Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)
Citrix Patches Two Actively Exploited NetScaler Zero-Days (TL-2026-2703) is a critical-severity software vulnerability scored CVSS 9.5, first published 2026-09-27. It has no confirmed attribution, affects Citrix NetScaler ADC, references 8 CVEs (CVE-2026-88771, CVE-2026-88772, CVE-2026-88773), maps to 28 MITRE ATT&CK techniques (T1003, T1033, T1037.004), and is covered by 9 detection rules and 33 indicators of compromise.
Key facts for TL-2026-2703
- Threat ID
- TL-2026-2703
- Severity
- CRITICAL
- CVSS
- 9.5
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-09-27
- Last reviewed
- 2026-09-27
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 33
- Updates
- 2026-09-27 · 4 updates · revalidated 4× · latest source
Citrix has released fixes (security bulletin CTX697096, 2026-09-27) for the two NetScaler ADC and NetScaler Gateway zero-days exploited in the wild: CVE-2026-88771, an unauthenticated remote code execution flaw caused by improper input validation that affects default configurations (CVSS 4.0 9.5), and CVE-2026-88772, a memory overflow leading to remote code execution or denial of service when DTLS is enabled, as it is by default on VPN virtual servers (CVSS 4.0 9.5). The same bulletin fixes six further flaws, CVE-2026-88773 through CVE-2026-88778. The zero-days first surfaced through a leaked NCSC-NL pre-notification before any vendor advisory; administrators should upgrade to 14.1-73.37 or 13.1-64.23 immediately and hunt for prior compromise, since exploitation predates the patch.
How Citrix Patches Two Actively Exploited NetScaler Zero-Days works
Update (2026-09-27): Citrix published security bulletin CTX697096 with fixes for the two exploited zero-days, now tracked as CVE-2026-88771 (unauthenticated remote code execution through improper input validation, CWE-20, CVSS 4.0 9.5, all deployments in default configuration) and CVE-2026-88772 (memory overflow leading to remote code execution or denial of service, CWE-119, CVSS 4.0 9.5, when DTLS is enabled, which is the default on VPN virtual servers). Citrix marks both as exploited in the wild. The bulletin also fixes CVE-2026-88773 (HTTP request smuggling, CVSS 9.3), CVE-2026-88774 (policy bypass through HTTP URL expressions, CVSS 7.0), CVE-2026-88775, CVE-2026-88776 and CVE-2026-88777 (memory overflows causing denial of service in Gateway/AAA, Oracle load-balancing and non-HTTP layer-7 configurations, CVSS 8.8 each) and CVE-2026-88778 (TCP initial sequence number prediction, CVSS 8.8). Fixed builds are NetScaler ADC and Gateway 14.1-73.37 and 13.1-64.23, NetScaler ADC 14.1-73.37 FIPS, and NetScaler ADC 13.1-37.279 FIPS/NDcPP. The original reporting below describes the pre-patch disclosure.
On 2026-09-25, a post to Reddit's r/Citrix community surfaced the contents of a pre-notification reportedly issued by the Dutch National Cyber Security Centre (NCSC-NL) to its partners under Traffic Light Protocol AMBER+STRICT restrictions, describing two unpatched, unauthenticated remote-code-execution vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway. Public reporting indicates NCSC-NL itself received the underlying intelligence from a European partner CERT before issuing its own pre-notification -- one link in a cross-border information-sharing chain that predates any Citrix confirmation. According to the leaked notification, Citrix itself discovered the flaws while conducting incident-response investigations inside customer environments, and exploitation had already been identified at multiple Citrix customers worldwide before any patch existed. On 2026-09-26, security firm watchTowr and independent researcher Kevin Beaumont independently corroborated that the in-the-wild exploitation was credible, with watchTowr stating plainly: "Two vulnerabilities - both RCE. Unpatched, 0days. Exploited in-the-wild - discovered during forensics." Kevin Beaumont added: "The Netscaler zero day thing is real, being used in active attacks. No patch yet, if sensitive to Netscaler vulns switch it off." watchTowr and multiple outlets explicitly distinguish this pair from the previously disclosed and already-patched CVE-2026-19490 and CVE-2026-19489, cautioning against conflating them.
Of the technical mechanics, only one detail has been confirmed through the NCSC-NL notification: one of the two flaws allows an unauthenticated attacker with external HTTPS reachability to "place shellcode directly into memory" on the appliance -- a technique that bypasses file-based antivirus and most endpoint detection because no malicious file ever touches disk. Technical detail on the second flaw remains undisclosed. As of 2026-09-27, Citrix has not published a formal security advisory, has not assigned CVE identifiers, has not disclosed affected build ranges, and has not released indicators of compromise -- a gap that multiple outlets (Tenable, Cyber Kendra, shattered.io, CyberSecurityNews) explicitly flag as leaving defenders to act on largely unverified secondary reporting; CyberSecurityNews notes vulnerability scanners cannot even flag exposed appliances without a published build range. Some administrators report inconsistent notification: several told reporters they received no NCSC-NL alert or Citrix communication directly, despite the public reporting. Critically, NCSC-NL's original warning states that because the flaws were exploited before any patch existed, simply shutting down or eventually patching an appliance will not remove an attacker who is already inside it -- prior NetScaler compromises in this same product line have involved intruders maintaining access post-patch via backdoors, so incident responders should assume compromise and hunt for persistence rather than treating a future patch as remediation on its own.
This is the latest in a recurring pattern of pre-authentication memory-safety weaknesses in NetScaler's edge-facing code paths, a lineage that traces back to the original CitrixBleed (CVE-2023-4966, 2023), a pre-auth memory-overread flaw that enabled session-token theft and was widely exploited before its own patch existed, and includes CVE-2025-6543, a NetScaler zero-day exploited against Dutch critical infrastructure -- a fact that helps explain NCSC-NL's central, recurring role in NetScaler zero-day response. Citrix patched CVE-2026-3055 ("CitrixBleed 3"), a SAML IdP memory-overread flaw enabling unauthenticated extraction of session data and credentials from process memory (repeated crafted requests can return different memory segments over time, enabling session hijacking and lateral movement), on 2026-03-23, after which CISA added it to the Known Exploited Vulnerabilities catalog within a week. Citrix patched a second pre-auth memory-overread flaw, CVE-2026-8451, on 2026-06-30, in the same disclosure batch as CVE-2026-8452, which watchTowr's own research notes was initially classified only as a denial-of-service issue before later analysis showed it was in fact a root-level pre-auth RCE -- underscoring how this vendor's own initial severity triage in this product line has previously understated real-world impact. Most recently, Citrix patched CVE-2026-19490 -- an authentication bypass via an alternate path or channel affecting AAA virtual servers handling SSL VPN, ICA Proxy, CVPN, and RDP Proxy functions -- on 2026-08-19; Singapore's Cyber Security Agency observed exploitation attempts against it by 2026-09-07, and CISA added it to the KEV catalog on 2026-09-09 with a federal remediation deadline of 2026-09-12. NetScaler 13.1 separately reached End of Maintenance on 2026-09-15, days before this newest pair of zero-days surfaced, complicating remediation options for organizations still running that branch.
Pending a Citrix advisory, published guidance is a mix of defensive best practice and community-sourced compensating controls rather than vendor-issued fix instructions: take internet-exposed NetScaler ADC/Gateway instances offline or restrict access to trusted networks, never expose the NetScaler Management Service to the public internet, verify the current build via the `show ns version` command so remediation can be triaged the moment Citrix publishes affected ranges, and -- absent any published IOCs -- monitor appliances for behavioral indicators of compromise: unexplained log gaps, unfamiliar or unexpected administrative sessions, unusual outbound connections from the appliance, and anomalous activity in crash-dump folders. Per Citrix's standing guidance for suspected NetScaler compromise, responders should also preserve VPX snapshots, remote syslog, tech-support bundles, and core dumps, isolate any suspect appliance, and reset service-account credentials and revoke/reissue certificates and private keys if compromise is suspected. Citrix and watchTowr indicate formal communications, CVE assignment, and patches are expected early in the week of 2026-09-28.
MITRE ATT&CK techniques used in TL-2026-2703
Credential Access
T1003 OS Credential Dumping; T1539 Steal Web Session Cookie; T1552.004 Unsecured Credentials: Private Keys; T1557 Adversary-in-the-Middle; T1558 Steal or Forge Kerberos Tickets
Discovery
T1033 System Owner/User Discovery
Persistence
T1037.004 Boot or Logon Initialization Scripts: RC Scripts; T1053.003 Scheduled Task/Job: Cron; T1078 Valid Accounts; T1136 Create Account; T1505.003 Web Shell
Privilege Escalation
T1055 Process Injection; T1068 Exploitation for Privilege Escalation
Defense Evasion
T1055 Process Injection; T1620 Reflective Code Loading
Execution
T1059.004 Command and Scripting Interpreter; T1059.006 Command and Scripting Interpreter: Python
Command and Control
T1071 Application Layer Protocol; T1071.001 Application Layer Protocol: Web Protocols; T1105 Ingress Tool Transfer
Initial Access
T1133 External Remote Services; T1190 Exploit Public-Facing Application
Lateral Movement
T1210 Exploitation of Remote Services; T1550.001 Use Alternate Authentication Material: Application Access Token
Impact
T1499.004 Endpoint Denial of Service: Application or System Exploitation
Resource Development
T1583.004 Acquire Infrastructure; T1588.005 Exploits; T1588.006 Obtain Capabilities: Vulnerabilities
Reconnaissance
Affected products and versions in Citrix Patches Two Actively Exploited NetScaler Zero-Days
- Citrix — NetScaler ADC
Vulnerable versions: 14.1 before 14.1-73.37; 13.1 before 13.1-64.23; 14.1-FIPS before 14.1-73.37 FIPS; 13.1-FIPS and 13.1-NDcPP before 13.1-37.279
Fixed in: 14.1-73.37; 13.1-64.23; 14.1-73.37 FIPS; 13.1-37.279 FIPS/NDcPP - Citrix — NetScaler Gateway
Vulnerable versions: 14.1 before 14.1-73.37; 13.1 before 13.1-64.23
Fixed in: 14.1-73.37; 13.1-64.23
Remediation for Citrix Patches Two Actively Exploited NetScaler Zero-Days
Patches
- NetScaler ADC and NetScaler Gateway 14.1-73.37 and later
- NetScaler ADC and NetScaler Gateway 13.1-64.23 and later
- NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later
- NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later
Immediate actions
- Upgrade NetScaler ADC and NetScaler Gateway to 14.1-73.37 or 13.1-64.23 (FIPS: 14.1-73.37 FIPS; FIPS/NDcPP: 13.1-37.279) on every instance
- Until every instance is upgraded, keep internet-exposed appliances offline or restricted to trusted management networks
- Never expose the NetScaler Management Service (NSIP/SNIP) directly to the public internet
- Hunt for compromise before and after patching: exploitation predates the fix, so an attacker already inside an appliance survives the upgrade unless actively found and evicted (NCSC-NL)
- Look for behavioral indicators: unexplained log gaps, unexpected administrative sessions, unusual outbound connections from the appliance, and anomalous entries in crash-dump folders
- Preserve forensic evidence (VPX snapshots, remote syslog, tech-support bundles and core dumps) before remediating
- If compromise is suspected, isolate the appliance, reset all local and service-account credentials, and revoke and reissue certificates and private keys
Workarounds
- For CVE-2026-88778, apply the enhanced TCP initial sequence number (ISN) generation configuration described in NetScaler documentation
- Restrict NetScaler ADC and Gateway access to trusted IP ranges until the upgrade is complete
Longer-term hardening
- Subscribe to Citrix security bulletins and patch NetScaler within days of release; this product line has a recurring pattern of exploited pre-auth memory-safety flaws, from CitrixBleed (CVE-2023-4966) through CVE-2025-6543, CVE-2026-3055, CVE-2026-8451/8452, CVE-2026-19490 and now CVE-2026-88771/88772
- Maintain a current inventory of all NetScaler ADC and Gateway instances, builds and internet exposure so advisories can be triaged in minutes
- Add behavioral and EDR-style monitoring on NetScaler appliances rather than relying only on signature-based detection
- Keep a standing NetScaler compromise-hunting playbook (web-shell sweep, admin-account audit, outbound-connection baseline) for every zero-day disclosure in this product line
CVEs associated with Citrix Patches Two Actively Exploited NetScaler Zero-Days
CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, CVE-2026-88778
Weaknesses (CWE) in Citrix Patches Two Actively Exploited NetScaler Zero-Days
CWE-20, CWE-119, CWE-444, CWE-16, CWE-342, CWE-787, CWE-179, CWE-330
Timeline of Citrix Patches Two Actively Exploited NetScaler Zero-Days
Showing the 20 most recent tracked events.
- Citrix patches CVE-2026-8451, a second pre-auth NetScaler memory-overread flaw, in the same disclosure batch as CVE-2026-8452 -- a flaw watchTowr's research later showed was initially under-classified as denial-of-service before being confirmed as a root-level pre-auth RCE.
- Citrix patches CVE-2026-19490, an authentication bypass via an alternate path or channel affecting NetScaler ADC/Gateway AAA virtual servers (SSL VPN, ICA Proxy, CVPN, RDP Proxy).
- CISA adds precursor flaw CVE-2026-8452 to its Known Exploited Vulnerabilities catalog after observing attackers drop web shells (x.php, z.php) and run discovery commands (id, echo) on compromised NetScaler appliances; telemetry shows 36 exploitation attempts from 12 unique attacker IPs across 10 countries. Federal remediation deadline: 2026-08-29.
- Singapore's Cyber Security Agency observes exploitation attempts against CVE-2026-19490.
- CISA adds CVE-2026-19490 to the Known Exploited Vulnerabilities catalog with a 2026-09-12 federal remediation deadline.
- CVE-2026-88772 is reserved in the CVE numbering system weeks ahead of public disclosure of active exploitation.
- NetScaler 13.1 reaches End of Maintenance, days before a new pair of unrelated zero-days surfaces, complicating remediation for organizations still on that branch.
- A Reddit r/Citrix post surfaces the contents of a Dutch NCSC-NL pre-notification (TLP:AMBER+STRICT), reportedly built on intelligence NCSC-NL received from a European partner CERT, describing two new, unpatched NetScaler ADC/Gateway RCE zero-days that Citrix discovered during incident-response work and that were already being exploited at multiple customers worldwide.
- watchTowr and independent researcher Kevin Beaumont publicly confirm the in-the-wild exploitation is credible and explicitly distinguish the two new zero-days from CVE-2026-19490/CVE-2026-19489; Citrix has not yet issued an advisory.
- The Canadian Centre for Cyber Security issues Alert AL26-024, warning Canadian IT professionals of active exploitation of CVE-2026-88771/88772 and urging forensic evidence preservation and credential/session reset readiness before patching.
- CISA publishes an alert amplifying Citrix's disclosure, confirming partner threat intelligence of active, global exploitation of CVE-2026-88771/88772.
- CISA adds CVE-2026-88771 and CVE-2026-88772 to the Known Exploited Vulnerabilities Catalog based on confirmed active exploitation, resolving the existing record's 'kev_pending' status.
- Citrix credits Michael Tucker, Chew Keong Tan, and Alex Bernier of the JPMorgan Chase XOR Team, and independent researcher Maxim Suhanov, for vulnerability research contributing to bulletin CTX697096.
- CVE-2026-88771 and CVE-2026-88772 remain absent from the CISA Known Exploited Vulnerabilities catalog at time of the CTX697096 bulletin, since in-the-wild exploitation began before a CVE could be assigned.
- Independent technical analysis synthesizing the watchTowr disclosure identifies the exploited component as the nsppe packet-processing daemon, describes a heap buffer overflow in malformed pipelined HTTP request handling, and details a three-stage post-exploitation playbook: in-memory backdoor injection, AAA daemon credential harvesting, and VPN session-token theft.
- Citrix ships fixed builds NetScaler ADC/Gateway 14.1-73.37 and 13.1-64.23, plus FIPS/NDcPP equivalents 14.1-73.37 FIPS and 13.1-37.279, closing all eight CVEs; the bulletin provides no workaround and no IOCs for either exploited zero-day.
- Cloud Software Group / Citrix publishes security bulletin CTX697096, formally disclosing eight NetScaler ADC/Gateway CVEs (CVE-2026-88771 through CVE-2026-88778) and confirming in-the-wild exploitation of CVE-2026-88771 (CVSS 9.5, improper input validation) and CVE-2026-88772 (CVSS 9.5, memory overflow).
- Coverage by BleepingComputer, The Hacker News, Tenable, and others confirms no CVE, affected-build list, patch, or indicators of compromise have been published; Citrix urges admins to take internet-exposed NetScalers offline or restrict access, while outlets circulate community-sourced behavioral monitoring guidance (log gaps, unfamiliar admin sessions, anomalous outbound connections) in lieu of vendor IOCs.
- Citrix and watchTowr indicate formal advisory publication, CVE assignment, and patches are expected "early next week" -- i.e., beginning this date.
- CISA's KEV Catalog entries for CVE-2026-88771 and CVE-2026-88772 set a Binding Operational Directive 26-04 remediation due date for U.S. federal civilian agencies.
Update history for TL-2026-2703
- 2026-09-27 — Citrix NetScaler ADC/Gateway Zero-Days (CVE-2026-88771, CVE-2026-88772) Actively Exploited, Added to CISA KEV: What changed CVE-2026-88771 and CVE-2026-88772 moved from 'KEV pending' to formally added to the CISA Known Exploited Vulnerabilities Catalog, with a BOD 26-04 federal remediation deadline of 2026-09-30; CISA and the Canadian Centre for Cyb
- 2026-09-27 — Citrix Confirms Two NetScaler Zero-Day Flaws (CVE-2026-88771, CVE-2026-88772) Exploited in Attacks: What changed No field escalations — severity (CRITICAL), exploitability (ACTIVE), status (ACTIVE) and CVSS score (9.5) already matched the existing record. New indicators (4) Added named vulnerability-research credits (JPMorgan Chase XOR Te
- 2026-09-27 — Citrix Confirms NetScaler 0-Day: CVE-2026-88771 and CVE-2026-88772 Under Active Exploitation: What changed Core fields unchanged (severity CRITICAL, exploitability ACTIVE, status ACTIVE, CVSS 9.5, attribution_confidence LOW). The newer report supplies a formal CVSS v4.0 vector string for CVE-2026-88771 not present in the existing re
- 2026-09-27 — Citrix NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778 (CTX697096): What changed The vendor-confirmation gap this threat was published on is now closed: Citrix's CTX697096 bulletin assigns CVE-2026-88771 and CVE-2026-88772 (CVSS 9.5 each) to the two previously unnumbered zero-days, discloses six additional
Sources cited for Citrix Patches Two Actively Exploited NetScaler Zero-Days
- Citrix admins warned to shut down NetScalers over 2 exploited zero-days
- Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
- Citrix NetScaler Zero-Day RCE vulnerabilities: FAQ
- Citrix NetScaler 0-Day RCE Vulnerabilities Actively Exploited in Attacks
- Citrix NetScaler 2 Zero-Days: No CVE Yet
- Unpatched NetScaler Zero-Days Exploited, watchTowr Says
- CISA Known Exploited Vulnerabilities Catalog: CVE-2026-19490
- Citrix Security Bulletin CTX696939 (NetScaler ADC/Gateway Authentication Bypass, CVE-2026-19490)
- CVE-2026-3055: Citrix NetScaler Memory Overread ("CitrixBleed 3")
- CVE-2026-3055 Threatens Citrix NetScaler SAML IDP
More in vulnerability
- CVE-2019-18935 Telerik UI Deserialization Exploited to Deploy Web Shells and a WordPress Scanner on IIS Servers
- Comment2Shell: Unauthenticated Stored XSS-to-RCE Chain in WordPress wpautop() (CVE-2026-93485)
- CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV Catalog
- SalesBleed: Indirect Prompt Injection Enables Zero-Click CRM Data Exfiltration in Salesforce Agentforce
- Cloudflare Containers Cross-Tenant Data Exposure via Unzeroed Reused Storage Blocks (skip_block_zeroing)
Detection coverage for TL-2026-2703
As of 2026-09-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2703 across Splunk SPL, Microsoft KQL and Sigma, covering 33 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.