FALCONINTERNET

CVE-2026-88771 and 88772: Citrix NetScaler Zero-Days Exploited for Days Before the Patch

Security
CVE-2026-88771 and 88772: Citrix NetScaler Zero-Days Exploited for Days Before the Patch

Citrix published security bulletin CTX697096 on September 27, 2026, covering eight vulnerabilities in NetScaler ADC and NetScaler Gateway. Two of them, CVE-2026-88771 and CVE-2026-88772, are critical remote code execution flaws that were already being weaponized before anyone outside the attacker community knew they existed. Both carry a CVSSv4 score of 9.5. CISA added them to its Known Exploited Vulnerabilities catalog the same day the patches dropped and ordered federal agencies to remediate by September 30.

How CVE-2026-88771 and CVE-2026-88772 work

CVE-2026-88771 is an improper input validation flaw (CWE-20) that lets an unauthenticated attacker run arbitrary operating system commands on the appliance. It works against the default NetScaler configuration: no special features need to be enabled, and Citrix rates attack complexity as low, meaning reliable exploitation is achievable against virtually any vulnerable device on the internet. This is the more dangerous of the two.

CVE-2026-88772 is a memory overflow vulnerability (CWE-119) that can lead to remote code execution or denial of service. It requires the DTLS (Datagram Transport Layer Security) feature to be enabled, but DTLS is on by default for VPN virtual servers, so the effective attack surface is nearly as wide. Citrix rates this one higher complexity to exploit, meaning reliable RCE may require more effort, though DoS is likely easier.

Both flaws require only network access. No credentials. No prior foothold inside the organization.

Perimeter devices exploited before a patch existed

NetScaler ADC and Gateway are edge devices that sit at the perimeter handling VPN access, load balancing, and user authentication. A compromised NetScaler is a gateway: attackers who own it see all traffic passing through it and hold a foothold with a clear path inward. Historically, NetScaler vulnerabilities have been a favorite of both ransomware operators and state-sponsored threat groups for exactly this reason.

What makes this incident worse than most: the exploitation started before any patch existed. Security researchers at watchTowr reported credible threat intelligence confirming compromises at multiple organizations during the week of September 22, five days before Citrix released the fixes. European government sources were warning organizations about active attacks throughout that entire week. Attack attempts targeting NetScaler devices in Japan were observed from September 24 onward. By the time Citrix disclosed and patched on September 27, attackers already had a multi-day head start against every affected deployment worldwide.

Affected versions and patched builds

Bulletin CTX697096 identifies the following vulnerable branches and their patched targets:

  • NetScaler ADC and Gateway 14.1: upgrade to 14.1-73.37 or later
  • NetScaler ADC and Gateway 13.1: upgrade to 13.1-64.23 or later
  • NetScaler ADC FIPS 14.1: upgrade to 14.1-73.37 FIPS or later
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP: upgrade to 13.1-37.279 or later

If you are running an older, end-of-life branch, it is not listed as patched. Treat it as vulnerable until confirmed otherwise.

Remediation steps, in order

CISA flagged something important that inverts the usual advice: check for compromise before patching. Applying the update can overwrite or destroy forensic evidence of a breach that occurred during the zero-day window. If there is any chance your appliance was exposed between September 22 and September 27, preserve logs and disk state first, then upgrade.

Practically:

  • Verify your version immediately. From the CLI, run show version. If the output shows anything below the patched thresholds above, you are vulnerable right now.
  • Audit the zero-day window. Citrix's NetScaler Console provides indicators of compromise. Review logs from September 22–27 for unexpected command execution, unrecognized administrator sessions, or anomalous outbound connections.
  • Upgrade on an emergency basis. Rapid7 used that phrase deliberately: waiting for your next maintenance window is not appropriate here. These CVEs have been actively exploited for days.
  • No workaround exists for CVE-2026-88771, so patching is the only fix. For CVE-2026-88772, disabling DTLS on VPN virtual servers eliminates the attack surface if an immediate patch is not possible.
  • Restrict management-plane access to the appliance from known-good IP ranges while the upgrade window opens, to reduce lateral exposure during remediation.

Mid-size organizations using Citrix remote access

NetScaler isn't exclusively enterprise technology. Many mid-market businesses run NetScaler Gateway for VPN and hybrid-workforce access, often deployed by a consultant or MSP and then left on autopilot for months or years. That steady-state posture is exactly the exposure model attackers count on: an internet-facing appliance running software from 2024 that nobody has touched since the implementation project closed.

If your organization uses Citrix for remote access in any form, this week is the time to confirm exactly what version is running. The September 30 CISA deadline applies to federal agencies under Binding Operational Directive 26-04, but it signals clearly that the threat actors involved are not waiting for a convenient maintenance window. Neither should you.

Active-exploitation zero-days on perimeter appliances are precisely the scenario where 24x7x365 NOC monitoring earns its place, catching version drift and live threat signals before the attackers have had days to work undisturbed.

Need this handled instead of explained?

We do this for a living — talk to an engineer about your setup.