Summary
Two vulnerabilities, CVE-2026-88771 and CVE-2026-88772, have been identified in Citrix NetScaler ADC and NetScaler Gateway, widely used appliances for remote access and application delivery. Both have been given a CVSS base score of 9.5 and allow an unauthenticated attacker with network access to remotely execute code on the appliance. Citrix and CISA have confirmed both are being actively exploited in the wild. Fixed versions are available and no workarounds exist.
Threat description
On 26 September 2026, security firm watchTowr publicly warned that unpatched vulnerabilities in Citrix NetScaler were being exploited. On 27 September 2026, Citrix published security bulletin CTX697096 with fixes, and CISA added both vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalogue.
NetScaler ADC and NetScaler Gateway sit at the edge of an organisation's network. They are commonly used to give staff remote access (VPN, virtual desktops) and to load-balance and protect internet-facing applications. Because of this position, NetScaler appliances have been a frequent target for attackers in recent years.
What is currently known
- CVE-2026-88771 (CVSS 9.5): improper input validation that lets an unauthenticated attacker run arbitrary commands on the appliance. It affects the default configuration and has low attack complexity.
- CVE-2026-88772 (CVSS 9.5): a memory overflow that can lead to remote code execution or denial of service. It affects appliances with DTLS enabled, which is the default for VPN virtual servers.
- Neither vulnerability requires valid credentials; network access to the appliance is enough.
- Confirmed exploitation of both vulnerabilities on unmitigated appliances, and reports that exploitation is taking place globally.
- Citrix's bulletin also covers six further vulnerabilities with CVSS scores between 7.0 and 9.3. Exploitation of those has not been confirmed.
- Fixed versions: NetScaler ADC and Gateway 14.1-73.37 and later, 13.1-64.23 and later.
What is still unknown
- How long the vulnerabilities were exploited before public disclosure.
- The scale of exploitation and which threat actors are involved.
Examples of possible risks
Depending on how an organisation uses NetScaler, successful exploitation could, for example, allow an attacker to:
- Gain a foothold on the network perimeter and move laterally into internal systems.
- Steal session tokens, credentials or certificates handled by the appliance.
- Intercept or tamper with traffic passing through the appliance.
- Disrupt remote access for staff through denial of service.
These are examples only. The actual impact will depend on each organisation's configuration and environment.
Applicability
This threat could affect any organisation that uses Citrix NetScaler ADC or NetScaler Gateway (including FIPS and NDcPP builds) on a version earlier than the fixed releases listed above. This includes appliances managed or hosted on an organisation's behalf by a third party.
NetScaler is widely used for remote access and virtual desktop delivery, so exposure is likely to be common across sectors such as financial services, professional services, healthcare and the public sector. Organisations that have already patched may still be affected if their appliances were compromised before the fix was applied.
Relevance to the supply chain
It is important to understand the extent to which your supply chain is affected by this threat because NetScaler is often the front door to a supplier's network. A compromised appliance can give an attacker access to the systems where your data is processed, or to the remote access paths your suppliers use to reach your environment.
We have published this threat on Risk Ledger because it meets our triage criteria: it is actively exploited, affects a widely used technology in its default configuration, and suppliers can give a clear answer on their exposure, patching and investigation. Because exploitation began before a fix was available, patching alone does not confirm that a supplier was not compromised, so we have also asked suppliers whether they have investigated for signs of compromise and rotated exposed credentials.
What should you do about it
There are a few immediate actions you can take to help protect yourself from this threat:
- Identify whether any of your systems are running Citrix NetScaler ADC or NetScaler Gateway, and which versions. Include appliances managed on your behalf.
- Preserve evidence before patching, if you suspect compromise. Capture logs, snapshots and core dumps from affected appliances.
- Update each instance to a fixed version (14.1-73.37 or later, 13.1-64.23 or later, or the corresponding FIPS/NDcPP build), as set out in Citrix bulletin CTX697096. Prioritise internet-facing appliances. There is no workaround, so if you cannot patch immediately, consider restricting access or taking appliances offline.
- Hunt for signs of exploitation on appliances that were exposed before patching. Citrix has not yet published IoCs, so monitor CISA and vendor updates and review appliance logs for unusual activity.
- Rotate credentials, sessions and certificates that were handled by or stored on affected appliances. If compromise is suspected, isolate the appliance and follow Citrix's incident guidance.
- Understand to what extent your suppliers or partners are affected, using their responses on Risk Ledger.
- Support your suppliers through actions 1 to 5.
Where to find more information
This is an evolving situation. You can keep up to date with the latest information on this threat by reading:
- CISA: Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway
- CISA Known Exploited Vulnerabilities catalogue
- Citrix security bulletin CTX697096
- NVD: CVE-2026-88771 and NVD: CVE-2026-88772
- watchTowr: Citrix NetScaler Zero-Day RCE FAQ
- Rapid7: Zero-Day Exploitation of Citrix NetScaler ADC and Gateway
- NCSC news and alerts
To understand how your supply chain is affected by the Citrix NetScaler zero-days, create your free account on Risk Ledger. You can find out more about how the Emerging Threats feature on Risk Ledger works here.



