{"id":281,"date":"2026-09-30T01:31:18","date_gmt":"2026-09-30T01:31:18","guid":{"rendered":"https:\/\/managedt.com\/blog\/citrix-netscaler-rce-zero-days-patches\/"},"modified":"2026-09-30T13:44:07","modified_gmt":"2026-09-30T13:44:07","slug":"citrix-netscaler-rce-zero-days-patches","status":"publish","type":"post","link":"https:\/\/managedt.com\/blog\/citrix-netscaler-rce-zero-days-patches\/","title":{"rendered":"Citrix confirms two NetScaler RCE zero-days, patches released"},"content":{"rendered":"<p>Citrix has confirmed that two critical remote code execution vulnerabilities in NetScaler are being exploited in the wild and has released patches covering them. Both flaws carry a severity score of 9.5, affect customer-managed NetScaler ADC and NetScaler Gateway appliances, and can be triggered without authentication, putting Internet-facing edge devices at immediate risk.<\/p>\n<h2>What Citrix disclosed<\/h2>\n<p>The two vulnerabilities are tracked as CVE-2026-88771 and CVE-2026-88772. Citrix&#8217;s security bulletin CTX697096 confirms both are zero-days that have been used against unmitigated deployments.<\/p>\n<p>CVE-2026-88771 is an improper input validation flaw that allows an unauthenticated attacker to execute arbitrary commands on the appliance. Citrix says it affects all NetScaler ADC and NetScaler Gateway deployments, including those using the default configuration, and does not require any additional feature to be enabled.<\/p>\n<p>CVE-2026-88772 is a memory overflow vulnerability that can lead to remote code execution or a denial-of-service condition. It can be exploited when DTLS is enabled on a NetScaler ADC or NetScaler Gateway. DTLS is enabled by default on VPN virtual servers, which broadens the exposed footprint for many deployments.<\/p>\n<p>The bulletin also fixes six other NetScaler vulnerabilities, for a total of eight flaws addressed in this update.<\/p>\n<h2>Which versions are affected<\/h2>\n<ul>\n<li>NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37<\/li>\n<li>NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23<\/li>\n<li>NetScaler ADC FIPS before 14.1-73.37 FIPS<\/li>\n<li>NetScaler ADC FIPS and NDcPP before 13.1-37.279<\/li>\n<\/ul>\n<p>Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds. Citrix notes the bulletin applies only to customer-managed NetScaler ADC and NetScaler Gateway appliances. Cloud Software Group is upgrading Citrix-managed cloud services and Citrix-managed Adaptive Authentication separately.<\/p>\n<h2>Why NetScaler appliances are a high-value target<\/h2>\n<p>NetScaler appliances are commonly deployed as Internet-facing edge devices that provide remote access and application delivery for internal corporate networks. Compromising one gives an attacker a foothold at the network perimeter and a potential path into internal systems without first breaching an endpoint inside the organization.<\/p>\n<h2>How the campaign surfaced before the patch<\/h2>\n<p>The first public signals came from Citrix administrators reporting on Reddit that IT suppliers and security teams were privately contacting their organizations and advising them to shut down NetScaler appliances. Other administrators said law enforcement, CERTs, and national cybersecurity agencies had reached out about the issue.<\/p>\n<p>Cybersecurity firm watchTowr later stated publicly that it was responding to rumors of multiple unpatched Citrix NetScaler remote code execution vulnerabilities being exploited, after verifying the information with what it called authoritative sources.<\/p>\n<h2>Early warning from the Dutch NCSC<\/h2>\n<p>Before Citrix disclosed the flaws publicly, the Dutch National Cyber Security Center reportedly sent a pre-notification to organizations in the Netherlands warning of two critical NetScaler zero-days. Multiple people shared copies of the notification online. The notice said the agency had received information from a European partner CERT about two vulnerabilities that could independently lead to remote code execution.<\/p>\n<p>The notice described one flaw as allowing attackers to place shellcode directly into memory, with technical details on the second still being researched at the time. No CVE identifiers had been assigned and Citrix had not yet published an advisory. According to the notification, Citrix identified the vulnerabilities while investigating incidents in customer environments and confirmed the attacks, then submitted a notification under the European Union&#8217;s Cyber Resilience Act.<\/p>\n<p>The Dutch NCSC said exploitation had been observed at multiple Citrix customers worldwide, although it could not say whether the attacks were widespread, and warned that exploitation attempts could increase once Citrix released patches and additional technical details. Because NetScaler upgrades can cause downtime, the agency aimed to give organizations time to prepare, implement safeguards where possible, and install patches quickly once available. The Dutch NCSC declined to confirm the advisory to outside press, citing its role serving its national constituency.<\/p>\n<h2>What administrators should do now<\/h2>\n<p>With fixes available and active exploitation confirmed, administrators should upgrade affected NetScaler ADC and NetScaler Gateway appliances to the patched versions as soon as possible. Organizations that cannot apply the updates immediately should reduce Internet exposure where operationally feasible until the appliances can be patched. Because both flaws can be triggered without authentication, leaving unpatched appliances reachable from the Internet carries direct risk of remote compromise.<\/p>\n<p>Review Secure Private Access Hybrid deployments that use NetScaler instances and confirm they are on the recommended builds. For environments where DTLS is in use, CVE-2026-88772 should be treated as immediately relevant since DTLS is enabled by default on VPN virtual servers.<\/p>\n<h2>FAQ<\/h2>\n<h3>What are CVE-2026-88771 and CVE-2026-88772?<\/h3>\n<p>They are two critical NetScaler remote code execution vulnerabilities, both scored 9.5, that Citrix confirmed are being exploited as zero-days. CVE-2026-88771 is an unauthenticated input validation flaw, while CVE-2026-88772 is a memory overflow exploitable when DTLS is enabled, and DTLS is enabled by default on VPN virtual servers.<\/p>\n<h3>Which NetScaler versions need to be patched?<\/h3>\n<p>NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37, 13.1 before 13.1-64.23, NetScaler ADC FIPS before 14.1-73.37 FIPS, and NetScaler ADC FIPS and NDcPP before 13.1-37.279. Secure Private Access Hybrid deployments using NetScaler instances are also affected.<\/p>\n<h3>Why are NetScaler appliances a priority to fix?<\/h3>\n<p>NetScaler appliances are typically deployed as Internet-facing edge devices providing remote access and application delivery. Both vulnerabilities can be exploited without authentication, giving an attacker a direct path from the perimeter into internal systems.<\/p>\n<p><script type=\"application\/ld+json\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"FAQPage\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"What are CVE-2026-88771 and CVE-2026-88772?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"They are two critical NetScaler remote code execution vulnerabilities, both scored 9.5, that Citrix confirmed are being exploited as zero-days. CVE-2026-88771 is an unauthenticated input validation flaw, while CVE-2026-88772 is a memory overflow exploitable when DTLS is enabled, and DTLS is enabled by default on VPN virtual servers.\"}},{\"@type\":\"Question\",\"name\":\"Which NetScaler versions need to be patched?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37, 13.1 before 13.1-64.23, NetScaler ADC FIPS before 14.1-73.37 FIPS, and NetScaler ADC FIPS and NDcPP before 13.1-37.279. Secure Private Access Hybrid deployments using NetScaler instances are also affected.\"}},{\"@type\":\"Question\",\"name\":\"Why are NetScaler appliances a priority to fix?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"NetScaler appliances are typically deployed as Internet-facing edge devices providing remote access and application delivery. Both vulnerabilities can be exploited without authentication, giving an attacker a direct path from the perimeter into internal systems.\"}}]}]}<\/script><\/p>\n<hr style=\"margin:2.5em 0 1em;opacity:.35\" \/>\n<p style=\"font-size:.85em;opacity:.7\">This article summarizes reporting from <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days\/\" target=\"_blank\" rel=\"nofollow noopener\">bleepingcomputer.com<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Citrix confirms two critical NetScaler RCE flaws are under attack and has shipped patches. Here is what is affected and what to do next.<\/p>\n","protected":false},"author":3,"featured_media":304,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-281","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/281","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/comments?post=281"}],"version-history":[{"count":1,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/281\/revisions"}],"predecessor-version":[{"id":282,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/281\/revisions\/282"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/media\/304"}],"wp:attachment":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/media?parent=281"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/categories?post=281"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/tags?post=281"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}