Two NetScaler RCE Zero-Days Were Exploited Before the Advisory Existed

On 27 September 2026 CISA issued an alert amplifying Citrix's disclosure of eight new vulnerabilities in NetScaler ADC and NetScaler Gateway — CVE-2026-88771 through CVE-2026-88778 — and added the first two straight to its Known Exploited Vulnerabilities catalog. Both are critical, both allow remote code execution, both were exploited as zero-days, and CISA says it holds partner threat intelligence confirming active exploitation globally. Citrix's bulletin is CTX697096, and patches are out now.

The two KEV entries are independently exploitable, which is the detail that makes this a shut-things-down weekend rather than a patch-Tuesday routine:

  • CVE-2026-88771 (CVSS 9.5) — remote code execution from improper input validation. Unauthenticated, arbitrary commands, on all NetScaler ADC and Gateway deployments including the default configuration, with no additional feature needing to be enabled.
  • CVE-2026-88772 (CVSS 9.5) — a memory overflow leading to remote code execution or denial of service. Exploitable where DTLS is enabled — and DTLS is on by default on VPN virtual servers, which is to say, on exactly the boxes facing the internet for remote access.

Affected builds are 14.1 before 14.1-73.37, 13.1 before 13.1-64.23, ADC FIPS before 14.1-73.37 FIPS, ADC FIPS and NDcPP before 13.1-37.279, plus Secure Private Access hybrid deployments running NetScaler instances. The bulletin covers customer-managed appliances; Citrix says it is upgrading its own managed cloud services and Adaptive Authentication itself.

The disclosure ran in reverse: shutdown calls first, advisory second

The first public signs did not come from a vendor bulletin. NetScaler administrators reported on Reddit that IT suppliers and security teams were calling them over the weekend and advising them to shut their NetScalers down immediately — without being able to say why. Others described outreach from law enforcement, CERTs, and national cybersecurity agencies. Security firm watchTowr then publicly confirmed it was reacting to rumors of multiple unpatched NetScaler RCE flaws in the wild after verifying them with what it called authoritative sources.

Before Citrix published, the Dutch National Cyber Security Centre reportedly sent a pre-notification to organizations in the Netherlands: two critical NetScaler zero-days, each independently capable of remote code execution, one of them allowing attackers to place shellcode directly into memory. The notice said Citrix had found the flaws while investigating incidents in customer environments, had observed exploitation at multiple customers worldwide, and had filed a notification under the EU's Cyber Resilience Act. No CVE identifiers existed yet. The NCSC's stated reason for the early warning is worth remembering the next time an upgrade window looks inconvenient: NetScaler upgrades can mean downtime, so the advance notice was meant to buy preparation time — and it warned explicitly that exploitation attempts would likely increase once patches and technical details landed.

That is the window we are now in. The patches are public, the KEV entries are public, and the exploit details will follow.

Why edge boxes keep deciding the incident

NetScaler appliances sit where this site's recent coverage keeps pointing: the systems that grant access are the systems under attack. A compromised NetScaler hands an attacker a foothold at the network perimeter — remote access and application delivery for internal networks — with a path inward that never required phishing an endpoint. The same week brought an unauthenticated RCE zero-day in F5's BIG-IP APM OAuth path; earlier in the month it was a forged-JWT admin bypass in WSO2's API gateway layer and four no-login flaws in ServiceNow's AI Platform. Gateways, identity layers, and delivery edges are not the scenery around the assets — they are the assets, and they hold the credentials for everything behind them.

For agent deployments the exposure is concrete rather than theoretical. Agents reach enterprise systems through precisely this kind of edge: VPN and gateway sessions, API calls through delivery tiers, tokens minted and validated at the perimeter. An attacker with code execution on the NetScaler in front of those flows does not need to attack your agent at all.

What to do

  • Hunt before you patch. CISA urges checking for indicators of compromise prior to patching, using the IoCs Citrix made available through NetScaler Console and its bulletin guidance — and explicitly warns to preserve forensic evidence first, because applying updates may destroy visibility. CERT-EU's standing advice for this class of incident is the same: image and preserve, then remediate.
  • Upgrade to the fixed builds now. 14.1-73.37, 13.1-64.23, and the corresponding FIPS/NDcPP and Secure Private Access builds. If you cannot patch immediately, reduce the appliances' internet exposure as far as operations allow until you can — the weekend's shutdown advice was crude, but the instinct behind it was correct.
  • Treat the other six CVEs as part of the same job. The bulletin fixes eight flaws total; the two KEV entries are the burning ones, not the only ones. Patch to the full fixed build, not around it.
  • Assume post-exploitation, not just exploitation. These are perimeter RCE flaws with confirmed in-the-wild use against multiple customers. A patched appliance is not a clean network: review sessions, accounts, and lateral paths that were reachable from the device, and rotate credentials that traversed it.

Sources: