
On Saturday, September 26, some network administrators got strange advice from their vendors and national security teams: take your NetScaler appliances offline. No one would say why. The advisory did not exist yet. The next day Citrix published security bulletin CTX697096: eight vulnerabilities in NetScaler ADC and NetScaler Gateway, two already exploited in the wild as zero-days, and one needing no special configuration at all.
The instinct is to rush to the upgrade. That instinct is half right. The step most people skip comes before the upgrade, and Citrix, CISA, and the Dutch center all agree on it: check for compromise first, preserve your evidence, then patch. Patching closes the hole but does not evict whoever walked through it.
What the bulletin actually says
Citrix disclosed eight CVEs. Two have confirmed active exploitation:
| CVE | Flaw | Trigger | CVSS 4.0 |
|---|---|---|---|
| CVE-2026-88771 | Improper input validation, unauthenticated arbitrary command execution (CWE-20) | None. Every deployment, including default configuration | 9.5 |
| CVE-2026-88772 | Memory buffer overflow in DTLS, RCE or denial of service (CWE-119) | DTLS enabled, the default on VPN virtual servers | 9.5 |
The other six, CVE-2026-88773 through 88778, cover HTTP request smuggling, memory overflows, a policy bypass, and TCP sequence number prediction. None had confirmed exploitation at disclosure, and the same fixed builds address all eight. Only the TCP sequence number issue has a documented workaround; for the two exploited flaws there is no mitigation short of upgrading. Disabling DTLS would blunt the second flaw, but that turns off your VPN, which trades one problem for another.
Fixed builds are 14.1-73.37 and later, 13.1-64.23 and later, with FIPS and NDcPP equivalents. Versions 13.0 and 12.1 are end of life and get nothing; those appliances need to move to a supported branch. Note that the fixed builds from the previous NetScaler patch round do not cover these flaws, so being current as of early September is not the same as being safe.
Why these two are worse than the usual NetScaler advisory
NetScaler has been in the news before. This is the third time this year both products entered CISA's Known Exploited Vulnerabilities catalog. What makes this round different:
No configuration required. Most recent NetScaler flaws needed the appliance to be running as a Gateway or AAA virtual server before they applied. CVE-2026-88771 needs nothing. If it is a NetScaler on an affected build, it is exposed.
The default-on precondition. CVE-2026-88772 needs DTLS, and DTLS is on by default for VPN virtual servers. The thing that makes the appliance a VPN box is the thing that makes it vulnerable.
The attack was already underway. The first public reports of exploitation surfaced September 25. watchTowr confirmed exploitation September 26, before a patch or CVE number existed. Researcher Kevin Beaumont reported attacks unfolding through the whole month of September. This was a campaign that disclosure interrupted, not one that disclosure started.
Exploitation went mass within hours. GreyNoise saw mass reconnaissance start around 8:30 a.m. EDT on September 28, escalating to mass exploitation by that evening. Censys counted 42,735 exposed hosts, with the US at 32% and Germany at 13%.
The payload waits. watchTowr's root-cause analysis of CVE-2026-88771 is worth reading in full. Attacker-controlled request data lands in the appliance's logs, and a maintenance script later interpolates that log data into a shell command. The injected command can run up to 24 hours after the original request. Your logs showed the attack a day before the script fired. A working proof of concept for this one is already public, which usually means exploitation gets easier from here, not harder.
The order of operations
The standard reflex is patch first, ask questions later. The agencies explicitly inverted that here, because applying the update can destroy forensic evidence of what happened during the zero-day window. CISA's wording: updates may result in loss of forensic visibility.
Inventory first. From the CLI, run
show versionon every NetScaler you are responsible for. Compare against the fixed builds. Anything below the line is vulnerable right now.Preserve evidence before you touch anything. Secure logs and memory dumps before upgrading. If you patch over the evidence, you lose the ability to answer the question that matters most: were we already hit?
Hunt with the indicators. Citrix provides indicators of compromise through NetScaler Console (14.1-73.36 or later with telemetry enabled), or on request from Citrix Support for shops without Console. For the log-poisoning flaw, watchTowr notes the injected payloads show up in syslog next to
AAAD API: sending login reqandprocess_kernel_socketmessages. Look for shell metacharacters in logged login fields and User-Agent values.Upgrade on an emergency basis. Rapid7's phrasing, and it is the right one: waiting for the next maintenance window is not appropriate for a confirmed, mass-exploited, unauthenticated RCE on your network edge.
Assume breach for anything exposed and unpatched. Any internet-facing appliance that was unpatched during the exposure window, and the ACSC says to look back to at least September 4, should be treated as compromised until a compromise assessment says otherwise. Patching does not remove persistence an attacker already installed.
Restrict the management plane while the window is open. Limit management access to known-good IP ranges. This does not fix the flaw, but it shrinks what a foothold can reach.
Deal with the end-of-life branches. If anything is still on 13.0 or 12.1, there is no patch coming. The upgrade to a supported branch is the project, and it needed to start before this weekend.
Australia's cyber center issued a critical alert on October 1 confirming exploitation at Australian organizations, with espionage assessed as the likely motive. That is the shape of this campaign: not smash-and-grab ransomware, but quiet access to the box that sits in front of everything.
The boring lesson underneath
Every NetScaler incident post ends up making the same point: the appliance at your network edge is the most privileged box you own and the least monitored. It terminates your VPN, it proxies your authentication, it sees everything, and in a lot of shops it is the one device whose logs nobody reviews and whose management interface is reachable from places it should not be.
The durable fixes are the dull ones. Keep an accurate inventory of edge appliances and build numbers so step one of the checklist takes minutes, not a discovery project. Ship their logs somewhere you actually look. Restrict management interfaces to a short list of source addresses as a standing posture, not an emergency measure. And write the compromise-assessment runbook before the weekend you need it, because the order of operations matters most when everyone is in a hurry.
The people who took their appliances offline on September 26, on a warning nobody could explain, made the hardest version of this call: acting on incomplete information because the downside of waiting was worse than the cost of the downtime. It was not a fun call to make. It was the right one.
Sources
- Sept 28 Advisory: Citrix NetScaler ADC and NetScaler Gateway Zero-Day Remote Code Execution (CVE-2026-88771, CVE-2026-88772) — Censys, September 28, 2026
- Citrix confirms two NetScaler RCE zero-days exploited in attacks — BleepingComputer, September 27, 2026
- Update: Ongoing Exploitation of Citrix NetScaler ADC and NetScaler Gateway Vulnerabilities — eSentire, September 28, 2026 (updated September 29)
- CVE-2026-88771: Citrix NetScaler ADC and Citrix NetScaler Gateway Vulnerability — watchTowr, September 27, 2026
- Critical alert: Aussie organisations targeted in Citrix NetScaler hacking campaign — Cyber Daily, October 1, 2026
- Virtualization Watch Issue 003: Citrix NetScaler Zero-Days Hit Over a Weekend — dev.to, September 30, 2026
- Operators shut down NetScaler appliances two days before anyone would tell them why — r3konx.asia, September 30, 2026
- NetScaler Zero-Day Response: Patch, Then Assume Breach — Brandefense, October 1, 2026



