Who should review this?
Organisations that operate or depend on customer-managed NetScaler
This guidance is relevant if your organisation, hosting provider or managed-service supplier uses customer-managed NetScaler ADC, NetScaler Gateway or Secure Private Access Hybrid instances. These appliances may provide remote access, VPN, application delivery, authentication or load-balancing services at a sensitive boundary.
Do not rely on the product name alone
Confirm who manages the appliance, the installed build, its configuration and its exposure. Citrix says its managed cloud services and Citrix-managed Adaptive Authentication are updated by Cloud Software Group; customer-managed instances require customer action.
Why the feed elevated it
Exploitation evidence makes this an immediate review
Known exploitation
Citrix reports observed exploitation of both vulnerabilities on unmitigated deployments; CISA has placed both in its KEV catalogue.
Boundary technology
NetScaler often sits between the internet and important applications, identities or internal services, increasing the consequence of compromise.
Remote code execution
Both vulnerabilities can lead to code execution without a valid user account when their respective preconditions are met.
Short response window
The CISA federal deadline is 30 September. Other organisations should treat it as a strong risk signal, not as a universal legal deadline.
The feed has done its job
It has raised a decision-useful signal: known exploitation, a critical network appliance and vendor fixes. The next step is to match that signal to real assets, configurations, owners and service consequences.
Confirmed technical picture
Two exploited flaws with different preconditions
| Vulnerability | Confirmed effect | Applicability |
|---|---|---|
| CVE-2026-88771 CVSS 4.0: 9.5 | Improper input validation can allow an unauthenticated attacker to execute arbitrary commands. | Citrix states that all affected NetScaler ADC and Gateway deployments are vulnerable, including default configurations. |
| CVE-2026-88772 CVSS 4.0: 9.5 | A memory-overflow vulnerability can lead to remote code execution or denial of service. | DTLS must be enabled. Citrix notes that DTLS is enabled by default on a VPN virtual server unless it is explicitly disabled. |
The same Citrix bulletin covers six additional vulnerabilities. They should be included in the change and exposure review even though CVE-2026-88771 and CVE-2026-88772 are the two for which exploitation has been reported.
Affected and fixed builds
Use the live vendor bulletin as the final authority
| Product line | Affected before | Vendor-fixed build |
|---|---|---|
| NetScaler ADC and NetScaler Gateway 14.1 | 14.1-73.37 | 14.1-73.37 or later |
| NetScaler ADC and NetScaler Gateway 13.1 | 13.1-64.23 | 13.1-64.23 or later in the 13.1 line |
| NetScaler ADC 14.1-FIPS | 14.1-73.37 FIPS | 14.1-73.37 FIPS or later |
| NetScaler ADC 13.1-FIPS and 13.1-NDcPP | 13.1.37.279 | 13.1.37.279 or later |
Unsupported versions need an escalation decision
If an appliance cannot move to a supported fixed build, do not record it as remediated. Restrict exposure, document the service dependency and exception owner, seek vendor or supplier advice and set a dated replacement or retirement decision.
Safe response workflow
Seven actions for an evidence-preserving response
Confirm every deployment and owner
Identify physical, virtual, FIPS, NDcPP, development, disaster-recovery and supplier-managed instances. Record the build, management owner, service purpose and internet exposure.
Establish configuration and reachability
Confirm whether DTLS is enabled and identify the VPN, authentication, load-balancing and application-delivery services each appliance supports. Do not assume that an appliance behind another control is unreachable.
Preserve evidence before changing state
Where feasible, retain appliance, remote-syslog, console, firewall, DNS and authentication evidence before shutdown, reboot, patching or rebuild. Collect relevant diagnostic information and document the time of each action.
Reduce exposure and contain proportionately
Prioritise internet-facing appliances. Restrict management and service access where operationally possible, while agreeing continuity arrangements for remote access and critical applications.
Install the relevant fixed build
Follow the current Citrix bulletin and your approved emergency-change process. Include paired appliances, secondary sites and dormant systems that could later return to service.
Validate security and service operation
Confirm the running build, external exposure, authentication, VPN and published-application workflows. Retest from the user and administrator perspectives rather than relying only on a successful upgrade message.
Investigate and escalate suspicious findings
Patching closes the vulnerability; it does not remove an established attacker. Activate incident response if evidence, exposure or uncertainty warrants it, and assess credentials, sessions, certificates, connected applications and internal movement.
Compromise assessment
Look beyond the appliance update
Where an affected appliance was reachable before the fix—or where reliable historic evidence is unavailable—review the latest Citrix indicators and compromise guidance. Useful evidence includes:
Preserve first; eradicate deliberately
Do not destroy the only useful evidence through an unrecorded reboot or rebuild. Where compromise is suspected, isolate proportionately, obtain specialist support and follow the current vendor incident-response guidance.
Close with assurance
Record evidence that the risk was actually reduced
RACF-CC alignment
One feed alert crosses the control system
Vulnerability Management identifies and remediates affected builds; Network Segmentation limits unnecessary exposure; Monitoring and Detection preserves and correlates evidence; and Incident Response manages suspected compromise. Governance and Risk records service ownership, exceptions and residual uncertainty.
Urgency still needs coordination
Understand → preserve → contain → update → validate → investigate → evidenceA technically correct emergency change can still disrupt remote care or access to important systems. Use the shortest safe route to risk reduction, with an accountable service owner and a tested fallback.
Primary and authoritative sources
Recheck the live guidance before acting
- Citrix: NetScaler ADC and NetScaler Gateway security bulletin — affected configurations, fixed builds and current vendor instructions.
- CISA: Two vulnerabilities added to the Known Exploited Vulnerabilities catalogue — exploitation status and federal response deadline.
- CVE record: CVE-2026-88771 — improper-input-validation vulnerability record.
- CVE record: CVE-2026-88772 — memory-overflow vulnerability record.
- Citrix: Steps to take if NetScaler ADC is suspected to be compromised — current vendor incident-response guidance.
- Canadian Centre for Cyber Security: Alert AL26-024 — evidence-preservation, investigation and risk-assessment guidance.
Last checked: 28 September 2026. This is a rapidly developing issue. Confirm the current Citrix bulletin, CISA status and supplier advice immediately before making a technical change.
Voluntary support
Found this useful? Support Trends4You
Trends4You's practical guides, RACF-CC resources and downloadable tools are provided free of charge. If they've helped you or your organisation, you can support the time and hosting that keeps them freely available.
Support is optional, handled securely by Stripe and does not provide additional access.
