default for VPN virtual servers, which means most Gateway deployments satisfy the precondition unless an administrator deliberately turned it off.

Citrix's own phrasing was that "exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed." The company did not state how widespread the exploitation is, who is behind it, or since when. That silence matters, because it leaves defenders unable to size their own risk.

The same bulletin carries six more flaws, CVE-2026-88773 through CVE-2026-88778, none of which Citrix lists as exploited. They are still serious: CVE-2026-88773 is an HTTP request smuggling issue at 9.3 Critical, CVE-2026-88774 is a policy bypass where any policy uses an HTTP URL-based expression, three are memory overflows at 8.8, and CVE-2026-88778 is a TCP initial sequence number prediction flaw. That last one is notable because the upgrade does not fix it on its own — it requires enabling Enhanced ISN Generation, a configuration change administrators frequently overlook.

Why This One Is Worse Than a Normal KEV Addition

CISA's involvement makes this a federal deadline, but the more useful signal came from watchTowr's forensic origin story. Bugs found in incident response are different in character from bugs found in a lab. They have already been used, against someone, for a reason.

The Hacker News reported that some administrators began taking appliances offline on September 26 after their IT suppliers' security teams phoned to advise immediate shutdown — a detail the vendor never mentioned publicly. The origin of those supplier calls has not been established, though the timing lines up with NCSC-NL's pre-notification. Emergency power-cycling a production VPN concentrator is a serious availability decision, and organisations made it anyway.

There is also a grim precedent. In 2025, a NetScaler flaw was exploited as a zero-day against Dutch organisations, and NCSC-NL found that patching alone did not remove the risk, because an attacker who gained access before the patch kept it. The agency told administrators to run its detection scripts rather than assume the update was the end of the story. The same caveat applies here, with the added complication that Citrix published no indicators of compromise in the initial bulletin.

Administrators patching for the earlier authentication bypass CVE-2026-19490 in August should note they are not covered. The builds that fixed it — 14.1-73.32 and 13.1-63.21 — sit inside the range affected by these new flaws. Similarly, appliances patched for CVE-2026-19490 remain vulnerable to the new issues unless they move to one of the newer fixed builds, a point watchTowr called out explicitly.

The Patch Versions, and One Gotcha

Fixed builds are now available across all supported branches:

  • NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37 — upgrade to 14.1-73.37 or later
  • NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23 — upgrade to 13.1-64.23 or later
  • NetScaler ADC 14.1-FIPS before 14.1-73.37 — upgrade to 14.1-73.37 FIPS or later
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP before 13.1-37.279 — upgrade to 13.1-37.279 or later

Hong Kong's CERT published a bulletin on September 28 rating the overall risk as Extremely High Risk, citing denial of service, security restriction bypass, sensitive information disclosure, and remote code execution across the affected products.

There is a deployment trap on the 13.1 branch. Citrix instructs administrators to run show ns variable first; if it returns any values, they should use 13.1-64.24 rather than 13.1-64.23, to avoid a known reboot loop during the upgrade. Separately, the 13.1 fix arrived after that branch reached End of Maintenance on September 15 under Citrix's release schedule — meaning the only patched option for a 13.1 deployment is a branch Citrix no longer supports on a normal cadence. That is a migration decision hiding inside a patch advisory, and it is the kind of detail that gets missed in a hurried maintenance window.

Secure Private Access hybrid deployments that use NetScaler instances are in scope too, since the bulletin applies to customer-managed appliances. Citrix noted it upgrades its own managed cloud services and Citrix-managed Adaptive Authentication itself, so the exposure concentrates on the gear customers own and operate.

The Response Order Matters

Because both flaws were exploited before a fix was public, installing the update tells you nothing about whether an attacker arrived first. The patch closes the door; it does not report on who was already inside.

Citrix's guidance for a suspected compromise puts preservation first. Administrators should capture a snapshot of a VPX instance, the logs held on remote syslog servers and NetScaler Console, a technical support bundle, and a core dump of the packet engine. Only then should they install the fixed build. The practical reason is simple: the upgrade can overwrite the artifacts that tell you what happened.

Compromise checks come next. watchTowr points to an IOC scan available on the NetScaler Console Security Advisory page in version 14.1-73.36 or later with telemetry enabled, or to Citrix Support for indicators. The critical caveat is Citrix's own warning that the IOCs do not cover every technique, so a clean scan result is not proof of a clean system. Treat a negative result as inconclusive, not reassuring.

After patching, rotate every password, secret, and certificate stored on or transiting the appliance — a compromise at the perimeter edge often means those are no longer trustworthy. Forward NetScaler logs to the SIEM, and confirm management interfaces are not reachable from the public internet. Then enable Enhanced ISN Generation, because that is the only thing that closes CVE-2026-88778.

The uncomfortable question every responder eventually has to answer is whether a box exposed to an unauthenticated RCE for an unknown number of days should simply be trusted again after a patch. In the 2025 Dutch incident, the national CERT's answer was no, and this bulletin offers defenders no basis for a more optimistic view.

Conclusion

Two unauthenticated remote code execution flaws in Citrix NetScaler, both rated 9.5, were used before Citrix could ship a fix. That is a meaningful escalation in severity for anyone who treats these appliances as routine infrastructure rather than crown-jewel perimeter equipment, because CVE-2026-88771 requires no authentication and no special configuration to exploit, and its exposure scope covers effectively the entire installed base on vulnerable branches.

What defenders have is unusually little: no vendor workaround, no published indicators of compromise in the first advisory, no scoping information about the attacker, and a forensic trail that runs from NCSC-NL's pre-notification through supplier phone calls to a full bulletin in roughly 48 hours. The fix builds are real and available across 14.1, 13.1, and their FIPS variants, and the 13.1 reboot-loop workaround is documented.

The next 72 hours are worth more than a routine patch cycle. Preserve the evidence, patch to the correct branch build, check for compromise while knowing the check is incomplete, rotate what the appliance held, and close the ISN gap the upgrade leaves open. The cybersecurity question is not whether to patch this week — it is whether an attacker was already inside before the patch landed.

Images

Open server rack filled with networking equipment, patch panels and cabling in an equipment room

Open equipment cabinet with patch panels, network devices and blue and orange cables in a utility room

References

← Back to Home