On 27 September 2026, Citrix released updates for eight security flaws in NetScaler ADC and NetScaler Gateway. Three are critical, and attackers were already using two of them before the fix came out.
Jan Kaastrup, Chief Cybersecurity Advisor at CSIS Security Group, commented: “If your organisation runs NetScaler, treat this as urgent. We recommend updating every affected appliance now and checking internet-facing appliances for signs of compromise.”
CVE-2026-88771 lets an attacker run commands on the appliance over the internet without logging in. It affects every NetScaler ADC and Gateway on an affected version, including those on standard settings.
There is no setting that switches it off. Updating is the only fix.
CVE-2026-88772 is a memory flaw that can let an attacker take control of the appliance or crash it. It affects appliances with DTLS turned on. DTLS is on by default for VPN, so NetScaler Gateway is exposed unless DTLS has been switched off.
Citrix scores both flaws 9.5 out of 10.
The same update fixes six more flaws. Citrix has not reported that these are being exploited, but each one matters if your appliance is set up in the way described.
Update to these versions or newer:
If you updated in August, you need to update again.
Secure Private Access Hybrid setups that use NetScaler also need updating. If Citrix runs NetScaler for you as a cloud service, Citrix handles the update.
Versions 13.0 and older are end of life and will not get a fix. Citrix has not said whether they are affected, but either way they need to be upgraded to a supported version.
Updating does not remove an attacker who is already inside. Treat internet-facing appliances as possibly compromised until you have checked them.
Full technical details are in the Citrix Security Bulletin CTX697096.
We have contacted CSIS clients directly with this guidance. If you are a client and have questions, please speak to your CSIS contact. More detail was provided on ThreatMatch, our threat intelligence platform.
If you are not a CSIS client and think an appliance may have been compromised, our emergency response team is available 24/7.
Sign up for our newsletter and get the latest cybersecurity analysis, reports and events from CSIS delivered straight to your inbox.
CSIS Security Group A/S is a leading European pure-play provider of tech-enabled cybersecurity and intelligence services. Operating 24/7, we deliver Managed Detection & Response, Incident Response, Security Consulting across all sectors, and provide a world-class threat intelligence capability through our SecAlliance brand. Accredited by organisations including CREST, we actively support global security initiatives to positively impact the cyber community.