BLOG

CISA Just Flagged Two Critical Citrix NetScaler Flaws — Patch Edge Appliances This Week

September 28, 2026

Over the weekend, CISA added two critical Citrix NetScaler vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog — CVE-2026-88771 and CVE-2026-88772 — and set a federal remediation deadline of September 30, 2026. Citrix (Cloud Software Group) confirmed both were exploited as zero-days before patches shipped. Both score CVSS 9.5 and can independently lead to unauthenticated remote code execution on affected NetScaler ADC and NetScaler Gateway appliances.

If August’s SharePoint and vCenter stories were about how fast an internet-facing server can fall after a PoC lands, this one is about the appliances that sit at the edge of many businesses: load balancers, SSL VPN gateways, and the front door to published apps. Compromise there often means a beachhead into authentication paths and the systems behind them.

What CISA and Citrix said

On September 27, 2026, Citrix published security bulletin CTX697096 covering eight NetScaler issues (CVE-2026-88771 through CVE-2026-88778). The same day, CISA amplified the disclosure, confirmed global exploitation of the two worst flaws, added them to the KEV catalog, and pointed Federal Civilian Executive Branch agencies to remediate under Binding Operational Directive (BOD) 26-04 by September 30.

That three-day federal window is the signal private-sector teams should not ignore. KEV listings mean confirmed exploitation — not theoretical risk scoring.

Why ADC / Gateway matters for MSPs and mid-market IT

CVE-2026-88771 is improper input validation that lets an unauthenticated attacker run arbitrary commands. It affects all NetScaler ADC and Gateway deployments in the vulnerable version ranges — including default configurations. No special feature has to be turned on.

CVE-2026-88772 is a memory-buffer issue that can lead to remote code execution or denial of service when DTLS is enabled. That sounds niche until you read Citrix’s note: DTLS is enabled by default on VPN virtual servers unless an admin explicitly disabled it. Many Gateway / SSL VPN deployments meet that precondition out of the box.

The same bulletin also fixes six additional issues (request smuggling, policy bypass, other memory/DoS paths, TCP ISN prediction). Those are not on the KEV list as of this writing — but if you are opening a maintenance window for the two exploited CVEs, apply the fixed builds that cover the full bulletin. Do not cherry-pick.

Affected builds and the fix

Per Citrix, supported versions are vulnerable before these releases (install these or later):

  • NetScaler ADC / Gateway 14.1-73.37 and later
  • NetScaler ADC / Gateway 13.1-64.23 and later (13.1 branch)
  • NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later
  • NetScaler ADC 13.1-FIPS / 13.1-NDcPP 13.1.37.279 and later

The bulletin applies to customer-managed NetScaler ADC and Gateway (including Secure Private Access hybrid setups that use customer-managed instances). Citrix-managed cloud services and Adaptive Authentication are updated by Cloud Software Group — still worth confirming which side of that line you sit on.

NetScaler 12.1 and 13.0 are end-of-life and do not receive these fixes. Those appliances need a migration to a supported release, not a hope that nobody is scanning them.

What to do this week

  • Inventory every NetScaler ADC and Gateway — production, DR, lab, and that “temporary” VPN box from two years ago. Note build and whether it is internet-reachable.
  • Check for compromise before you patch when you can. CISA encourages looking for indicators first. Citrix publishes IoC guidance via NetScaler Console and a separate compromise-response article. Updates can wipe forensic visibility — preserve evidence if something looks wrong.
  • Apply the fixed builds as an emergency change, not next month’s window. September 30 is an outer bound for federal agencies; treat it as urgency, not leisure, for everyone else.
  • If you suspect compromise: isolate, preserve forensics, rebuild from known-clean media/config where Citrix recommends it, and rotate credentials, secrets, and certificates that lived on or authenticated through that appliance. Then inspect systems the appliance could reach.
  • After the patch: reduce unnecessary internet exposure, keep management interfaces off the open internet, and stay on a supported train so the next emergency bulletin is not blocked by EOL.

The MSP translation

For a mid-sized business without a dedicated appliance team watching CISA alerts every weekend, the gap is operational: knowing which edge devices you own, who patches them, and how fast an emergency window can open. That is managed IT work — not forwarding a headline after attackers already had a head start.

If you run NetScaler (or your IT partner does), ask three plain questions today: What build are we on? Is it at or above the fixed releases above? Did anyone look for compromise before or during the upgrade?

Essential Solutions helps South Louisiana businesses — and clients further afield — keep edge infrastructure, Microsoft environments, and day-to-day operations on a sane patch cadence. Need a second set of eyes on exposure or an emergency change window? Call the public desk at (225) 336-0273 or reach out through esllc.com.