Citrix released security updates on September 27, 2026, for two critical remote code execution vulnerabilities in NetScaler ADC and NetScaler Gateway after confirming that attackers had exploited both flaws on unmitigated systems.
Both vulnerabilities carry a critical CVSS v4.0 score of 9.5, but they affect NetScaler deployments under different conditions.
| Vulnerability | Impact | Precondition |
|---|---|---|
| CVE-2026-88771 | Improper input validation can allow an unauthenticated attacker to execute arbitrary commands remotely. | All NetScaler ADC and NetScaler Gateway deployments are affected, including default configurations. No additional feature needs to be enabled. |
| CVE-2026-88772 | A memory overflow can cause remote code execution or denial of service. | Datagram Transport Layer Security (DTLS) must be enabled. Citrix says DTLS is enabled by default on VPN virtual servers. |
NetScaler ADC and Gateway appliances commonly sit at the edge of enterprise networks, handling services such as VPN access, authentication, load balancing and connections to internal applications. A compromised appliance can give an attacker a foothold at the network perimeter and a path toward connected systems.
Affected and fixed NetScaler builds
Citrix’s bulletin applies to customer-managed NetScaler ADC and NetScaler Gateway products. Secure Private Access Hybrid deployments that use NetScaler instances are also affected.
| Product branch | Affected versions | Fixed build |
|---|---|---|
| NetScaler ADC and NetScaler Gateway 14.1 | Versions before 14.1-73.37 | 14.1-73.37 or later |
| NetScaler ADC and NetScaler Gateway 13.1 | Versions before 13.1-64.23 | 13.1-64.23 or later |
| NetScaler ADC 14.1-FIPS | Versions before 14.1-73.37 FIPS | 14.1-73.37 FIPS or later |
| NetScaler ADC 13.1-FIPS and 13.1-NDcPP | Versions before 13.1-37.279 | 13.1-37.279 or later |
Cloud Software Group said it is applying the required updates to Citrix-managed cloud services and Citrix-managed Adaptive Authentication. Administrators remain responsible for customer-managed appliances.
Citrix lists 13.1-64.23 as a fixed build but has also documented a cyclic reboot issue affecting a specific configuration. Administrators should run show ns variable before upgrading. If the command returns configured variables, Citrix recommends using 13.1-64.24 to avoid the upgrade problem.
The bulletin addresses eight vulnerabilities in total. CVE-2026-88771 and CVE-2026-88772 are the two issues Citrix has confirmed were exploited before patches became available.
CISA adds both NetScaler flaws to its exploited-vulnerability catalog
Security firm watchTowr warned on September 26 that multiple unpatched NetScaler remote code execution vulnerabilities were reportedly being exploited. Citrix published the CVE identifiers, affected builds and fixes the following day.
The Cybersecurity and Infrastructure Security Agency added both vulnerabilities to its Known Exploited Vulnerabilities catalog on September 27. CISA said reports and partner threat intelligence confirmed that threat actors were exploiting the flaws globally.
Federal Civilian Executive Branch agencies have a September 30, 2026, remediation deadline for both CVEs. CISA also marked forensic triage as required under its federal guidance. Although the directive applies to federal agencies, CISA encourages other organizations to prioritize vulnerabilities listed in the catalog.
What administrators should do now
CISA advised organizations to check for signs of compromise before patching where possible because installing an update may reduce forensic visibility. The Dutch National Cyber Security Centre similarly recommended preserving a memory dump and at least one month of logs before updating, followed by continued monitoring for suspicious traffic or activity.
- Identify every affected appliance. Inventory customer-managed NetScaler ADC, NetScaler Gateway and Secure Private Access Hybrid instances. Prioritize systems reachable from the internet.
- Preserve evidence where operationally feasible. Citrix’s incident-response guidance recommends recording system time and NTP settings, retaining local and centralized logs, taking a VPX snapshot, generating a technical support bundle and collecting an appropriate memory dump.
- Check for indicators of compromise. Citrix has made generic indicator checks available through NetScaler Console where the required version, telemetry and other prerequisites are present. Organizations that cannot use the Console feature can contact Citrix Support.
- Install the fixed build. Upgrade every affected appliance to the appropriate release. Citrix has not published a workaround that replaces installing the security update.
- Escalate suspicious findings as a security incident. Citrix recommends isolating suspected appliances, rotating service account credentials and other secrets, revoking certificates and private keys, and investigating systems that communicated with the appliance. A compromised instance may need to be rebuilt and restored from a verified backup.
- Reduce future exposure. Management services should remain off the public internet. NetScaler logs should be forwarded to an external logging or security information and event management platform for centralized monitoring and investigation.
Citrix warns that its available indicators do not cover every technique an attacker may use. A scan that finds nothing suspicious is not proof that an exposed appliance was never compromised.

Tech Help Canada Staff researches, writes, and reviews practical content for business owners and professionals. Our coverage spans business, marketing, SEO, technology, and the tools and systems people use to grow and operate online. We focus on clear, useful information backed by research, hands-on experience, and editorial review. Learn more about our team and editorial standards. Need help with something? Contact Us







