The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway are being exploited globally. Both flaws, CVE-2026-88771 and CVE-2026-88772, carry a CVSS score of 9.5 and can allow an unauthenticated attacker to execute arbitrary commands or code remotely under certain conditions.

NetScaler appliances commonly sit at the network edge and process critical traffic. Real illustrative photo: Unsplash
CISA Adds Both Flaws to the KEV Catalog
CISA added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) catalog on September 27, 2026, after receiving reports and partner intelligence confirming active exploitation. The agency required U.S. federal civilian organizations to complete remediation by September 30, 2026, and urged all organizations to treat the flaws as an emergency priority.
CVE-2026-88771 Enables Pre-Authentication Command Injection
CVE-2026-88771 is an improper input validation flaw affecting all NetScaler ADC and NetScaler Gateway deployments. According to watchTowr Labs, a Perl script used to process crash information builds a system command from attacker-controlled data. This creates a path for a pre-authentication request to trigger command execution with root privileges.
CVE-2026-88772 Threatens Servers with DTLS Enabled
CVE-2026-88772 stems from improper restriction of operations within a memory buffer. It can lead to remote code execution or denial of service when DTLS is enabled. Because DTLS is enabled by default on VPN virtual servers, many publicly exposed systems may be affected.
Exposure Scale and Signs of Attack
Palo Alto Networks Unit 42 identified more than 50,277 publicly exposed NetScaler appliances that were potentially vulnerable as of September 27. GreyNoise observed the earliest exploitation attempt on September 24; the threat actor tried to obtain a root shell, install a password-protected web shell, and disguise its communication path as a CSS file.
Patched Versions
Citrix has released fixes in NetScaler ADC and NetScaler Gateway 14.1-73.37 and later, version 13.1-64.23 and later, NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later, and version 13.1-FIPS and 13.1-NDcPP 13.1.37.279 and later. NetScaler ADC and Gateway versions 12.1 and 13.0 have reached end of life and should be upgraded to a supported release.
Installing the Patch Alone Is Not Enough
Because exploitation has already occurred, patching only prevents new intrusions and does not remove an existing compromise. Administrators should run the indicators of compromise provided by Citrix through NetScaler Console, preserve evidence, isolate suspicious appliances, and review every server previously connected to them.
Response Process for Suspected Compromise
Organizations should revoke credentials and active sessions, rebuild appliances on the latest firmware from a trusted source, rotate all local account passwords and Key Encryption Keys (KEKs), and replace associated SSL certificates when restoring from a known-good backup. NetScaler hardening guidance should then be applied before returning the system to service.
Priority Actions for Organizations
Security teams should inventory every Internet-facing NetScaler appliance, confirm its version and DTLS status, and prioritize patches for VPN endpoints and edge devices. Authentication logs, web processes, configuration files, and anomalous traffic dating back to September 24 should be included in the investigation. Devices that cannot be patched immediately should be isolated from the Internet or taken out of service until remediation is complete.
Lessons from the NetScaler Incident
Edge appliances have broad access and often fall outside routine update cycles, making them high-value targets. The KEV catalog helps organizations shift from theoretical severity scores to real-world exploitation risk, but effective defense still requires asset management, monitoring for indicators of compromise, and a tested recovery plan.
VNCyberS compiled from CISA, Citrix, and The Hacker News















