Resources

Citrix NetScaler Zero-Days: Emerging Threat published on Risk Ledger

Two actively exploited Citrix NetScaler zero-days allow unauthenticated remote code execution. See fixed versions and what to ask your suppliers.
Emily Hodges
|
Chief Operating Officer
September 28, 2026
|
4
mins read
Citrix NetScaler Zero-Days: Emerging Threat published on Risk Ledger

Threat summary

CVE-2026-88771 and CVE-2026-88772 are critical, actively exploited vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway that let an unauthenticated attacker run code on an unpatched appliance.

  • Both carry a CVSS score of 9.5, and CISA added both to its Known Exploited Vulnerabilities catalogue on 27 September 2026.
  • CVE-2026-88771 affects appliances in their default configuration. CVE-2026-88772 needs DTLS, which is on by default for VPN virtual servers.
  • Fixed builds are 14.1-73.37 and 13.1-64.23 or later, plus the matching FIPS and NDcPP builds. There is no workaround.
  • Exploitation started before a fix existed, so a patched appliance may still have been compromised.
  • Ask suppliers that run NetScaler whether they've patched, checked for compromise and rotated exposed credentials.

‍

Summary

Two vulnerabilities, CVE-2026-88771 and CVE-2026-88772, have been identified in Citrix NetScaler ADC and NetScaler Gateway, widely used appliances for remote access and application delivery. Both have been given a CVSS base score of 9.5 and allow an unauthenticated attacker with network access to remotely execute code on the appliance. Citrix and CISA have confirmed both are being actively exploited in the wild. Fixed versions are available and no workarounds exist.

‍

Threat description

On 26 September 2026, security firm watchTowr publicly warned that unpatched vulnerabilities in Citrix NetScaler were being exploited. On 27 September 2026, Citrix published security bulletin CTX697096 with fixes, and CISA added both vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalogue.

NetScaler ADC and NetScaler Gateway sit at the edge of an organisation's network. They are commonly used to give staff remote access (VPN, virtual desktops) and to load-balance and protect internet-facing applications. Because of this position, NetScaler appliances have been a frequent target for attackers in recent years.

What is currently known

  • CVE-2026-88771 (CVSS 9.5): improper input validation that lets an unauthenticated attacker run arbitrary commands on the appliance. It affects the default configuration and has low attack complexity.
  • CVE-2026-88772 (CVSS 9.5): a memory overflow that can lead to remote code execution or denial of service. It affects appliances with DTLS enabled, which is the default for VPN virtual servers.
  • Neither vulnerability requires valid credentials; network access to the appliance is enough.
  • Confirmed exploitation of both vulnerabilities on unmitigated appliances, and reports that exploitation is taking place globally.
  • Citrix's bulletin also covers six further vulnerabilities with CVSS scores between 7.0 and 9.3. Exploitation of those has not been confirmed.
  • Fixed versions: NetScaler ADC and Gateway 14.1-73.37 and later, 13.1-64.23 and later.

What is still unknown

  • How long the vulnerabilities were exploited before public disclosure.
  • The scale of exploitation and which threat actors are involved.

Examples of possible risks

Depending on how an organisation uses NetScaler, successful exploitation could, for example, allow an attacker to:

  • Gain a foothold on the network perimeter and move laterally into internal systems.
  • Steal session tokens, credentials or certificates handled by the appliance.
  • Intercept or tamper with traffic passing through the appliance.
  • Disrupt remote access for staff through denial of service.

These are examples only. The actual impact will depend on each organisation's configuration and environment.

‍

Applicability

This threat could affect any organisation that uses Citrix NetScaler ADC or NetScaler Gateway (including FIPS and NDcPP builds) on a version earlier than the fixed releases listed above. This includes appliances managed or hosted on an organisation's behalf by a third party.

NetScaler is widely used for remote access and virtual desktop delivery, so exposure is likely to be common across sectors such as financial services, professional services, healthcare and the public sector. Organisations that have already patched may still be affected if their appliances were compromised before the fix was applied.

‍

Relevance to the supply chain

It is important to understand the extent to which your supply chain is affected by this threat because NetScaler is often the front door to a supplier's network. A compromised appliance can give an attacker access to the systems where your data is processed, or to the remote access paths your suppliers use to reach your environment.

We have published this threat on Risk Ledger because it meets our triage criteria: it is actively exploited, affects a widely used technology in its default configuration, and suppliers can give a clear answer on their exposure, patching and investigation. Because exploitation began before a fix was available, patching alone does not confirm that a supplier was not compromised, so we have also asked suppliers whether they have investigated for signs of compromise and rotated exposed credentials.

‍

What should you do about it

There are a few immediate actions you can take to help protect yourself from this threat:

  1. Identify whether any of your systems are running Citrix NetScaler ADC or NetScaler Gateway, and which versions. Include appliances managed on your behalf.
  2. Preserve evidence before patching, if you suspect compromise. Capture logs, snapshots and core dumps from affected appliances.
  3. Update each instance to a fixed version (14.1-73.37 or later, 13.1-64.23 or later, or the corresponding FIPS/NDcPP build), as set out in Citrix bulletin CTX697096. Prioritise internet-facing appliances. There is no workaround, so if you cannot patch immediately, consider restricting access or taking appliances offline.
  4. Hunt for signs of exploitation on appliances that were exposed before patching. Citrix has not yet published IoCs, so monitor CISA and vendor updates and review appliance logs for unusual activity.
  5. Rotate credentials, sessions and certificates that were handled by or stored on affected appliances. If compromise is suspected, isolate the appliance and follow Citrix's incident guidance.
  6. Understand to what extent your suppliers or partners are affected, using their responses on Risk Ledger.
  7. Support your suppliers through actions 1 to 5.

‍

Where to find more information

This is an evolving situation. You can keep up to date with the latest information on this threat by reading:

‍

To understand how your supply chain is affected by the Citrix NetScaler zero-days, create your free account on Risk Ledger. You can find out more about how the Emerging Threats feature on Risk Ledger works here.

Emerging Threat

Download for free

Pattern Trapezoid Mesh

Get the security manager's briefing

Monthly research, case studies and practical guides you won't find anywhere else.

Join thousands of security managers turning their TPRM programmes into success stories.