ConicPlex

Start Your Project

A rack-mounted network gateway appliance in a blue-lit data center, with a physical access badge resting on top, representing the Citrix NetScaler ADC and Gateway zero-day vulnerabilities

On this Page

Citrix Patches Two Critical Zero-Day Flaws in NetScaler ADC and Gateway (CVE-2026-88771, CVE-2026-88772)

Citrix patched two actively exploited NetScaler ADC and Gateway zero-days – CVE-2026-88771 and CVE-2026-88772. CISA set a September 30 patch deadline for federal agencies.

Sameer Malek

September 29, 2026

Citrix has patched two critical, actively exploited zero-day vulnerabilities in NetScaler ADC and NetScaler Gateway, the appliances many organizations use to handle VPN access and load balancing at the network edge. Tracked as CVE-2026-88771 and CVE-2026-88772, both carry a CVSS score of 9.5 and let an unauthenticated attacker run code on the appliance. Citrix shipped fixed builds on September 27, 2026, and CISA has ordered US federal agencies to patch by September 30.

What the NetScaler Zero-Day Vulnerabilities Actually Do

CVE-2026-88771 is an improper input validation flaw. Citrix’s own bulletin notes it affects every NetScaler ADC and Gateway deployment, including ones running the default configuration, with no extra feature flag required to be exposed. That is what pushes it from serious to urgent: there is no “if you turned this on” caveat.

CVE-2026-88772 is a memory overflow bug that can lead to remote code execution or denial of service. It needs DTLS enabled to be reachable, but DTLS ships on by default for VPN virtual servers, so in practice most NetScaler Gateway setups used for remote access are exposed too.

CISA’s advisory confirms threat actors are exploiting both flaws globally, not just in a handful of targeted incidents. Shadowserver’s scans put the number of internet-facing NetScaler instances at over 23,000, which gives a sense of how large the exposed surface actually is.

Six More Flaws Patched in the Same Bulletin

Citrix’s security bulletin CTX697096 covers eight CVEs in total. Alongside the two zero-days, it fixes CVE-2026-88773 (HTTP request smuggling, CVSS 9.3), a feature policy bypass, and four separate memory overflow or denial-of-service issues affecting things like Gateway/AAA servers, Oracle load balancing configurations, and TCP sequence number prediction. None of these six are confirmed under active exploitation yet, but they ship in the same update, so there is no reason to patch selectively.

Who Needs to Patch, and How Fast

The fix applies to NetScaler ADC and Gateway 14.1 before build 14.1-73.37, and 13.1 before build 13.1-64.23, including the FIPS and NDcPP variants. Citrix has published patched builds for both branches. If you are still running NetScaler 12.1 or 13.0, those branches are end of life and are not getting a fix, which means the only real option is migrating to a supported version.

One detail worth flagging before anyone rushes to patch: CISA specifically recommends checking for indicators of compromise first. Applying the update can wipe out the forensic evidence needed to tell whether an appliance was already breached, so the guidance is to review logs and run compromise checks before, not after, updating.

For most website and app teams this sits a layer below the CMS or codebase, but it is still worth a look if any client infrastructure, staging environment, or internal admin tool sits behind a NetScaler gateway for remote access. We have covered similar edge-infrastructure exploitation before, including the critical VMware vCenter flaw ransomware gangs were exploiting and the Gitea RCE flaw CISA confirmed was under active attack, and the pattern is consistent: internet-facing management and access appliances are getting scanned and hit within days of a CVE going public.

Sources

Sameer Malek is a Senior Full Stack Developer at ConicPlex, working across the stack on projects that don’t fit neatly into one platform or framework. He’s often the person weighing a genuine platform or architecture decision rather than defending one side of it, since his work regularly crosses between WordPress, custom builds, and everything in between. He writes here about the comparisons and tradeoffs that come up when there’s more than one reasonable way to build something.

Leave a Reply

Your email address will not be published. Required fields are marked *

Keep reading

Software

A developer desk at night with a monitor glowing WordPress blue, a corkboard map with red location pins in the background, illustrating a WordPress provider directory build.

Store Locator Plugin or Custom Provider Directory: What a Multi-Provider WordPress Site Actually Needs

A WordPress store locator plugin works fine when you’re mapping a fixed set of your own addresses. It starts breaking…

Aftab Memon

September 29, 2026

Software

A small retail shop counter at closing time with a card payment terminal, receipt printer, stacked paper sales reports, and a laptop showing an abstract dashboard while a shopkeeper sorts receipts by hand

When Tool Sprawl Costs More Than Building a Custom Merchant Dashboard

When separate payment, POS, and billing tools start costing more in reconciliation time than a custom dashboard would cost to…

Sameer Malek

September 28, 2026

News & Updates

A laptop on a desk showing an abstract blue, red, yellow, and green light swirl representing a slow-moving Google search ranking update, with an hourglass beside it symbolizing the long rollout

Google’s September 2026 Spam Update Could Take Two Weeks, Its Longest Rollout Yet

Google’s September 2026 spam update began September 24 and could take up to two weeks to complete, making it the…

Sameer Malek

September 28, 2026

WhatsApp
Husen Memon
Husen Memon
Typically replies instant