CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV Catalog

CISA Adds Two Citrix NetScaler Vulnerabilities (TL-2026-2711) is a critical-severity software vulnerability scored CVSS 9.5, first published 2026-09-27. It has no confirmed attribution, affects Citrix (Cloud Software Group) NetScaler ADC, references 2 CVEs (CVE-2026-88771, CVE-2026-88772), maps to 16 MITRE ATT&CK techniques (T1046, T1059, T1068), and is covered by 9 detection rules and 14 indicators of compromise.

Key facts for TL-2026-2711

Threat ID
TL-2026-2711
Severity
CRITICAL
CVSS
9.5 (CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H)
Status
ACTIVE
Category
VULNERABILITY
First published
2026-09-27
Last reviewed
2026-09-27
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
government administration, financial services, health, technology, telecoms
Target regions
Global
Detection rules
9
Indicators of compromise
14
Updates
2026-09-27 · revalidated 1× · latest source

Malware and tooling in CISA Adds Two Citrix NetScaler Vulnerabilities

Malware and tooling: NetScaler Console Security Advisory workflow (v14.1-73.36+)

CISA added CVE-2026-88771 (unauthenticated arbitrary command execution via improper input validation) and CVE-2026-88772 (memory-overflow RCE/DoS on DTLS-enabled VPN virtual servers) to its Known Exploited Vulnerabilities catalog on 2026-09-27, both CVSS v4.0 9.5, after Citrix confirmed active exploitation on unmitigated NetScaler ADC and Gateway appliances. This is the third round of emergency NetScaler patches since June 2026, and the fixed builds for August's CVE-2026-19490 remain vulnerable to both new flaws.

How CISA Adds Two Citrix NetScaler Vulnerabilities works

On 2026-09-26, security research firm watchTowr disclosed that it had identified two previously unknown NetScaler ADC and NetScaler Gateway remote-code-execution zero-days during forensic investigations, and several managed-service providers privately advised customers to take NetScaler appliances offline before any public advisory existed. On 2026-09-27, Citrix (Cloud Software Group) confirmed the findings, publishing security bulletin CTX697096 and stating plainly that 'exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed.' CISA added both CVEs to its Known Exploited Vulnerabilities (KEV) catalog the same day and invoked Binding Operational Directive (BOD) 26-04, requiring Federal Civilian Executive Branch agencies to prioritize rapid remediation on publicly exposed assets.

CVE-2026-88771 (CWE-20, Improper Input Validation) is an unauthenticated, network-exploitable flaw (CVSS v4.0 9.5, vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H) that lets a remote, unauthenticated attacker execute arbitrary commands on the appliance. Citrix and multiple outlets emphasize that every NetScaler ADC and NetScaler Gateway deployment is affected, including default configurations with no optional feature enabled -- meaning configuration hardening cannot substitute for patching, and no workaround exists.

CVE-2026-88772 (CWE-119, Improper Restriction of Operations within the Bounds of a Memory Buffer) is a memory-overflow flaw (CVSS v4.0 9.5, vector CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H) reachable only when DTLS is enabled on a virtual server -- a setting on by default for VPN virtual servers on NetScaler Gateway -- and capable of producing remote code execution (described by reporting as able to 'inject shellcode directly into memory') or denial of service.

Both flaws affect NetScaler ADC and NetScaler Gateway builds before 14.1-73.37 and before 13.1-64.23, plus the FIPS/NDcPP variants before 14.1-73.37 FIPS and 13.1.37.279 FIPS/NDcPP. Citrix's CTX697096 bulletin patches six additional, non-exploited CVEs in the same release (CVE-2026-88773 HTTP request smuggling CVSS 9.3, CVE-2026-88774 policy-expression bypass CVSS 7.0, CVE-2026-88775/88776/88777 memory-overflow variants CVSS 8.8 each, and CVE-2026-88778 TCP ISN prediction CVSS 8.8), none of which Citrix has stated are under active exploitation. Notably, the builds that fixed August 2026's CVE-2026-19490 authentication bypass (14.1-73.32 and 13.1-63.21) remain fully vulnerable to both CVE-2026-88771 and CVE-2026-88772, meaning organizations that patched for the prior incident are still exposed.

No file hashes, IP addresses, domains, or other network indicators of compromise for this specific exploitation campaign have been publicly released by Citrix, watchTowr, or any reporting outlet as of this writing; Citrix states only that generic (non-specific) indicator checks are available through the NetScaler Console Security Advisory workflow (available from Console version 14.1-73.36 with Cloud Connect), explicitly cautioning that these checks 'cannot cover every attacker technique and may miss compromises.' No threat actor or campaign has been attributed to the exploitation.

This marks the third wave of actively exploited NetScaler zero-days disclosed in roughly three months: CTX696604 (2026-06-30) fixed six CVEs including CVE-2026-8451, a pre-authentication SAML-IdP memory overread described as 'CitrixBleed-style' because it can leak live session cookies (MITRE ATT&CK T1539, Steal Web Session Cookie), which was exploited within roughly two days of disclosure; CTX696939 (2026-08-19) fixed CVE-2026-19490 (authentication bypass, CVSS v4.0 9.3, letting an unauthenticated attacker circumvent authentication on NetScaler appliances configured as an SSL VPN/ICA Proxy/CVPN/RDP Proxy Gateway or an AAA virtual server) and CVE-2026-19489 (memory overflow, CVSS v4.0 8.8, reachable only when SIP ALG is enabled on a Large Scale NAT group), with CVE-2026-19490 added to the CISA KEV catalog on 2026-09-09; and now CTX697096 (2026-09-27) fixes CVE-2026-88771 and CVE-2026-88772. Citrix NetScaler ADC and Gateway appliances function as internet-facing VPN gateways, ICA proxies, AAA authentication servers, and application delivery controllers across enterprise and government networks, making each disclosure a high-value, broadly exposed target for opportunistic internet-scale exploitation.

Security-vendor technical breakdowns of CTX697096 (strix.ai) specify the exact configuration heuristic for CVE-2026-88772 exposure: any `add vpn vserver` or `add lb vserver` built with the DTLS service type, or a VPN vserver where the `-dtls` parameter is not explicitly set to `OFF`, is vulnerable -- and because DTLS defaults to enabled on VPN vservers, the large majority of Gateway deployments meet this condition with no explicit administrator action. Separately, Citrix's own CTX697096 remediation guidance is explicit that patching alone is insufficient for hosts exploited before the fix shipped: upgrading 'does not remove persistence or other artifacts left by attackers,' and Citrix directs defenders to review authentication and network-activity logs, hunt for unexpected files, processes, and configuration changes, monitor for unauthorized outbound connections, and deploy File Integrity Monitoring. That guidance -- consistent with watchTowr's own framing that exploitation of an internet-facing NetScaler appliance 'can create a strong foothold for lateral movement and credential theft' -- indicates attackers who exploited CVE-2026-88771/CVE-2026-88772 pre-patch are expected to have gone beyond initial command execution to drop tooling on the appliance (T1105, Ingress Tool Transfer) and establish outbound command-and-control channels (T1071, Application Layer Protocol) rather than exploiting and immediately withdrawing.

MITRE ATT&CK techniques used in TL-2026-2711

Discovery

T1046 Network Service Discovery

Execution

T1059 Command and Scripting Interpreter

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Command and Control

T1071 Application Layer Protocol

Persistence

T1078 Valid Accounts

Initial Access

T1133 External Remote Services; T1190 Exploit Public-Facing Application

Lateral Movement

T1210 Exploitation of Remote Services

Stealth

T1211 Exploitation for Stealth

Impact

T1499 Endpoint Denial of Service; T1499.004 Endpoint Denial of Service: Application or System Exploitation

Credential Access

T1539 Steal Web Session Cookie; T1552 Unsecured Credentials

Resource Development

T1588.005 Exploits

Reconnaissance

T1595.002 Active Scanning: Vulnerability Scanning

Defense Evasion

T1620 Reflective Code Loading

Affected products and versions in CISA Adds Two Citrix NetScaler Vulnerabilities

  • Citrix (Cloud Software Group) — NetScaler ADC
    Vulnerable versions: 14.1 before 14.1-73.37; 13.1 before 13.1-64.23; 14.1 FIPS before 14.1-73.37 FIPS; 13.1 FIPS and NDcPP before 13.1.37.279
    Fixed in: 14.1-73.37; 13.1-64.23; 14.1-73.37 FIPS; 13.1.37.279 FIPS and NDcPP
  • Citrix (Cloud Software Group) — NetScaler Gateway
    Vulnerable versions: 14.1 before 14.1-73.37; 13.1 before 13.1-64.23
    Fixed in: 14.1-73.37; 13.1-64.23

Remediation for CISA Adds Two Citrix NetScaler Vulnerabilities

Patches

  • NetScaler ADC 14.1-73.37 or later
  • NetScaler ADC 13.1-64.23 or later
  • NetScaler Gateway 14.1-73.37 or later
  • NetScaler Gateway 13.1-64.23 or later
  • NetScaler ADC/Gateway 14.1-73.37 FIPS or later
  • NetScaler ADC 13.1.37.279 FIPS and NDcPP or later

Immediate actions

  • Upgrade all NetScaler ADC and NetScaler Gateway appliances to 14.1-73.37 or later, or 13.1-64.23 or later (FIPS/NDcPP builds: 14.1-73.37 FIPS or 13.1.37.279 FIPS and NDcPP), regardless of current build -- including instances already patched for August 2026's CVE-2026-19490, since builds 14.1-73.32 and 13.1-63.21 remain vulnerable to CVE-2026-88771 and CVE-2026-88772
  • Treat every internet-facing NetScaler ADC/Gateway appliance as potentially compromised pending forensic verification, since watchTowr identified these flaws during forensic investigation of real-world exploitation rather than as theoretical research
  • Run Citrix's NetScaler Console Security Advisory workflow (Console v14.1-73.36 or later with Cloud Connect) for generic indicator-of-compromise checks, while recognizing Citrix's own caveat that these checks cannot cover every attacker technique
  • Where immediate patching is not possible, disable DTLS on VPN virtual servers as an interim compensating control for CVE-2026-88772 (note: DTLS is enabled by default on VPN virtual servers)

Workarounds

  • Disable DTLS on VPN virtual servers to mitigate CVE-2026-88772 pending patch deployment
  • No workaround exists for CVE-2026-88771: it affects every default configuration with no optional feature to disable, so patching is the only effective mitigation

Longer-term hardening

  • Adopt continuous, rapid version tracking for NetScaler ADC/Gateway given the demonstrated pattern of actively exploited zero-days in this product line in June/July, August, and September 2026
  • Forward NetScaler logs and NetScaler Console telemetry to an external SIEM to support forensic detection independent of the appliance's own security state
  • Segment NetScaler Gateway/AAA/VPN management and administration interfaces away from unrestricted internet exposure where operationally feasible
  • Establish an emergency-patch SLA for internet-facing edge and VPN appliances given the sub-monthly cadence of exploited NetScaler CVE disclosures observed in 2026

CVEs associated with CISA Adds Two Citrix NetScaler Vulnerabilities

CVE-2026-88771, CVE-2026-88772

Weaknesses (CWE) in CISA Adds Two Citrix NetScaler Vulnerabilities

CWE-20, CWE-119

Timeline of CISA Adds Two Citrix NetScaler Vulnerabilities

  • Citrix publishes CTX696604, fixing six NetScaler ADC/Gateway CVEs including CVE-2026-8451, a pre-authentication SAML-IdP memory overread described as 'CitrixBleed-style' for its ability to leak live session cookies; it is exploited in the wild within roughly two days of disclosure.
  • Citrix publishes CTX696939, fixing CVE-2026-19490 (authentication bypass, CVSS v4.0 9.3) and CVE-2026-19489 (memory overflow, CVSS v4.0 8.8) in NetScaler ADC and Gateway, patched in builds 14.1-73.32 and 13.1-63.21.
  • CISA adds CVE-2026-19490 to the Known Exploited Vulnerabilities catalog based on evidence of active exploitation.
  • NetScaler 13.1 reaches Citrix's End of Maintenance date; Citrix nonetheless ships an emergency 13.1-64.23 security build twelve days later to remediate the two actively exploited zero-days.
  • National CERTs and law enforcement begin privately notifying select organizations about unpatched NetScaler RCE flaws ahead of public disclosure.
  • Dutch NCSC-NL issues pre-notification to Netherlands organizations after receiving information from a European partner CERT.
  • Security research firm watchTowr discloses that it identified two previously unknown NetScaler ADC/Gateway RCE zero-days during forensic investigations; some managed-service providers privately advise customers to take NetScaler appliances offline ahead of any public advisory.
  • Canadian Centre for Cyber Security issues advisory AL26-024, warning that exploitation of CVE-2026-88771 and CVE-2026-88772 has been observed across multiple Citrix customer environments worldwide.
  • Citrix submits incident notifications under the EU Cyber Resilience Act's disclosure requirements after discovering CVE-2026-88771 and CVE-2026-88772 were exploited as zero-days during customer incident investigations.
  • Citrix confirms Secure Private Access Hybrid deployments that rely on on-premises/Hybrid NetScaler instances are also affected and must be patched; Citrix-managed cloud and Adaptive Auth configurations are excluded.
  • CISA adds CVE-2026-88771 and CVE-2026-88772 to the Known Exploited Vulnerabilities catalog, invoking Binding Operational Directive 26-04 for Federal Civilian Executive Branch remediation.
  • Citrix (Cloud Software Group) publishes security bulletin CTX697096, confirming active exploitation of CVE-2026-88771 and CVE-2026-88772 and releasing fixed builds 14.1-73.37 and 13.1-64.23; the bulletin notes the prior CVE-2026-19490 patch builds (14.1-73.32, 13.1-63.21) remain vulnerable to both new flaws.

Update history for TL-2026-2711

Sources cited for CISA Adds Two Citrix NetScaler Vulnerabilities

More in vulnerability

Detection coverage for TL-2026-2711

As of 2026-09-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2711 across Splunk SPL, Microsoft KQL and Sigma, covering 14 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats