If you run Citrix NetScaler ADC or NetScaler Gateway, stop scrolling and check your version. On September 27 CISA added two critical zero-days to its Known Exploited Vulnerabilities (KEV) catalog after confirming attackers are exploiting them globally in real-world attacks. Both vulnerabilities — CVE-2026-88771 and CVE-2026-88772 — independently enable unauthenticated remote code execution on the appliance. This is not a drill.
What the vulnerabilities are. Citrix disclosed eight new flaws affecting NetScaler ADC and NetScaler Gateway, tracked as CVE-2026-88771 through CVE-2026-88778. Two of them, CVE-2026-88771 and CVE-2026-88772, were already being used in the wild before Citrix shipped patches — true zero-days. Both carry a CVSS score of 9.5 out of 10.
CVE-2026-88771 is an improper input validation flaw that lets an unauthenticated remote attacker execute arbitrary commands on the appliance. Critically, it affects every NetScaler ADC and Gateway deployment in the affected versions with no additional feature required to be enabled. If the box is reachable, the flaw is reachable.
CVE-2026-88772 is a memory overflow that can result in remote code execution or a denial of service. It specifically affects appliances with DTLS enabled — and DTLS is enabled by default for VPN virtual servers on NetScaler Gateway unless an administrator has explicitly switched it off. Between the two, you have an unauthenticated RCE that works out of the box, and a second one that hits the most common Gateway configuration there is.
Why it matters. NetScaler ADC is the load-balancer and application delivery controller sitting in front of your business apps, and NetScaler Gateway is the remote-access / VPN gateway. These are internet-facing edge devices. Compromise here does not stop at the appliance — it can hand an attacker an entry point into your internal network, the same way prior NetScaler incidents led to lateral movement and data theft. Attackers routinely weaponize gateway and edge flaws within days, and the fact that CISA issued a dedicated alert on a weekend means threat intelligence confirmed active, global exploitation.
Patch now — and patch the right build. Citrix fixed these vulnerabilities in NetScaler ADC and Gateway 14.1-73.37 and later, and in the 13.1-64.23 and later releases, plus the 14.1-FIPS, 13.1-FIPS and 13.1-NDcPP branches. Here is the part people get wrong: if you patched last month for the earlier authentication-bypass flaw CVE-2026-19490 and you are sitting on builds 14.1-73.32 or 13.1-63.21, those builds are still inside the affected range for these new zero-days. Installing those older builds does not close the hole. You need the 14.1-73.37 / 13.1-64.23 (or later) releases.
Hunt for compromise before and after patching. CISA urges you to check for indicators of compromise prior to patching. Citrix has published IOCs available through NetScaler Console and in its security bulletin (CTX697096). If you suspect the appliance was hit, preserve forensic evidence before applying updates — patching can wipe the forensic trail. Forensics-triage requirements under BOD 22-01 apply to exposed federal systems for exactly this reason.
Account for the end-of-life trap. The NetScaler 13.1 branch reached End of Maintenance on September 15, 2026. If you are still on 13.1, treat this as a strong push to move to a supported 14.1 release — an unsupported branch will not reliably get you out of harm’s way in future rounds.
What you should do right now.
1. Identify your exposure. Inventory every NetScaler ADC and Gateway instance and note the exact build. Anything below 14.1-73.37 or 13.1-64.23 is vulnerable.
2. Patch to a fixed build. Upgrade to 14.1-73.37+ or 13.1-64.23+ (or the matching FIPS/NDcPP build). Remember the earlier builds 14.1-73.32 and 13.1-63.21 should not be your final stop — they remain affected.
3. Restrict management and DTLS exposure. Limit management console and IP-access control to trusted IPs, and disable DTLS on VPN virtual servers if you do not actively use it.
4. Check for signs of compromise. Review Citrix’s IOCs in NetScaler Console and CTX697096. If you find anything, assume full compromise and run an incident response — reset credentials, review configs, and check for persistence.
Do not wait on this one. KEV-listed zero-days with confirmed global exploitation are being used right now, and edge gateways are the front door to your network. Every day you hold off patching is a day attackers have the keys.