If your organization runs a customer-managed NetScaler ADC or Gateway, the first question this Monday is whether every active and standby appliance is running a fixed build. Citrix disclosed eight vulnerabilities on September 27, 2026, and says it has observed exploitation of two of them on unmitigated deployments: CVE-2026-88771 and CVE-2026-88772. Both can lead to remote code execution. A successful upgrade closes the reported flaws; it does not establish that an appliance was never compromised. Citrix security bulletin CTX697096

The immediate decision: Inventory every customer-managed instance, check the full running build, plan a supported upgrade, and preserve available evidence if exposure or compromise is possible. Disabling DTLS changes the prerequisite for one of the exploited flaws; it does not fix CVE-2026-88771.

Two Exploited Flaws, Different Preconditions

FlawCitrix’s descriptionDeployment prerequisite
CVE-2026-88771Improper input validation can let an unauthenticated attacker execute arbitrary commands.Every affected NetScaler ADC and Gateway deployment, including default configurations. No additional feature is required.
CVE-2026-88772A memory overflow can cause remote code execution or denial of service.DTLS enabled on an ADC or Gateway. DTLS is enabled by default on VPN virtual servers unless explicitly disabled.

Citrix assigns each a CVSS v4.0 base score of 9.5 and confirms exploitation of both. The bulletin does not provide a complete exploit chain, affected request path, campaign scope, or a reliable public signature for either flaw. Treat those as unknowns rather than filling them in from older NetScaler incidents. Citrix security bulletin

The distinction matters during triage. A Gateway with DTLS explicitly off may not meet the stated prerequisite for CVE-2026-88772, but it still needs the update for CVE-2026-88771. A NetScaler behind an access control is still affected if it runs a vulnerable build; reachability changes who can attempt exploitation, not whether the flaw exists.

Find the Appliances and Check the Build

The affected supported branches and Citrix’s first fixed builds are: Citrix security bulletin

Product branchAffected buildFixed build listed by Citrix
NetScaler ADC and Gateway 14.1Earlier than 14.1-73.3714.1-73.37 or later
NetScaler ADC and Gateway 13.1Earlier than 13.1-64.2313.1-64.23 or later in the 13.1 branch
NetScaler ADC 14.1-FIPSEarlier than 14.1-73.37 FIPS14.1-73.37 FIPS or later
NetScaler ADC 13.1-FIPS and 13.1-NDcPPEarlier than 13.1-37.27913.1-37.279 or later in the respective branch

The bulletin covers customer-managed NetScaler ADC and Gateway instances. Secure Private Access Hybrid deployments that use NetScaler instances also require those instances to be upgraded. Citrix says it is updating Citrix-managed cloud services and Citrix-managed Adaptive Authentication itself. Do not assume a cloud subscription means a separately operated NetScaler appliance has been patched. Citrix security bulletin

The NetScaler owner or managed service provider should reconcile appliance inventory against internet-facing addresses, internal virtual servers, high-availability peers, disaster-recovery systems, and hybrid deployments. Record the running version of each instance, not only an upgrade package or a Console finding. Identify which branch and build each instance actually uses before selecting an update.

To assess the additional DTLS prerequisite for CVE-2026-88772, review the active configuration for VPN virtual servers without an explicit -dtls OFF and for virtual servers of type DTLS. Citrix’s bulletin gives configuration examples. An explicit -dtls OFF means that VPN virtual server does not meet this flaw’s DTLS prerequisite; its absence does not mean DTLS is off. Confirm the live configuration and relevant network path rather than relying on a copied configuration file alone. Citrix configuration guidance

Upgrade Without Missing an Operational Trap

The owner of the appliance should schedule and install a Citrix-supported fixed build as soon as possible. Capture the current configuration and follow the normal backup, high-availability, and rollback procedure for that deployment. Verify that both peers and any recovery instances are upgraded, the running builds meet Citrix’s fixed-version table, and Gateway and application-delivery health checks pass. Those health checks show the service survived the change; the build check shows the reported vulnerabilities were addressed.

There is a specific 13.1 upgrade caveat. Citrix reports that 13.1-64.23 can enter a cyclic reboot for a configuration that has NetScaler variables defined. Citrix says to run show ns variable before upgrading: if it returns a list of configured variables, plan for 13.1-64.24 instead. If it returns no output, Citrix says the deployment is not susceptible to this known issue. The same Citrix post warns that NetScaler Console may temporarily mislabel a system already running 13.1-64.23 as vulnerable; verify the actual running build before escalating a scan result. Citrix operational guidance

Citrix also notes that upgrades can enforce signed SAML assertions where a deployment previously configured samlRejectUnsignedAssertion OFF. Confirm that the identity provider issues signed assertions and test authentication after upgrading. Citrix operational guidance

If an upgrade cannot happen immediately, reduce unnecessary exposure to affected virtual servers where the service design permits it, and coordinate any traffic restrictions with the application and network owners. Disabling DTLS may remove the documented prerequisite for CVE-2026-88772, but may disrupt VPN traffic and leaves CVE-2026-88771 unresolved. Citrix’s prescribed remediation for both exploited flaws is the fixed software. Do not treat MFA, a DTLS change, or a clean IOC scan as a substitute for the update. Citrix security bulletin

Investigate Exposure and Possible Compromise

Patching and incident response are separate workstreams because exploitation predates disclosure. For appliances that were reachable while running affected builds, preserve relevant appliance and externally forwarded logs, configuration snapshots, and upgrade timestamps. Correlate suspicious inbound activity with system and configuration changes, unexpected files, new accounts, and outbound connections. These are investigation leads, not a published signature for the two CVEs. Engage the incident-response team and Citrix Support if evidence suggests compromise; follow established forensic handling before rebuilding or removing artifacts.

Citrix is making generic indicators of compromise available through NetScaler Console. Its September 27 guidance says the feature supports Console service and Console on-premises with Cloud Connect starting at 14.1-73.36, requires the telemetry channel, and appears after Citrix releases the detection logic. Customers without Console can contact Citrix Support for the applicable indicators or help running the scan. Record the logic update date and scan result if the feature is available. Citrix explicitly warns that its indicators do not cover every attacker technique, so a negative result is not proof of a clean appliance. Citrix IOC guidance, NetScaler Console documentation

Citrix recommends forwarding NetScaler logs to an external logging or SIEM platform. If that forwarding was absent, document the visibility gap rather than claiming that no exploitation occurred. If compromise is confirmed, determine the attacker’s access and persistence, contain the appliance with the service owner, and recover from a trusted state. Review secrets and sessions accessible through that specific deployment and rotate or revoke them where the investigation warrants it. Citrix operational guidance

Completion Check for the NetScaler Owner

  1. Every customer-managed ADC and Gateway instance, including peers and recovery systems, has an identified owner, branch, full running build, and exposure record.
  2. Each affected instance runs a Citrix-listed fixed build, with the 13.1 variable check and SAML authentication test handled where applicable.
  3. Gateway, VPN, and application-delivery services pass post-upgrade checks. Temporary access restrictions are documented and reviewed once patching is complete.
  4. The incident-response owner has reviewed available evidence from the vulnerable period. A negative generic IOC scan is recorded as one data point, not a clean bill of health.

The September 27 bulletin fixes six additional NetScaler vulnerabilities alongside the two exploited flaws. Administrators should review the full bulletin for their other feature-specific prerequisites; this article concentrates on the two for which Citrix confirms exploitation. Citrix security bulletin

Sources