SoftwareGuide

NetScaler zero-days: which builds fix CVE-2026-88771

Two NetScaler zero-days are under attack. Which ADC and Gateway builds fix them, whether the DTLS condition applies to you, and how to check for compromise.

Source-based. Written from the documents, reporting and reviews linked in the text. Nothing here was tested hands-on by The Ruling Desk. How we work

Curved glass office building of Citrix headquarters in Fort Lauderdale, Florida, with cars parked in front
Photo: Coolcaesar / Wikimedia Commons, CC BY-SA 3.0

Two NetScaler zero-days, CVE-2026-88771 and CVE-2026-88772, are being exploited against Citrix NetScaler ADC and NetScaler Gateway appliances, and the fix is to upgrade to build 14.1-73.37 or 13.1-64.23 or later. This guide walks you through which versions are affected, whether the DTLS condition on the second flaw applies to your setup, how to look for signs of compromise before you patch, and what to do if you can't patch today.

Key takeaways

  • Both flaws are confirmed exploited: Citrix's security bulletin, published September 27, 2026, says exploits of both "on unmitigated NetScaler deployments have been observed." Both carry a CVSS v4 score of 9.5.
  • CVE-2026-88771 needs no special setup: Citrix says it lets an unauthenticated attacker run commands on any deployment, default configuration included. CVE-2026-88772 needs DTLS, which is on by default on VPN virtual servers.
  • Fixed builds: 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS and 13.1-37.279 (FIPS and NDcPP), or later. Rapid7 notes that end-of-life 12.1 and 13.0 get no patch.
  • Check before you patch: CISA and Citrix advise running the indicators of compromise scan and preserving evidence first, because an update can wipe forensic traces and won't evict an attacker who is already in.
  • No workaround exists, per watchTowr's FAQ. If you can't upgrade right away, cutting the appliance's internet exposure is the stopgap security firms describe.

What the NetScaler zero-days do

The Citrix security bulletin CTX697096 covers eight vulnerabilities, but two are the emergency:

  • CVE-2026-88771 is an improper input validation flaw (CWE-20). Citrix says it allows an unauthenticated attacker to execute commands, and it affects all deployments, including default configurations.
  • CVE-2026-88772 is a memory overflow (CWE-119) that can lead to remote code execution or denial of service. Citrix lists one precondition: DTLS, the UDP-based version of TLS that Gateway uses for faster VPN traffic, must be enabled.

CISA added both to its Known Exploited Vulnerabilities catalog on September 27 and gave US federal civilian agencies until September 30 to act under Binding Operational Directive 26-04. The catalog lists ransomware use for both as "Unknown" as of September 29.

The other six CVEs in the bulletin (CVE-2026-88773 through CVE-2026-88778) range from 7.0 to 9.3 and include an HTTP request smuggling flaw and several memory overflows. Citrix does not list them as exploited, and the same builds fix all eight.

Which versions are affected and which builds fix them

BranchVulnerableUpgrade to
NetScaler ADC and Gateway 14.1before 14.1-73.3714.1-73.37 or later
NetScaler ADC and Gateway 13.1before 13.1-64.2313.1-64.23 or later
NetScaler ADC 14.1 FIPSbefore 14.1-73.37 FIPS14.1-73.37 FIPS or later
NetScaler ADC 13.1 FIPS and NDcPPbefore 13.1-37.27913.1-37.279 or later
12.1 and 13.0end of lifea supported branch

Rapid7's analysis of the zero-days points out that 12.1 and 13.0 are past end of life and receive no fix, so an appliance still on either needs a move to 13.1 or 14.1. BleepingComputer reports that Secure Private Access hybrid deployments, which run on NetScaler, are affected too.

Rows of black server racks with blue network cabling in a data center with a raised tile floor
Photo: Carl Lender / Wikimedia Commons, CC BY 2.0

Step 1: Find every NetScaler you run and its build

Start with an inventory, because the appliance you forgot is the one that gets hit. If you manage your fleet with NetScaler Console, its remediation guide for CVE-2026-88771 shows the path: open Security Advisory, then CVE Detection, then the Impacted Instances tab, and filter for the CVE. The scheduled scan can take a couple of hours, so click Scan-Now to get results on demand.

Scale matters here. Palo Alto Networks' Unit 42 threat brief says its Cortex Xpanse tool found 50,277 internet-exposed NetScaler instances that "could potentially be vulnerable" as of September 27. That is an estimate of exposure, not a count of compromised devices.

Step 2: Check whether DTLS is on

CVE-2026-88771 applies to you regardless of setup. CVE-2026-88772 only applies if DTLS is enabled, and Citrix's bulletin warns that it is on by default for VPN virtual servers, which is what a Gateway deployment uses.

Citrix gives two example configuration lines to compare against yours:

  • add vpn vserver vpn1 SSL 10.0.0.0 443 means DTLS is on (the default), so the appliance is exposed.
  • add vpn vserver vpn1 SSL 10.0.0.0 443 -dtls OFF means DTLS is off for that virtual server.

Turning DTLS off does not make you safe: CVE-2026-88771 still applies. Treat this check as a way to understand your exposure, not as a substitute for the upgrade.

Step 3: Look for compromise before you patch

This is the step people skip, and the one every official source puts first. CISA's alert on the zero-days urges organizations to "check for indication of compromise prior to patching" and to preserve forensic evidence, because applying updates "may result in loss of forensic visibility."

What that means in practice, per the sources:

  1. Run Citrix's IOC scan. watchTowr's FAQ on the flaws says the scan runs from the Security Advisory page in NetScaler Console version 14.1-73.36 or later with telemetry enabled, or you can ask Citrix Support for the indicators. Citrix warns the IOCs don't cover every technique, so a clean result is not proof you weren't compromised.
  2. Preserve evidence. Unit 42 recommends keeping snapshots, logs, support bundles and core dumps before you change anything.
  3. Hunt beyond the IOCs. Unit 42 suggests looking for suspicious administrative sessions, unexpected outbound connections and unexplained gaps in logging.

If you find signs of compromise, bring in incident response before you wipe anything.

Step 4: Upgrade to a fixed build

Upgrade each appliance to the build for its branch in the table above. In NetScaler Console, select the affected instances under Impacted Instances and click Proceed to upgrade workflow, which loads them into an upgrade job; Citrix's documentation says several instances can be remediated at once. Rapid7 advises applying the update "on an emergency basis, outside of normal patching cycles."

Step 5: Clean up after the upgrade

Patching closes the door, but it doesn't check who already walked through it. Unit 42 is blunt: "Updating and patching will not remove access for attackers that have already established persistence." watchTowr's FAQ recommends rotating credentials after the update and keeping management interfaces off the internet.

What to do if you can't patch now

There is no configuration workaround for either exploited flaw: watchTowr's FAQ says "upgrading is the only fix." Until you can upgrade:

  • Cut internet exposure where you can. BleepingComputer's report advises organizations that can't update right away to reduce internet exposure where operationally possible, and Unit 42 recommends isolating vulnerable systems from the network.
  • Run the IOC scan and preserve evidence now, so you are ready when the maintenance window comes.
  • Plan the upgrade within days, not weeks. For US federal agencies, CISA's deadline is September 30.

Who told admins to shut NetScalers down

The "shut them down" advice didn't come from Citrix or CISA. According to BleepingComputer, admins posted on Reddit that their IT suppliers' security teams told them to shut their NetScalers down immediately, before any details were public. The outlet also reports that law enforcement, CERTs and national cybersecurity agencies contacted organizations directly, and that the Dutch NCSC-NL sent pre-notification warnings. watchTowr publicly flagged rumors of unpatched NetScaler remote code execution flaws circulating before Citrix confirmed them.

As of September 29, neither the Citrix bulletin nor CISA's alert tells you to power the appliances off. Taking one offline is a local call: it cuts exposure, but on a Gateway it also cuts remote access for your users.

Troubleshooting

  • The Console scan shows nothing: give the scheduled scan a couple of hours, or click Scan-Now. An empty IOC result still doesn't prove the appliance is clean.
  • You're on 12.1 or 13.0: there's no patch for those branches, so plan a move to 13.1 or 14.1 and reduce exposure meanwhile.
  • You run FIPS or NDcPP builds: use the FIPS-specific builds in the table, not the standard ones.
  • Your Gateway has DTLS off: you still need the upgrade for CVE-2026-88771.

You can follow our coverage of flaws like this one on the Cybersecurity tag and in the Software section.

Bottom line

If you run NetScaler ADC or Gateway, these NetScaler zero-days are confirmed exploited by Citrix and CISA, and the only fix is a build of 14.1-73.37, 13.1-64.23 or the matching FIPS release. Run the IOC scan and save evidence first, upgrade next, then rotate credentials, because a patch won't remove an attacker who is already inside. Watch the Citrix bulletin for updates to the indicators and CISA's catalog for any change in the ransomware field.

FAQ

Are CVE-2026-88771 and CVE-2026-88772 being exploited?

Yes. Citrix's bulletin says exploits of both have been observed on unmitigated deployments, and CISA added both to its Known Exploited Vulnerabilities catalog on September 27, 2026. How widespread the attacks are has not been disclosed.

Is there a workaround if I can't upgrade?

No configuration workaround exists for either flaw, according to watchTowr's FAQ. Reducing internet exposure or isolating the appliance lowers the risk until you can upgrade, but it doesn't fix the flaw.

Does turning off DTLS protect my NetScaler?

Only against CVE-2026-88772, and only on the virtual servers where you turn it off. CVE-2026-88771 affects default configurations regardless of DTLS, so you still need the fixed build.

Is NetScaler 13.0 or 12.1 getting a patch?

No. Rapid7 notes both branches are end of life and receive no fix, so the path is an upgrade to a supported 13.1 or 14.1 build.

Filed under Software

Newsletter

New articles, in your inbox.

Free. Unsubscribe in one click. Your email is kept by beehiiv, our newsletter service, and used only for this newsletter.