Citrix has confirmed active exploitation of two critical NetScaler remote-code-execution vulnerabilities and released patches in security bulletin CTX697096, after a weekend in which administrators were warned privately before any public advisory existed. CVE-2026-88771 is caused by improper input validation and permits an unauthenticated attacker to execute arbitrary commands; Citrix rates it 9.5 and states it affects every NetScaler ADC and NetScaler Gateway deployment, "including those using the default configuration", with no optional feature needing to be enabled. CVE-2026-88772 is a memory overflow that can yield remote code execution or denial of service, also rated 9.5, and is reachable where DTLS is enabled — which Citrix notes is the default on VPN virtual servers. The bulletin fixes eight vulnerabilities in total (CVE-2026-88771 through CVE-2026-88778). Affected builds are NetScaler ADC and Gateway 14.1 before 14.1-73.37 and 13.1 before 13.1-64.23, NetScaler ADC FIPS before 14.1-73.37 FIPS, and FIPS and NDcPP before 13.1-37.279; Secure Private Access Hybrid deployments using NetScaler instances are also affected. The bulletin applies only to customer-managed appliances — Cloud Software Group is upgrading Citrix-managed cloud services and managed Adaptive Authentication centrally. CISA added both CVEs to the Known Exploited Vulnerabilities catalog on 27 September, citing "reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally", and advised checking for indications of compromise before patching because the update may result in loss of forensic visibility, with IoCs available through NetScaler Console. The pre-disclosure sequence is the notable part: administrators began reporting on 26–27 September that IT suppliers, law enforcement, CERTs and national agencies were telephoning them to advise shutting appliances down, and watchTowr publicly warned it was "rapidly reacting to rumours" after verifying them with authoritative sources. NetScaler appliances are commonly deployed as internet-facing edge devices providing remote access and application delivery, so a compromise yields a perimeter foothold with a path inward that does not require compromising an endpoint first.
| Attribute | Detail |
|---|---|
| Sector | Global (Macro) |
| Date | 2026-09-28 |
| Source | CISA |
| Reliability | Tier 1 |
| CVEs | CVE-2026-88771, CVE-2026-88772, CVE-2026-88778 |