we_are_coded.by CODE · The world, decoded
БГ
Citrix

Two holes in Citrix NetScaler are already being exploited, and CISA gave three days to patch

Citrix · event date: 28 September 2026Security

On Sunday, 27 September, Cloud Software Group issued a bulletin on eight vulnerabilities in NetScaler ADC and NetScaler Gateway. Two of them, scored 9.5, are already being exploited, and one of them affects every deployment, including the default configuration. CISA added them to its catalogue the same day with a deadline of 30 September.

In short
  • CVE-2026-88771 can let an unauthenticated attacker run commands. There is no precondition: every deployment is vulnerable.
  • CVE-2026-88772 is a memory overflow when DTLS is on, and on a VPN vServer DTLS is on by default.
  • The fixes are 14.1-73.37 and 13.1-64.23, plus the FIPS builds. Citrix updates its own cloud services itself.
Checked on1 October 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

The bulletin came out on a Sunday. That alone is information.

A critical bulletin on a Sunday, and inside it is said outright: exploitation of two of the holes on unmitigated deployments has been observed.

The facts: on 27 September 2026 Cloud Software Group (Citrix) published bulletin CTX697096 on eight vulnerabilities in NetScaler ADC and NetScaler Gateway, CVE-2026-88771 through CVE-2026-88778. The two most serious: CVE-2026-88771, execution of arbitrary commands by an unauthenticated attacker due to improper input validation, affecting all deployments including the default configuration, CVSS v4.0 9.5; CVE-2026-88772, a memory overflow leading to code execution or denial of service when DTLS is enabled (on by default on a VPN vServer), CVSS v4.0 9.5. Citrix writes that exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated deployments have been observed. Fixed versions: 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS and 13.1-37.279 FIPS and NDcPP. Secure Private Access hybrid deployments using NetScaler are also affected. Citrix-managed cloud services are updated by the company. CISA added both vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalogue on 27 September with a deadline of 30 September for federal agencies.

Why it hurts

NetScaler sits on the edge of the network. Employees come in through it from outside. A breach there is not a breach in one server but on the threshold of the whole company.

The first hole has no precondition. You do not need to have switched on a special feature or got a setting wrong. It is in the default configuration. The second needs DTLS, and on the VPN server DTLS runs unless someone has explicitly turned it off.

CISA's deadline for federal agencies is three days. For everyone else the clock is already running.

If you run NetScaler yourself rather than in Citrix's cloud, check the version. Below 14.1-73.37 or below 13.1-64.23, you update, and only then sit down with the indicators of compromise Citrix has published in a separate blog. Read them carefully. If someone is already in, the patch shuts the door behind them but does not put them out.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→Citrix - NetScaler ADC and NetScaler Gateway Security Bulletin CTX697096, 27.09.2026→CISA - Known Exploited Vulnerabilities Catalog, CVE-2026-88771
Original: https://wearecoded.com/en/articles/citrix-netscaler-cve-2026-88771-kev.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news