Citrix Patches Two Exploited NetScaler RCE Zero-Days

CVE-2026-88771 lets unauthenticated attackers run commands on default NetScaler setups. Citrix fixed eight flaws in 14.1-73.37 and 13.1-64.23.

By Vivek • • 5 Min Read • 0 • Follow on Google News Add to Preferred Source
NetScaler RCE exploited in wild

Citrix on Sunday released patches for two critical NetScaler ADC and NetScaler Gateway vulnerabilities that attackers exploited as zero-days, one of which allows unauthenticated command execution on appliances running the default configuration.

The flaws, tracked as CVE-2026-88771 and CVE-2026-88772, each carry a CVSS v4 score of 9.5. They are among eight vulnerabilities addressed in security bulletin CTX697096.

“Exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments has been observed,” Citrix said. The company did not say who was behind the attacks, how many organisations were hit, or when exploitation began.

The fixes are in NetScaler ADC and NetScaler Gateway 14.1-73.37 and 13.1-64.23, NetScaler ADC 14.1-73.37 FIPS, and 13.1.37.279 for the 13.1-FIPS and 13.1-NDcPP editions. Appliances updated in August for the exploited authentication bypass CVE-2026-19490 remain vulnerable, because those builds, 14.1-73.32 and 13.1-63.21, predate the new fixes.

CVE-2026-88771 is an improper input validation flaw that lets a remote, unauthenticated attacker execute arbitrary commands on the appliance. According to Citrix, every NetScaler ADC and NetScaler Gateway deployment is affected, including those left at their default configuration, and no additional features need to be enabled.

CVE-2026-88772 is a memory overflow that can lead to remote code execution or denial of service. It can only be exploited when DTLS, the UDP-based version of the TLS encryption protocol, is enabled, and NetScaler turns DTLS on by default for VPN virtual servers.

The patches follow a weekend in which organisations took NetScaler appliances offline after IT suppliers and CERT teams relayed shutdown advice attributed to the Dutch National Cyber Security Centre. On Saturday, security firm watchTowr said two unpatched NetScaler RCE flaws had been exploited in the wild and were discovered during forensic investigations.

The new zero-days follow two other NetScaler flaws that were exploited this year. CISA added CVE-2026-8452 to its Known Exploited Vulnerabilities catalog in August and CVE-2026-19490 on September 9. As of publication, the agency had not listed either of the new flaws.

Which NetScaler deployments are affected?

Citrix said that every NetScaler ADC and NetScaler Gateway deployment is affected by at least one of the eight flaws and recommends upgrading immediately. The remaining six vulnerabilities depend on which features and virtual servers are configured.

For CVE-2026-88772, a VPN virtual server configured with -dtls OFF is not exposed. A VPN virtual server without that setting has DTLS enabled by default, as does any DTLS-type virtual server.

CVE-2026-88773, an HTTP request smuggling flaw that Citrix found internally, affects appliances with load balancing, content switching, VPN or authentication virtual servers of type HTTP or SSL. CVE-2026-88774 affects the same configurations: URLs that are not normalised can slip past the web application firewall and security rules. It was reported externally and has been fixed since the 14.1-72 builds.

Three more memory overflows can cause erratic behaviour or denial-of-service attacks. CVE-2026-88775 affects appliances configured as a Gateway or AAA virtual server. CVE-2026-88776 affects load-balancing virtual servers of the Oracle type. CVE-2026-88777 affects load balancing, content switching and CGNAT (LSN/NAT64) deployments that use non-HTTP Layer 7 features such as FTP, RTSP, DNS64 or NAT64.

CVE-2026-88778 allows TCP initial sequence number prediction on appliances with TCP-based virtual servers where Enhanced ISN Generation is disabled. Running show ns tcpparam | grep "Enhanced ISN Generation" shows the setting, and fixing this flaw requires a configuration change in addition to the update.

What should admins check before upgrading?

Build 13.1-64.23 has a known issue that can cause an appliance to enter a reboot loop during the upgrade under a specific configuration. Citrix said admins should run show ns variable, and if the command lists configured variables, plan to upgrade to 13.1-64.24 instead.

The Security Advisory feature in NetScaler Console may wrongly flag appliances on 13.1-64.23 as vulnerable. Citrix said an automatic advisory update will correct this, and no Console or appliance upgrade is needed.

The new builds also stop accepting unsigned SAML assertions. Any configuration that sets samlRejectUnsignedAssertion to OFF is converted to the secure default during the upgrade, so identity providers must issue signed assertions.

Organisations that powered their NetScalers down over the weekend can now apply the update before bringing the appliances back online.

How can admins check NetScaler for compromise?

Citrix is making generic indicators of compromise available through the Security Advisory page in NetScaler Console, both in the cloud service and on-premises, starting with Console 14.1-73.36 and later with Cloud Connect. The scan requires the telemetry channel to be enabled and appears only once Citrix releases the detection logic. Customers who do not use Console can ask Citrix Support for the indicators or for help running the scan.

Citrix cautioned that the indicators do not cover every technique attackers use and may fail to identify actual compromises, and it advised hiring experienced forensic investigators. The company also recommends NetScaler Console’s File Integrity Monitoring and forwarding NetScaler logs to an external SIEM.

Updating does not remove an attacker who is already inside an appliance. Following an earlier NetScaler zero-day in 2025, the Dutch NCSC warned that intruders could maintain access even after patches were applied.

Community Discussion

Join the conversation. Ask questions, share solutions, and help others.

0 Comments

Be the first to start the discussion!

Leave a Comment

Your email address will not be published. Required fields are marked *

We respect your privacy, your information is safe with us.

Latest Articles

View all