What is Citrix NetScaler?
NetScaler ADC is Citrix's application delivery controller, a network appliance that terminates TLS, load balances traffic, and enforces web application firewall policy at the edge of an enterprise network. NetScaler Gateway is the same platform running as a remote-access gateway, giving employees VPN and single sign-on to internal applications. Both sit on the public internet by design and hold high-value material: TLS private keys, directory service credentials, and active user sessions. A gateway appliance is also, functionally, the front door to the internal network, so code execution on it is rarely the end of the intrusion.
Overview
CVE-2026-88772 is a memory overflow in NetScaler ADC and NetScaler Gateway that an unauthenticated remote attacker can trigger against appliances with DTLS enabled, leading to remote code execution or denial of service. Citrix rates it 9.5 Critical under CVSS 4.0; NVD scores it 8.1 High under CVSS 3.1, the lower score driven by High attack complexity. Both scoring systems agree it needs no privileges and no user interaction.
It is one of two zero-days in Citrix bulletin CTX697096, published 2026-09-27, which fixed eight NetScaler vulnerabilities (CVE-2026-88771 through CVE-2026-88778). Citrix stated that exploits of this CVE and CVE-2026-88771 had been observed against unmitigated deployments before any patch existed. The disclosure was preceded by an unusual scramble: over the weekend of 2026-09-26, IT suppliers, national CERTs, and law enforcement began telling organizations to shut NetScaler appliances down without explaining why. One administrator described being told by their supplier's security team to power the appliances off immediately, with no details offered.
The precondition matters less than it sounds. DTLS is enabled by default on VPN virtual servers, so a standard NetScaler Gateway deployment is vulnerable unless an administrator has deliberately turned DTLS off. In practice most gateway deployments meet the condition. Appliances used purely as load balancers, with no VPN virtual server configured, are less likely to be exposed to this specific issue, though CVE-2026-88771 in the same bulletin affects every deployment regardless of configuration.
Affected Versions
| Product | Vulnerable | Fixed |
|---|---|---|
| NetScaler ADC and NetScaler Gateway 14.1 | before 14.1-73.37 | 14.1-73.37 and later |
| NetScaler ADC and NetScaler Gateway 13.1 | before 13.1-64.23 | 13.1-64.23 and later |
| NetScaler ADC 14.1 FIPS | before 14.1-73.37 FIPS | 14.1-73.37 FIPS and later |
| NetScaler ADC 13.1 FIPS / NDcPP | before 13.1-37.279 | 13.1-37.279 and later |
Only deployments with DTLS enabled are affected. End-of-life branches receive no fix and must be migrated to a supported build.
Technical Details
The CWE assignment is CWE-119, improper restriction of operations within the bounds of a memory buffer. In plain terms, code handling DTLS traffic writes or reads outside the memory region it was given, either because a length field is trusted without checking it against the buffer size or because a size calculation can be made to wrap. Corrupting memory in a network-facing daemon lets an attacker either crash the process, which is the denial of service outcome, or steer execution, which is the remote code execution outcome.
Beyond that classification, the specifics are not public. Citrix has not described the affected component, the packet structure that triggers the overflow, or the code path involved. No independent reverse-engineering write-up of this CVE had been published at the time of writing, in contrast to CVE-2026-88771, which was reconstructed from a patch diff within days. No proof-of-concept code, public or private, has been reported. This page will describe the mechanism when a credible technical analysis exists; until then, treat the overflow internals as unknown rather than inferring them.
What is established: no authentication is required, the attack is reachable over the network against the DTLS listener, and CVSS 4.0 and 3.1 both assign High attack complexity, which usually indicates the attacker needs to win a race, groom the heap, or defeat some memory layout randomization rather than simply send one malformed packet. That is consistent with exploitation by a capable actor and inconsistent with commodity mass scanning.
Discovery
No external researcher has been credited. According to the NCSC-NL pre-notification, Citrix identified the vulnerabilities while investigating customer security incidents, and exploitation was confirmed at multiple Citrix customers worldwide. Information reached NCSC-NL via a European partner CERT, prompting the private warnings issued on 2026-09-26, and Citrix filed a notification under the EU Cyber Resilience Act. watchTowr, whose CEO Benjamin Harris publicly confirmed active exploitation before the vendor advisory landed, drove much of the early public awareness.
Exploitation Context
Citrix confirmed observed exploitation and acknowledged that attackers planted webshells on compromised appliances, warning customers that applying the update does not remove an attacker who is already in and recommending they retain experienced forensic investigators. CISA stated that threat actors are exploiting these vulnerabilities globally.
Exposure is substantial. Shadowserver counted more than 20,000 exposed NetScaler instances on 2026-09-28; Palo Alto Networks Cortex Xpanse counted over 50,277 exposed instances on 2026-09-27. The counts measure reachable appliances rather than confirmed vulnerable ones. Researchers characterized confirmed compromises as real but not widespread, which fits targeted operations rather than opportunistic exploitation.
No threat actor has been named. Tenable noted that roughly two-thirds of threat activity against NetScaler over the past seven years involved APT groups, and Kevin Beaumont assessed this campaign as probably nation-state aligned and well resourced, espionage rather than opportunistic. CVE-2026-88771 and CVE-2026-88772 are separate vulnerability classes with separate preconditions and there is no public evidence they are chained; each yields code execution on its own. This is the thirteenth NetScaler-related entry in the CISA KEV catalog.
Remediation
- Upgrade to 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, or 13.1-37.279 as applicable. Citrix has published no workaround and states patching is the only fix.
- Preserve evidence before patching. Citrix and CISA both warn that updating can destroy forensic visibility. Capture logs, configuration, and disk state first if compromise is plausible.
- If you cannot patch immediately, reduce internet exposure where operationally possible, up to and including taking the appliance offline. That was the advice several national CERTs gave before the advisory existed. Disabling DTLS on VPN virtual servers removes this vulnerability's precondition, but note it does not address CVE-2026-88771, which needs no precondition at all, so it is not a substitute for patching.
- Run the IOC check. NetScaler Console 14.1-73.36 or later with telemetry enabled exposes an IOC scan on the Security Advisory page. Citrix cautions that the IOCs do not cover every technique, so a clean result is not proof the appliance is uncompromised.
- Treat an internet-facing appliance that ran an unpatched build during September 2026 as suspect. Follow Citrix CTX694799: rotate every credential the appliance held, replace TLS certificates and keys, terminate all active sessions, and reset local accounts.
- Hunt for unexpected outbound connections from the appliance, unexplained gaps in logging, DTLS listener crashes or restarts, new files in web-accessible paths, and administrative sessions you cannot account for.
- Federal civilian agencies were required to remediate by 2026-09-30 under BOD 26-04, a three-day window, and to perform the forensic triage the directive specifies.
Key Details
| Property | Value |
|---|---|
| CVE ID | CVE-2026-88772 |
| Vendor / Product | Citrix — NetScaler |
| NVD Published | 2026-09-27 |
| NVD Last Modified | 2026-09-28 |
| CVSS 3.1 Score | 8.1 |
| CVSS 3.1 Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Severity | HIGH |
| CWE | CWE-119 find similar ↗ |
| CISA KEV Added | 2026-09-27 |
| CISA KEV Deadline | 2026-09-30 |
| Known Ransomware Use | No |
CVSS 3.1 Breakdown
Required Action
Timeline
| Date | Event |
|---|---|
| 2026-09-26 | NCSC-NL privately warns Dutch organizations; suppliers and CERTs advise shutting NetScaler appliances down |
| 2026-09-27 | Citrix publishes security bulletin CTX697096 with fixed builds; CVE record published |
| 2026-09-27 | CISA issues alert and adds CVE-2026-88772 to the Known Exploited Vulnerabilities catalog |
| 2026-09-30 | CISA BOD 26-04 remediation deadline |
References
| Resource | Type |
|---|---|
| NVD - CVE-2026-88772 | Vulnerability Database |
| CISA KEV Catalog Entry | US Government |
| Citrix Security Bulletin CTX697096 - CVE-2026-88771 through CVE-2026-88778 | Vendor Advisory |
| Citrix CTX694799 - Steps to Take if NetScaler ADC is Suspected of Compromise | Vendor Advisory |
| CISA Alert - Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway | US Government |
| Tenable - Citrix NetScaler Zero-Day RCE Vulnerabilities FAQ | Security Research |
| watchTowr - Citrix NetScaler Zero-Day RCE FAQ | Security Research |
| Unit 42 Threat Brief - NetScaler Zero Days Exploited in the Wild | Security Research |
| BleepingComputer - Citrix Confirms Two NetScaler RCE Zero-Days Exploited in Attacks | News |
| Cybersecurity Dive - Citrix Urges Immediate Upgrades Amid Widespread Exploitation | News |