Security

Citrix patches two actively exploited NetScaler zero days as CISA sets September 30 deadline

Citrix shipped emergency fixes for two NetScaler remote code execution flaws that attackers were already exploiting, and US federal agencies must remediate them by September 30, 2026.

T
By TechQuire Daily Staff TechQuire Daily Staff
September 28, 2026 / 7 min read

Citrix NetScaler ADC and NetScaler Gateway are among the most widely deployed pieces of application delivery and remote access infrastructure in the world. Enterprises use them to balance traffic, terminate VPN connections and publish internal services to the internet. Because the appliances sit directly on the network edge, they are a favorite target for attackers looking for a way into corporate environments. That position has made NetScaler a recurring target of emergency patching cycles.

The first public warnings did not come from the vendor. On September 26, 2026, administrators on the r/Citrix forum reported that their IT suppliers and security teams were calling to advise them to shut down NetScaler appliances immediately, sometimes without explaining why. The same day, the security firm watchTowr wrote on X that it was reacting to rumors that multiple unpatched NetScaler remote code execution vulnerabilities were circulating in the wild. The company described the information as credible even though details were scarce, and said the flaws had been found during forensic investigations. The Dutch National Cyber Security Centre also sent a pre-notification to organizations in the Netherlands.

Citrix confirmed the problem the following day. On September 27, 2026, the company published security bulletin CTX697096, disclosing eight vulnerabilities in customer managed NetScaler ADC and NetScaler Gateway appliances. Two of them, tracked as CVE-2026-88771 and CVE-2026-88772, had already been exploited in the wild as zero-days. Both carry a CVSS v4.0 base score of 9.5. Citrix said that exploitation of the two flaws had been observed against unmitigated NetScaler deployments, and it shipped fixes for them along with patches for the other six issues.

The same day, the US Cybersecurity and Infrastructure Security Agency added both vulnerabilities to its Known Exploited Vulnerabilities catalog. CISA cited reports and partner threat intelligence confirming that threat actors were exploiting the flaws globally, and it set a remediation deadline of September 30, 2026 for federal civilian agencies covered by its requirements. That gave many government defenders only three days, including a weekend, to find, patch or take offline appliances that are often difficult to update without service disruption.

Key Facts

The two exploited flaws differ in reach but are equally severe. CVE-2026-88771 is an improper input validation vulnerability that lets an unauthenticated attacker run arbitrary commands on the appliance. It affects every NetScaler ADC and NetScaler Gateway deployment running an affected build, including those in the default configuration, and it does not require any additional feature to be enabled. Security Affairs reported on September 28, 2026 that CISA added the flaw as a Citrix NetScaler improper input validation vulnerability that applies to default deployments.

CVE-2026-88772 is a memory overflow, classified as CWE-119, meaning improper restriction of operations within the bounds of a memory buffer. It can lead to remote code execution or denial of service. Exploitation requires DTLS to be enabled, but DTLS is enabled by default on VPN virtual servers, so many internet facing deployments are exposed without any administrator action. The Hacker News reported on September 27, 2026 that the flaw affects appliances with DTLS enabled, which is on by default for VPN virtual servers.

Citrix says administrators should upgrade to NetScaler ADC and NetScaler Gateway 14.1-73.37 and later, or 13.1-64.23 and later. FIPS and NDcPP builds have their own fixed versions: 14.1-73.37 FIPS and later, and 13.1-37.279 and later. Appliances still running 14.1-73.32 and 13.1-63.21, the builds that fixed the August authentication bypass tracked as CVE-2026-19490, fall inside the affected range and need the new update. SOCRadar reported on September 28, 2026 that Citrix released emergency updates for eight vulnerabilities in bulletin CTX697096.

The same bulletin also fixed six lower rated flaws, including CVE-2026-88773, an HTTP request smuggling issue rated 9.3, and CVE-2026-88774, a policy bypass rated 7.0, along with four memory overflow and TCP initial sequence number issues rated 8.8. One of those, CVE-2026-88778, involves TCP ISN prediction and is mitigated by enabling Enhanced ISN Generation, which means that upgrading alone is not the complete remediation for that particular flaw. CSO Online reported on September 28, 2026 that Citrix made generic indicators of compromise available through NetScaler Console.

Exposure data underlines the scale of the problem. Cybernews reported on September 28, 2026 that Shadowserver tracking found about 22,000 exposed NetScaler ADC instances visible online, with roughly 8,800 of them in the United States, alongside approximately 1,700 NetScaler Gateway instances. This is also the third round of emergency NetScaler patches since June 2026.

Analysis

What this really means is that the edge of the network remains the softest part of enterprise defense, and that the patching treadmill for security appliances is now a permanent operational burden. NetScaler boxes are not optional tools for most of the organizations that run them. They terminate VPN sessions and route application traffic, so taking them offline to patch means interrupting remote work and customer facing services. That friction is exactly what attackers count on, and it explains why the window between disclosure and exploitation keeps shrinking.

The forensic problem is just as serious. Because this was the first public disclosure, organizations cannot tell from the patch alone whether a device was already breached. Agnidipta Sarkar, chief evangelist at ColorTokens, said that remote code execution on these NetScaler deployments means an unauthenticated remote attacker can run arbitrary commands on the appliance, typically with high privileges. He added that successful attackers install persistent backdoors and webshells, modify configurations, disable logging, create rogue virtual servers, or brick and deny service to the device, and that they could then pivot into the internal network and reach Active Directory.

The bigger picture here is that Citrix is fighting a structural problem rather than a single bug. Three emergency NetScaler patch cycles since June 2026, including the August authentication bypass CVE-2026-19490, suggest that the code base is under sustained adversarial scrutiny. The two September zero-days are not related to CVE-2026-19490 and CVE-2026-19489 disclosed in August, according to Security Affairs, so defenders cannot assume that last month's update covers this month's threat.

The early warning network also moved faster than the formal one. watchTowr CEO Benjamin Harris wrote in a LinkedIn post on Sunday that Monday would be too late, before Citrix had published its bulletin. Administrators had to interpret rumors, phone calls from suppliers and a forum thread until the vendor confirmed the flaws and shipped fixes. CISA acknowledged the difficulty directly, noting that updating Citrix NetScaler appliances can be complex and may require downtime.

Why It Matters

For federal civilian agencies, the September 30, 2026 deadline is a hard stop. CISA added both CVEs to the Known Exploited Vulnerabilities catalog on September 27, 2026, and the catalog carries binding remediation timelines for covered agencies. For private sector organizations the pressure is commercial rather than legal, but the risk is the same: an unpatched appliance that is reachable from the internet can hand an intruder a privileged foothold with no credentials and no user interaction.

The numbers explain why this is not a niche concern. Nearly 22,000 NetScaler ADC appliances are visible online according to Shadowserver, and roughly 8,800 of those are in the United States. The affected versions include the builds that many administrators adopted only weeks earlier to fix the August authentication bypass, which means some teams are patching the same appliance for the third time in four months.

Persistence is the other reason this matters. RCE on a NetScaler appliance gives an attacker the ability to disable logging, create rogue virtual servers and install webshells, and from there to move deeper into the network toward Active Directory. Organizations that were exposed need to check for compromise and preserve forensic evidence before updating where possible, as CISA and Citrix have urged.

Next Up

Administrators should inventory NetScaler ADC and NetScaler Gateway deployments, identify those running builds before 14.1-73.37 and 13.1-64.23, and apply the fixed releases, including the FIPS and NDcPP variants. Where patching cannot happen at once, isolating the management interface and limiting internet exposure reduces risk. Teams should also enable Enhanced ISN Generation to mitigate CVE-2026-88778, and use the generic indicators of compromise published through NetScaler Console to hunt for signs of intrusion.

Longer term, the pattern of repeated emergency NetScaler patches since June 2026 is likely to keep repeating until vendors and customers change how these appliances are operated. Expect continued scrutiny from watchTowr, Shadowserver and national cyber agencies. The lesson of the September zero-days is that the first public disclosure is not the start of the incident. For some organizations, it is already the end of a quiet one.

Tagged

Comments (0)

No comments yet. Be the first to share your thoughts.