CISA Flags Two Actively Exploited Citrix NetScaler Zero Days in Known Exploited Vulnerabilities Catalog
Two critical flaws in Citrix NetScaler ADC and NetScaler Gateway, tracked as CVE-2026-88771 and CVE-2026-88772, have been added to the CISA Known Exploited Vulnerabilities catalog after being exploited as zero-days before any patch existed. Both carry a CVSS score of 9.5. CVE-2026-88771 is an improper input validation issue that can let an unauthenticated remote attacker execute arbitrary commands, and it affects all NetScaler ADC and NetScaler Gateway deployments in their default configuration with no additional features needed. CVE-2026-88772 is a memory buffer overflow, classified as CWE-119, that can lead to remote code execution or a denial-of-service condition, and it affects deployments with DTLS enabled — the default state on VPN vServers. Any organisation running NetScaler ADC or NetScaler Gateway as a remote access or load-balancing gateway should treat itself as in scope until it has confirmed its build level.
Citrix has confirmed the two issues were exploited before fixes were released, but detailed exploitation mechanics have not been published, and our team is not going to reconstruct the request structure from what is available. What is known is the shape of the attack surface. CVE-2026-88771 sits in input handling on a network-reachable interface and results in command execution without authentication, which is the cleanest possible path from internet exposure to appliance control. CVE-2026-88772 is a memory-safety defect reached through the DTLS listener, and a pre-notification circulated to organisations in the Netherlands described one of the flaws as allowing an attacker to inject shellcode directly into memory. The first public signals were informal — on 26 September administrators reported that IT providers and security teams were privately telling them to take NetScaler systems offline, sometimes without explanation — and independent researchers subsequently said they were investigating credible reports of multiple unpatched NetScaler remote code execution flaws being used in the wild, with the vulnerabilities surfacing during forensic investigations. The two zero-days are separate from CVE-2026-19490 and CVE-2026-19489, the NetScaler vulnerabilities disclosed in August.
NetScaler appliances sit at the network edge and terminate VPN and application sessions, so control of one gives an attacker a position in front of internal systems, visibility of session material, and a durable foothold that survives most endpoint-focused detection. The default-configuration reach of CVE-2026-88771 is what makes this set unusual: there is no feature flag or non-standard deployment that narrows the affected population, and the DTLS prerequisite for CVE-2026-88772 is itself a default on VPN vServers. Exploitation is not modelled or predicted here — both CVE-2026-88771 and CVE-2026-88772 were added to the CISA KEV catalog on 27 September 2026, meaning in-the-wild exploitation is confirmed, and CISA has stated it received reports and partner threat intelligence showing threat actors exploiting the vulnerabilities globally. The window between exploitation and disclosure is the core problem for defenders: attacks were already running while administrators were being told to pull systems offline without being told why, so an appliance patched today may already have been touched. For context on the wider NetScaler picture, CVE-2026-19490 from the August round is also KEV-listed, added 9 September 2026, and FIRST EPSS currently puts its probability of exploitation in the next 30 days at 7.0 percent, while CVE-2026-19489 sits at 3.2 percent. CISA has acknowledged that updating these appliances is operationally complex and may require downtime, and the agency set a 30 September 2026 deadline for federal civilian agencies under BOD 22-01.
Attack Surface
Remote Access Service, Infrastructure, Web Application
Tactics
Initial Access, Execution, Impact, Credential Access
Techniques
- T1190 – Exploit Public-Facing Application
- T1059 – Command and Scripting Interpreter
- T1499 – Endpoint Denial of Service
- T1552 – Unsecured Credentials
SuperPRO's Threat Countermeasures Procedures
- Upgrade to a fixed build: NetScaler ADC and NetScaler Gateway 14.1-73.37 or later, 13.1-64.23 or later, NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS or later, and NetScaler ADC 13.1-FIPS / 13.1-NDcPP 13.1.37.279 or later. FCEB agencies are bound by BOD 22-01 to remediate CVE-2026-88771 and CVE-2026-88772 by 30 September 2026.
- Inventory every NetScaler ADC and NetScaler Gateway instance by exact build, including VPX, MPX, SDX and FIPS appliances, since CVE-2026-88771 affects default configurations with no feature toggle required and cannot be scoped out by deployment type.
- Identify VPN vServers with DTLS enabled, which is the default, as these are the deployments exposed to the CWE-119 buffer overflow in CVE-2026-88772, and restrict reachability of the DTLS listener to required client networks where an upgrade cannot be scheduled immediately.
- Run the generic indicators of compromise Citrix has published through NetScaler Console against all managed appliances and record the results before any rebuild, so post-exploitation evidence is not destroyed by the upgrade itself.
- Where compromise is suspected, follow the Citrix response sequence: preserve evidence from the NetScaler VPX instance, isolate the device from the network, revoke credentials and access, then rebuild the appliance on the latest firmware rather than patching in place.
- After recovery, rotate local account passwords and Key Encryption Keys, replace SSL certificates restored from a known-good backup, and review servers and systems reachable from the appliance for signs of onward compromise.
- Alert on unexpected shell or command execution originating from NetScaler management and NSIP processes, on new or modified files under the appliance configuration directories, and on administrative logins from unfamiliar source addresses, forwarding NetScaler logs off-box so tampering by a root-level attacker remains detectable.