Citrix NetScaler CVE-2026-88771 and 88772: What to Do Now

Critical Citrix NetScaler vulnerabilities under active exploitation: what to do now

On 27 September 2026, Citrix released updates for eight security flaws in NetScaler ADC and NetScaler Gateway. Three are critical, and attackers were already using two of them before the fix came out.

Jan Kaastrup, Chief Cybersecurity Advisor at CSIS Security Group, commented: “If your organisation runs NetScaler, treat this as urgent. We recommend updating every affected appliance now and checking internet-facing appliances for signs of compromise.”

 

The two flaws being exploited

CVE-2026-88771 lets an attacker run commands on the appliance over the internet without logging in. It affects every NetScaler ADC and Gateway on an affected version, including those on standard settings.

There is no setting that switches it off. Updating is the only fix.

CVE-2026-88772 is a memory flaw that can let an attacker take control of the appliance or crash it. It affects appliances with DTLS turned on. DTLS is on by default for VPN, so NetScaler Gateway is exposed unless DTLS has been switched off.

Citrix scores both flaws 9.5 out of 10.

 

The other six flaws

The same update fixes six more flaws. Citrix has not reported that these are being exploited, but each one matters if your appliance is set up in the way described.

  • CVE-2026-88773 (critical): Lets an attacker sneak hidden requests past the appliance to the servers behind it. Affects appliances that handle web traffic.

  • CVE-2026-88774 (high): Lets specially crafted web addresses get around security rules that check URLs.

  • CVE-2026-88775 (high): A memory flaw that can crash the appliance or make it behave unpredictably. Affects appliances used for VPN, remote access or login.

  • CVE-2026-88776 (high): The same type of flaw, on appliances that load balance Oracle database traffic.

  • CVE-2026-88777 (high): The same type of flaw, on appliances that use certain non-web protocols, such as FTP, for load balancing or network address translation.

  • CVE-2026-88778 (high): Makes network connections easier to predict, which can help an attacker interfere with them. This one needs a setting change as well as the update.

 

Which versions to install

Update to these versions or newer:

  • NetScaler ADC and Gateway 14.1: 14.1-73.37

  • NetScaler ADC and Gateway 13.1: 13.1-64.23

  • NetScaler ADC 14.1-FIPS: 14.1-73.37 FIPS

  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP: 13.1-37.279

If you updated in August, you need to update again.

Secure Private Access Hybrid setups that use NetScaler also need updating. If Citrix runs NetScaler for you as a cloud service, Citrix handles the update.

Versions 13.0 and older are end of life and will not get a fix. Citrix has not said whether they are affected, but either way they need to be upgraded to a supported version.

 

What to do now

  1. If you can, check each appliance for signs of compromise before you update, for example with the built-in check in NetScaler Console. Save evidence such as logs first, because updating can wipe traces an investigator will need.

  2. Update all NetScaler appliances as soon as possible, including backup and cluster appliances.

  3. If you cannot update right away, cut the appliance off from the internet or take it offline until it is updated.

  4. For CVE-2026-88778, turn on Enhanced ISN Generation.

  5. After updating, sign out all active users.

Updating does not remove an attacker who is already inside. Treat internet-facing appliances as possibly compromised until you have checked them.

Full technical details are in the Citrix Security Bulletin CTX697096.

We have contacted CSIS clients directly with this guidance. If you are a client and have questions, please speak to your CSIS contact. More detail was provided on ThreatMatch, our threat intelligence platform.

If you are not a CSIS client and think an appliance may have been compromised, our emergency response team is available 24/7.


Stay updated

Sign up for our newsletter and get the latest cybersecurity analysis, reports and events from CSIS delivered straight to your inbox.

bg light

CSIS Newsletter

CSIS_PRI_LOGO_TURQUOISE_RGB

 

 


About CSIS

CSIS Security Group A/S is a leading European pure-play provider of tech-enabled cybersecurity and intelligence services. Operating 24/7, we deliver Managed Detection & Response, Incident Response, Security Consulting across all sectors, and provide a world-class threat intelligence capability through our SecAlliance brand. Accredited by organisations including CREST, we actively support global security initiatives to positively impact the cyber community.