Citrix released emergency security updates on Sunday, September 27, addressing two critical zero-day vulnerabilities in NetScaler ADC and NetScaler Gateway. The release follows a weekend of urgent warnings from national security agencies, including the Dutch National Cyber Security Centre (NCSC-NL), which had advised organizations to shut down affected appliances entirely because of active exploitation and a lack of immediate patches.
The vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, both carry a critical CVSS v4.0 score of 9.5. Citrix confirmed that these flaws were being targeted in the wild prior to the patch release. Security firm watchTowr verified that the exploits were identified during forensic investigations of compromised customer environments, suggesting that threat actors had already established a foothold in some networks.
CVE-2026-88771 is an improper input validation flaw that allows unauthenticated remote command execution. This vulnerability is particularly dangerous as it affects all NetScaler deployments regardless of specific configuration. The second flaw, CVE-2026-88772, is a memory overflow vulnerability that requires Datagram Transport Layer Security (DTLS) to be enabled. Because DTLS is the default setting for many VPN virtual servers, a significant portion of the NetScaler install base was vulnerable by default.

The NCSC-NL’s decision to issue private warnings over the weekend, utilizing a TLP:AMBER+STRICT protocol to reach administrators directly, highlighted the severity of the situation. Recommending the complete shutdown of perimeter enterprise hardware is a rare move, typically reserved for critical RCE flaws where no other mitigation is effective. While some administrators considered disabling DTLS to mitigate CVE-2026-88772, that action provides no defense against the unauthenticated command execution capabilities of CVE-2026-88771.
Required Patch Versions
Citrix has urged administrators to move beyond temporary mitigations and apply the firmware updates immediately. The following versions contain the necessary fixes:
- NetScaler ADC and NetScaler Gateway 14.1-73.37 and later
- NetScaler ADC and NetScaler Gateway 13.1-64.23/24 and later
This incident follows a pattern of high-stakes targeting against NetScaler appliances throughout 2026. Administrators who were forced to keep appliances online during the unpatched window are advised to check for indicators of compromise, as the patches will secure the system moving forward but will not remove an existing attacker presence.
