Citrix NetScaler: Two Actively Exploited Zero-Days. Patching Alone Is Not Enough.
Attackers are exploiting two critical vulnerabilities in NetScaler ADC and NetScaler Gateway. Patching now closes the vulnerability. The patch does not determine whether an attacker is already in the system.
Key Points.
On September 27, 2026, Citrix disclosed eight vulnerabilities in NetScaler ADC and NetScaler Gateway. Two of them (CVE-2026-88771 and CVE-2026-88772, CVSS 9.5) are already being actively exploited and allow attackers to remotely execute code without authentication. An exploit is now publicly available. Security researchers are observing widespread, automated attacks. T
he supported product versions listed below are generally affected. No special configuration is required for CVE-2026-88771: All customer-managed NetScaler ADC and NetScaler Gateway deployments running a vulnerable build are affected. For the remaining seven vulnerabilities, the configuration prerequisites described in the Citrix Security Bulletin apply. The BSI classifies the situation as Criticality 3 out of 4 (Orange): Measures must be taken immediately.
Your most important tasks: Identify affected instances and update them to a patched build as soon as possible. For CVE-2026-88778, you must then also implement the TCP configuration change specified by Citrix.
Also, check for any indications that a compromise has already occurred. For CVE-2026-88771, Citrix does not provide a configuration workaround to replace the upgrade!
Am I affected?
You are affected if you operate NetScaler ADC or NetScaler Gateway yourself and are using a version listed in the left column. This also applies to Secure Private Access hybrid deployments that use their own NetScaler instances. For CVE-2026-88771, no additional features or special configuration are required; even the default configuration is affected.
|
Product Line |
Affected |
Fixed as of |
|---|---|---|
|
NetScaler ADC and Gateway 14.1 |
prior to 14.1-73.37 |
14.1-73.37 |
|
NetScaler ADC and Gateway 13.1 |
prior to 13.1-64.23 |
13.1-64.23 |
|
NetScaler ADC 14.1-FIPS |
Prior to 14.1-73.37 FIPS |
14.1-73.37 FIPS |
|
NetScaler ADC 13.1-FIPS and 13.1-NDcPP |
prior to 13.1-37.279 |
13.1-37.279 |
You can view your version number in the NetScaler interface or via the command line using the `show version` command. Citrix describes which additional configurations are relevant for the remaining six vulnerabilities in the security bulletin (see Sources).
What to Do Now.
Follow the steps below in this order. Checking for a possible compromise is also relevant for systems that have already been updated.
1. Determine impact and reduce exposure.
Identify all NetScaler instances, including HA, cluster, standby, and DR systems. Check the build, internet accessibility, and DTLS configuration. Restrict access to vulnerable systems as much as operationally feasible until the update is applied.
2. Back up forensic data—without delaying the update.
If possible, create a snapshot and back up relevant logs. If specific anomalies are detected, coordinate any further changes to the system with an incident response team.
3. Apply the patch.
Update to the version listed in the table above. For perimeter systems, do not wait for the next regular maintenance window.
▪ Citrix offers some newer builds marked as “Early Access.” Test these before deployment.
▪ Additionally, address CVE-2026-88778. For instances that meet the criteria for CVE-2026-88778, remediation is only complete after two steps: First, update the instance to a build that includes the fix, and then apply the TCP configuration change provided by Citrix for Enhanced ISN Generation. Afterward, check the security posture again.
4. Check for compromise.
Warning: The vulnerabilities were exploited before patches were available. A patched system may therefore already be compromised—in other words, the patch does not remove an attacker’s already established access!
▪ Citrix provides Indicators of Compromise (IOCs) via the NetScaler Console (Security Advisory, IOC Scan; according to Citrix, this is available starting with Console version 14.1-73.36 with telemetry enabled). If you do not have the Console, you can request the IOCs directly from Citrix Support.
▪ Citrix updates the IOCs as soon as new information becomes available. Therefore, check regularly over the next few weeks to see if an update is available, and repeat the scan.
▪ Important: The result “No Compromise Detected” is not a definitive all-clear. Citrix explicitly notes that the IOC information does not cover all attack techniques, may have limited forensic value, and may overlook actual compromises.
5. If you suspect a compromise: investigate the entire chain of events.
A compromised NetScaler is often just the starting point.
▪ Immediately isolate systems with concrete evidence of a compromise.
▪ Have the system thoroughly analyzed and rule out the possibility that attackers have reached other systems on the network via lateral movement.
▪ Rotate or revoke, on a risk-based basis, any credentials, keys, certificates, tokens, and sessions that an attacker may have accessed during the identified period of compromise.
▪ Contact an incident response team immediately, such as our SIRT (contact information below).
There are no workarounds in the strict sense. Citrix lists configurations for some of the eight vulnerabilities that prevent exploitation. However, this does not protect against CVE-2026-88771, which has already been exploited.
Why this is urgent.
NetScaler sits at the edge of the network and controls access to internal applications. This is precisely why attackers have repeatedly exploited Citrix vulnerabilities in the past as a way to gain entry into corporate networks. On September 27, the U.S. agency CISA added both vulnerabilities to its catalog of actively exploited vulnerabilities.
Since a proof-of-concept was made public, attacks have expanded from targeted individual incidents to widespread scans. According to figures from security researchers (as of September 29), approximately 5,700 NetScaler systems in Germany are accessible from the internet, and less than one-tenth of them worldwide have been patched.
Added to this is the speed of the threat. The BSI assumes that AI-powered exploit development is making it possible to analyze patches faster and faster. The six additional vulnerabilities, for which there are currently no reports of attacks, are therefore likely to be exploited soon as well.
How Bechtle Can Help.
You can implement the steps above on your own. If you currently lack the time or experience to do so, we’re here to help.
|
Your situation. |
Our Support. |
|
|---|---|---|
|
You need help with patching. |
Our Citrix specialists will update your appliances and verify the configuration. Contact: Your local Bechtle IT service provider |
|
|
You’ve applied the patches and want to make sure no one is on the system. |
Contact: Your local Bechtle IT service provider |
|
|
You have a specific suspicion or have noticed unusual activity. |
Our Security Incident Response Team (SIRT) handles analysis and containment around the clock (please understand that there may be wait times due to the high volume of requests) |
Sources
- Citrix: Security Bulletin CTX697096 for CVE-2026-88771 through CVE-2026-88778 (September 27, 2026)
- Citrix: Security Bulletin on the Tech Zone Blog with additional information
- NetScaler Docs: Locating and Updating Affected Instances in the NetScaler Console
- Citrix: Best Practices for NetScaler ADC Deployments
- BSI: Recommendations for the Secure Use of Application Delivery Controllers
- watchTowr: FAQ on CVE-2026-88771 and CVE-2026-88772
- Help Net Security: NetScaler zero-day exploitation escalates into mass attacks (September 29, 2026)