Security
Citrix Confirmed Two Exploited NetScaler Zero-Days on Sunday. Admins Had Already Shut the Appliances Down Without Being Told Why
Citrix published bulletin CTX697096 on September 27 covering eight NetScaler flaws, two of them 9.5-rated remote code execution bugs it says are already being exploited. The warning reached administrators two days earlier through suppliers and national CERTs, with no detail attached — and that informal channel is now how edge-appliance disclosure actually works.
MAI
Citrix published security bulletin CTX697096 on Sunday, September 27, covering eight vulnerabilities in NetScaler ADC and NetScaler Gateway. Two of them, CVE-2026-88771 and CVE-2026-88772, both scored 9.5, are already being used in attacks. The company's wording is unambiguous: "Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed."
By the time that sentence appeared, a good number of NetScaler appliances had been switched off for two days by administrators who could not have told you which vulnerability they were hiding from.
What the bulletin covers
| CVE | CVSS | Citrix's description |
|---|---|---|
| CVE-2026-88771 | 9.5 | Remote code execution from improper input validation — exploited |
| CVE-2026-88772 | 9.5 | Memory overflow leading to remote code execution or denial of service — exploited |
| CVE-2026-88773 | 9.3 | HTTP request smuggling |
| CVE-2026-88774 | 7.0 | Policy bypass from improper handling of HTTP URL expressions |
| CVE-2026-88775 | 8.8 | Memory overflow causing unpredictable behaviour or denial of service |
| CVE-2026-88776 | 8.8 | Memory overflow in Oracle load balancing configurations |
| CVE-2026-88777 | 8.8 | Memory overflow with non-HTTP L7 protocol features |
| CVE-2026-88778 | 8.8 | TCP sequence number prediction |
Affected builds are NetScaler ADC and Gateway 14.1 before 14.1-73.37 and 13.1 before 13.1-64.23, with the FIPS variants fixed at their own build levels. The fix is to move to 14.1-73.37 or 13.1-64.23 or later. One item does not close with the update alone: CVE-2026-88778 also requires a TCP configuration change documented by Citrix. An organisation that patches and stops there will still be carrying that one.
CISA published its own alert, "Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway," the same day, and posted a Known Exploited Vulnerabilities catalog addition dated September 27 as well.
The warning arrived before the information did
The sequence here is the part worth sitting with. Over the weekend, private warnings moved through IT suppliers, managed service providers, law enforcement contacts and national cybersecurity agencies. NCSC-NL pre-notified organisations in the Netherlands. watchTowr said publicly on September 26 that it was "rapidly reacting to rumors that multiple unpatched Citrix NetScaler RCE vulnerabilities are circulating in the wild," and judged that "while details are scarce, the information is credible." The flaws had surfaced in forensic investigations. No victim was named, and watchTowr did not say whose investigations they were.
What reached the people who had to make a decision was closer to a rumour with a good pedigree. One administrator described the call to BleepingComputer:
We got a call from our IT supplier's security team, they couldn't give any details but they advised to shut our Netscalers down.
That is a request to take down remote access, load balancing and authentication for an entire organisation — on a Saturday, on the strength of a warning whose substance the caller was not permitted to share. Some did it. Kiteworks customers had been asked to do something comparable the weekend before, for six hours, on the basis of federal threat intelligence.
What defenders should do now
Patch to the fixed builds, and apply the separate TCP configuration change for CVE-2026-88778. Treat an appliance that was running an affected build and reachable from the internet as potentially compromised rather than merely vulnerable: a device that terminates sessions and holds credentials does not become clean when its software is updated. Citrix's own guidance points at preserving evidence — snapshots, logs, core dumps — isolating appliances, resetting credentials and revoking certificates. It also repeats the line it has repeated for years: "The NetScaler Management Services should never be exposed to the public internet."
That last instruction is worth reading carefully, because it is not the mitigation it sounds like. The management plane should never have been public. The service plane — the gateway, the virtual servers, the thing users authenticate against — has to be, or the appliance has no function. Closing the door that was already meant to be shut does not narrow the surface that is actually under attack.
The pattern
This is the second NetScaler emergency in six weeks. Citrix patched CVE-2026-19490, an authentication bypass, on August 19; CISA added it to the KEV catalog on September 9. Anyone who patched in August is not covered here, and the two events are unrelated beyond the product they share.
Edge appliances have become the place where the industry's disclosure process visibly fails. The devices are internet-facing by design, they hold the credentials that make lateral movement cheap, and their vendors are now routinely in the position of confirming exploitation after the fact. The informal network — a call from a supplier, a CERT pre-notification, a research firm publishing a rumour it believes — is filling the gap, and it is doing so by asking organisations to take consequential action without being given a reason. It works, up to a point. It is also not a process anyone designed, and it cannot be audited, prioritised or planned around. The next time a supplier calls on a Saturday, the only input a defender has is how much they trust the caller.
Sources: Citrix security bulletin CTX697096, CISA alert: Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway, CISA Adds Two Known Exploited Vulnerabilities to Catalog, BleepingComputer: Citrix admins warned to shut down NetScalers over 2 exploited zero-days, The Hacker News: Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation