Sep 28, 2026

Citrix NetScaler: Two Critical Zero-Days Put VPNs on Alert

Back to blog

The headline landed on a Sunday, but the problem had been building before the weekend. On September 27, 2026, Citrix published updates for eight flaws in NetScaler ADC and NetScaler Gateway. Two of them, CVE-2026-88771 and CVE-2026-88772, were rated critical, can enable remote code execution, and were already being exploited before many teams had time to schedule maintenance.

The official Citrix bulletin confirms exploitation on unmitigated systems. CISA added both CVEs to its KEV catalog on the same day and warned that global exploitation is confirmed. This is not a theoretical vulnerability: it is a race between attackers looking for exposed appliances and administrators who need to preserve evidence before updating.

Illustration of two Citrix NetScaler devices used as application delivery controllers
NetScaler commonly sits at the network edge, handling VPN, authentication, and application traffic. Illustration: OpenClipart/FreeSVG, public domain

What exactly happened?

Citrix fixed eight vulnerabilities in the same package, but two carry the urgency. CVE-2026-88771 is described as an input validation flaw that can let an unauthenticated attacker execute arbitrary commands. CVE-2026-88772 involves memory overflow and can also lead to remote code execution or denial of service, especially when DTLS is enabled on NetScaler ADC or Gateway.

The uncomfortable part is where the product sits. NetScaler ADC and Gateway are not quiet servers hidden on an internal subnet: they are edge components. They are often exposed to the internet for VPN, ICA Proxy, CVPN, RDP Proxy, load balancing, and authentication. When a remote flaw appears there, the whole perimeter is in play.

Why are these two CVEs treated as zero-days?

Because exploitation was observed before most organizations could apply public fixes. CISA says it received reports and partner threat intelligence confirming global exploitation. watchTowr, which followed the case before the official identifiers existed, described the incident as two NetScaler RCE zero-days and published a technical FAQ with the timeline: public warning on September 26, Citrix bulletin and KEV entries on September 27.

The zero-day label does not mean every appliance is compromised. It means there was a window in which attackers could exploit the flaw before a public fix existed. In remote-access products, that window is especially dangerous because the exposed surface is easy to find.

Who needs to act first?

Any team running NetScaler ADC or NetScaler Gateway should treat this as a priority, but the urgency is highest for appliances directly exposed to the internet, used as VPN or AAA virtual servers, or running with DTLS enabled. Citrix lists fixed builds including 14.1-73.37, 13.1-64.23, and the applicable FIPS/NDcPP variants. The practical guidance is simple: identify every appliance, confirm its version and update plan, and do not assume a forgotten box in a secondary data center is out of reach.

BleepingComputer adds the scale: Shadowserver tracks more than 23,000 IP addresses with exposed NetScaler fingerprints, including roughly 22,000 ADC appliances and more than 1,500 Gateway instances. Not all of them will be vulnerable, but the footprint explains why these bugs receive immediate attention.

Citrix icon used by the official support page
The Citrix support page is the canonical reference for fixed builds, preconditions, and update notes. Image: Citrix Support

Should teams update immediately or investigate first?

The short answer is: both, but in the right order. CISA recommends, where possible, checking for signs of compromise before applying the update, because the process may reduce forensic visibility. Citrix provides generic indicators through NetScaler Console, but also warns that those indicators may not cover every attacker technique.

That creates a real operations tension. Waiting too long increases exploitation risk. Updating without preserving logs, snapshots, or support bundles can erase important clues if the appliance has already been used as an entry point. For smaller teams, the message is not to stage a cinematic investigation; it is to retain minimum evidence, run the available checks, and update to the fixed build without turning analysis into a reason for delay.

Is there a workaround?

For the two critical flaws, the public guidance is to update. watchTowr puts it plainly: there is no published workaround that replaces installing the fixed builds. For CVE-2026-88772, Citrix explains that DTLS is a relevant precondition and is enabled by default on VPN vServer, but disabling one configuration component should not be treated as the final answer for an exposed appliance that may already have been probed.

The distinction between temporary mitigation and a real fix matters here. In perimeter incidents, attackers often return to targets they have already mapped. An appliance left partially mitigated, without a corrected version and without compromise review, remains a risky bet.

Why does this matter beyond Citrix customers?

Because this is another reminder that the enterprise perimeter is still a collection of critical, proprietary boxes that are hard to take offline. VPNs, gateways, firewalls, and ADCs must be reachable to do their job, but that reachability turns every authentication, parsing, or memory bug into a direct intrusion opportunity.

The lesson from September 2026 is not only "patch Citrix". It is inventory, telemetry, and emergency rehearsal. If an organization does not know how many exposed appliances it has, what versions they run, who approves maintenance windows, and where forensic logs live, then every zero-day starts late. NetScaler is this week's name; the pattern is much larger.

Comments (2)

Anti-spam powered by Cloudflare Turnstile.