On Sunday, 27 September, Cloud Software Group issued a bulletin on eight vulnerabilities in NetScaler ADC and NetScaler Gateway. Two of them, scored 9.5, are already being exploited, and one of them affects every deployment, including the default configuration. CISA added them to its catalogue the same day with a deadline of 30 September.
- CVE-2026-88771 can let an unauthenticated attacker run commands. There is no precondition: every deployment is vulnerable.
- CVE-2026-88772 is a memory overflow when DTLS is on, and on a VPN vServer DTLS is on by default.
- The fixes are 14.1-73.37 and 13.1-64.23, plus the FIPS builds. Citrix updates its own cloud services itself.
The bulletin came out on a Sunday. That alone is information.
A critical bulletin on a Sunday, and inside it is said outright: exploitation of two of the holes on unmitigated deployments has been observed.
Why it hurts
NetScaler sits on the edge of the network. Employees come in through it from outside. A breach there is not a breach in one server but on the threshold of the whole company.
The first hole has no precondition. You do not need to have switched on a special feature or got a setting wrong. It is in the default configuration. The second needs DTLS, and on the VPN server DTLS runs unless someone has explicitly turned it off.
If you run NetScaler yourself rather than in Citrix's cloud, check the version. Below 14.1-73.37 or below 13.1-64.23, you update, and only then sit down with the indicators of compromise Citrix has published in a separate blog. Read them carefully. If someone is already in, the patch shuts the door behind them but does not put them out.