Citrix has patched two critical, actively exploited zero-day vulnerabilities in NetScaler ADC and NetScaler Gateway, the appliances many organizations use to handle VPN access and load balancing at the network edge. Tracked as CVE-2026-88771 and CVE-2026-88772, both carry a CVSS score of 9.5 and let an unauthenticated attacker run code on the appliance. Citrix shipped fixed builds on September 27, 2026, and CISA has ordered US federal agencies to patch by September 30.
What the NetScaler Zero-Day Vulnerabilities Actually Do
CVE-2026-88771 is an improper input validation flaw. Citrix’s own bulletin notes it affects every NetScaler ADC and Gateway deployment, including ones running the default configuration, with no extra feature flag required to be exposed. That is what pushes it from serious to urgent: there is no “if you turned this on” caveat.
CVE-2026-88772 is a memory overflow bug that can lead to remote code execution or denial of service. It needs DTLS enabled to be reachable, but DTLS ships on by default for VPN virtual servers, so in practice most NetScaler Gateway setups used for remote access are exposed too.
CISA’s advisory confirms threat actors are exploiting both flaws globally, not just in a handful of targeted incidents. Shadowserver’s scans put the number of internet-facing NetScaler instances at over 23,000, which gives a sense of how large the exposed surface actually is.
Six More Flaws Patched in the Same Bulletin
Citrix’s security bulletin CTX697096 covers eight CVEs in total. Alongside the two zero-days, it fixes CVE-2026-88773 (HTTP request smuggling, CVSS 9.3), a feature policy bypass, and four separate memory overflow or denial-of-service issues affecting things like Gateway/AAA servers, Oracle load balancing configurations, and TCP sequence number prediction. None of these six are confirmed under active exploitation yet, but they ship in the same update, so there is no reason to patch selectively.
Who Needs to Patch, and How Fast
The fix applies to NetScaler ADC and Gateway 14.1 before build 14.1-73.37, and 13.1 before build 13.1-64.23, including the FIPS and NDcPP variants. Citrix has published patched builds for both branches. If you are still running NetScaler 12.1 or 13.0, those branches are end of life and are not getting a fix, which means the only real option is migrating to a supported version.
One detail worth flagging before anyone rushes to patch: CISA specifically recommends checking for indicators of compromise first. Applying the update can wipe out the forensic evidence needed to tell whether an appliance was already breached, so the guidance is to review logs and run compromise checks before, not after, updating.
For most website and app teams this sits a layer below the CMS or codebase, but it is still worth a look if any client infrastructure, staging environment, or internal admin tool sits behind a NetScaler gateway for remote access. We have covered similar edge-infrastructure exploitation before, including the critical VMware vCenter flaw ransomware gangs were exploiting and the Gitea RCE flaw CISA confirmed was under active attack, and the pattern is consistent: internet-facing management and access appliances are getting scanned and hit within days of a CVE going public.



