Skip to content
CloudkuCloudku

Citrix NetScaler Zero-Days Under Attack: What to Do Now

CVE-2026-88771 and CVE-2026-88772 in NetScaler ADC and Gateway are being exploited. Affected versions, fixed builds and an urgent response checklist.

Cloudku teamPublished

On 27 September 2026, Cloud Software Group, the company behind Citrix, shipped fixes for eight vulnerabilities in NetScaler ADC and NetScaler Gateway. Two of them, CVE-2026-88771 and CVE-2026-88772, had already been exploited before a patch existed. The same day, the US Cybersecurity and Infrastructure Security Agency (CISA) issued an alert and added both to its Known Exploited Vulnerabilities (KEV) catalog.

If your organization relies on NetScaler for VPN, remote access or load balancing, this one needs your attention today. Below is what happened, who is exposed, and a practical checklist.

What happened

According to Citrix bulletin CTX697096, both headline flaws carry a CVSS v4.0 score of 9.5 (Critical):

  • CVE-2026-88771 is an input validation flaw that lets an unauthenticated attacker run arbitrary commands. It affects every deployment, including default configurations.
  • CVE-2026-88772 is a memory overflow that can lead to remote code execution or denial of service. It requires DTLS, which Citrix notes is on by default for VPN virtual servers.

Citrix confirmed it has observed exploitation of both CVEs on unmitigated appliances. CISA said attackers are exploiting them globally, and The Hacker News reported that US federal civilian agencies were given until 30 September 2026 to patch.

The other six CVEs in the bulletin (CVE-2026-88773 through CVE-2026-88778) score between 7.0 and 9.3 and each depend on specific configurations. We have not seen reports of them being exploited.

How widespread the attacks are

  • Palo Alto Networks Unit 42 traced reconnaissance against NetScaler Gateways back to 21 August 2026, and saw a web shell dropped via CVE-2026-88771 on 21 September, before public disclosure.
  • Mandiant and Google Threat Intelligence, as cited by Tenable, date CVE-2026-88772 exploitation to at least early September. Australia’s ACSC advises hunting for compromise back to at least 4 September.
  • Once watchTowr published a root-cause analysis and proof of concept, activity shifted to opportunistic, internet-wide exploitation (Help Net Security).
  • Unit 42 counted more than 50,000 internet-exposed NetScaler instances potentially vulnerable as of 27 September.

A follow-up flaw: CVE-2026-88779

On 3 October 2026 Citrix published a second bulletin, CTX697174, for CVE-2026-88779, a memory overflow causing denial of service (CVSS v4.0 8.7). It only applies to appliances configured as a SAML Service Provider or SAML Identity Provider. Tenable reports CISA added it to KEV on 4 October. Bottom line: if you use SAML and already upgraded to the 27 September builds, you need to upgrade again.

Affected and fixed versions

Taken from bulletins CTX697096 and CTX697174. Citrix recommends everyone move to the newest builds, so the right-hand column is the safest target.

Branch Vulnerable to CVE-2026-88771 to -88778 if below Latest build (also fixes CVE-2026-88779)
NetScaler ADC & Gateway 14.1 14.1-73.37 14.1-73.41 or later
NetScaler ADC & Gateway 13.1 13.1-64.23 13.1-64.28 or later
NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS 14.1-73.41 FIPS or later
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 13.1-37.282 or later

Secure Private Access Hybrid deployments that use NetScaler instances are also affected. The bulletins cover customer-managed appliances; Cloud Software Group is updating the Citrix-managed cloud services itself.

Versions 12.1 and 13.0 are end-of-life, and per Tenable Citrix has not said whether they are affected. If you still run them, treat them as at risk and plan a move to a supported branch.

Who is at risk

Practically any organization with NetScaler ADC or Gateway facing the internet, for example as:

  • a VPN or remote access gateway (SSL VPN, ICA Proxy for Citrix Virtual Apps and Desktops),
  • a login or authentication portal (AAA, SAML),
  • a load balancer in front of public applications.

Because CVE-2026-88771 needs no credentials and works on default settings, assume any unpatched appliance is already being probed.

Urgent checklist

This order follows Citrix and CISA guidance. One point from CISA matters a lot: if you suspect compromise, preserve forensic evidence before you patch, because updating can wipe the traces investigators need.

  1. Take inventory. List every NetScaler appliance (MPX, SDX, VPX), its build and its role. Use the precondition checks in the Citrix bulletin to confirm exposure, such as whether DTLS is enabled or SAML is configured.
  2. Check for compromise first. Citrix provides indicators of compromise through NetScaler Console (telemetry must be enabled) or via Citrix Support. Citrix also released a detection script, though Help Net Security notes it may miss some compromises as attackers change tactics.
  3. Upgrade to the latest build in the table above, as soon as you can. CISA points out NetScaler upgrades can be complex and may need downtime, so book the maintenance window now.
  4. If you cannot patch today, cut internet exposure where operationally possible. Mandiant (via Tenable) suggests blocking inbound UDP 443 at an upstream firewall and disabling DTLS on gateways that do not need it. That only blunts CVE-2026-88772, not CVE-2026-88771, so patching remains mandatory.
  5. If you find signs of compromise, follow Citrix article CTX694799:
    • preserve evidence (VPX snapshot, logs from remote syslog and NetScaler Console, a technical support bundle, a core dump),
    • isolate the appliance from the network,
    • revoke credentials and access: service account secrets (LDAP, RADIUS shared secrets, OAuth tokens, API keys, SNMP communities), user accounts that authenticated through Gateway or AAA, and certificates and private keys stored on the device,
    • investigate connected systems, especially authentication servers and jump hosts,
    • rebuild the appliance, upgrade firmware, and restore from a backup you have confirmed predates the compromise,
    • after restoring, change all local passwords, rotate the Key Encryption Keys (KEK) and replace all SSL certificates.
  6. Revoke active sessions and rotate credentials after patching. Mandiant recommends this even without confirmed compromise, since a patch does not evict an attacker who is already in. The Citrix bulletin does not list specific session-termination commands, so use official documentation or ask Citrix Support.
  7. Keep watching. Citrix advises monitoring rebuilt systems for at least 90 days. Unit 42 suggests hunting for suspicious admin sessions, unexpected outbound connections and unexplained gaps in logs. Remember that patching does not remove a web shell that is already in place.

One more point from Citrix that applies everywhere: NetScaler management services should never be reachable from the public internet.

The wider lesson for any gateway or VPN

Edge devices keep turning out to be the front door for attackers, whatever the brand. A few habits pay off:

  • Treat your gateway as a crown-jewel asset. It faces the internet and holds the credentials and access paths into your network.
  • Have an emergency patch path. Agree in advance how you will apply a critical fix within hours, downtime included.
  • Ship logs off the box. Remote syslog keeps evidence intact even if the appliance is compromised.
  • Keep management interfaces off the internet.
  • Plan for the gateway failing. Isolated, tested backups and monitoring of the endpoints behind the gateway decide how fast you recover.

How Cloudku can help

Cloudku does not offer Citrix services and does not patch customers’ NetScaler appliances. That work stays with your IT team and the vendor.

Where we can help is the protection and recovery layer behind it. Cloudku Cyber Protection, built on Acronis, gives you separate cloud backup stored in an Acronis data center in Indonesia with AES-256 encryption and AI-based anti-malware and anti-ransomware. On request, we also provide Disaster Recovery, XDR, and 24/7 MDR delivered by Acronis TRU to help spot suspicious activity on your endpoints. Cloudku also runs its own BGP network (AS133337) backed by a 24/7 NOC.

Sources

  1. CISA — Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway (27 Sep 2026)
  2. Cloud Software Group — NetScaler ADC and NetScaler Gateway Security Bulletin CTX697096 (27 Sep 2026)
  3. Cloud Software Group — Security Bulletin for CVE-2026-88779, CTX697174 (3 Oct 2026)
  4. Cloud Software Group — Steps to Take if NetScaler ADC is Suspected to be Compromised, CTX694799
  5. BleepingComputer — Citrix admins warned to shut down NetScalers over 2 exploited zero-days (27 Sep 2026)
  6. The Hacker News — CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally (28 Sep 2026)
  7. Help Net Security — NetScaler zero-day exploitation escalates into mass attacks (29 Sep 2026)
  8. Palo Alto Networks Unit 42 — NetScaler zero-days exploited (Sep–Oct 2026)
  9. Tenable — Frequently asked questions about reported Citrix NetScaler zero-day vulnerabilities (Oct 2026)

This article is for general information. Verify details against the cited sources before acting.

Need help applying this?

The Cloudku team can help you review your infrastructure and set up the right protection.

Talk to our team