Citrix NetScaler unauthenticated RCE vulnerability

Citrix confirmed on September 27 that a Citrix NetScaler unauthenticated RCE vulnerability, tracked as two separate CVEs, was already being exploited in the wild before any patch existed. CVE-2026-88771 lets an attacker with no credentials run arbitrary commands on any NetScaler ADC or Gateway appliance in a vulnerable version, default configuration included. Its sibling flaw, CVE-2026-88772, hits most Gateway deployments too, because the setting it depends on ships turned on by default.
What Happened
CVE-2026-88771 is an improper input-validation flaw (CVSS 9.5) that allows an unauthenticated, remote attacker to execute arbitrary commands on the appliance. Citrix and independent researchers at watchTowr and Rapid7 confirm the attack complexity is low and that every NetScaler ADC and NetScaler Gateway deployment on an affected version is exposed, whether or not the appliance has been hardened beyond factory settings.
CVE-2026-88772 (also CVSS 9.5) is a memory-buffer overflow in DTLS handling that can trigger remote code execution or denial of service. DTLS is enabled by default on VPN virtual servers, so most Gateway deployments meet the precondition without any deliberate configuration choice.
Both vulnerabilities were confirmed exploited as genuine zero-days, meaning attackers were using them before Citrix’s own disclosure. Fixed builds shipped September 27 in security bulletin CTX697096: NetScaler ADC and Gateway 14.1-73.37 or later, and 13.1-64.23 or later on the 13.1 branch. The same bulletin patches six additional, lower-severity CVEs (CVE-2026-88773 through CVE-2026-88778) in the same builds, so one upgrade resolves the full set. CISA added both headline CVEs to its Known Exploited Vulnerabilities catalog on September 27, with a federal remediation deadline of Wednesday, September 30, and a forensic-triage requirement under Binding Operational Directive 26-04, not remediation alone.
Why It Matters
NetScaler ADC and Gateway are among the most widely deployed load-balancing and VPN gateway products in DACH banking, insurance, healthcare and manufacturing environments. “Default configuration is exploitable” removes the usual first line of defense IT teams reach for, the assumption that a hardened, non-default setup is safe. This joins a long list of 2026 edge-device vendors DIESEC has tracked with actively exploited CVEs, including FortiGate, Cisco, Palo Alto, Check Point, SonicWall, WatchGuard, Zyxel, F5 and Arista. Internet-facing gateway appliances are, by a wide margin, the most consistently exploited category of infrastructure this year.
The BOD 26-04 forensic-triage requirement is worth flagging on its own: CISA is asking federal agencies not just to patch, but to assume the appliance may already be compromised and investigate accordingly. Any DACH organization treating CISA KEV deadlines as a de facto patching SLA, a common practice in Mittelstand vendor-risk programs, should read that requirement the same way.
What You Should Do Now
- Upgrade every NetScaler ADC and NetScaler Gateway appliance to 14.1-73.37 or later, or 13.1-64.23 or later on the 13.1 branch, immediately, not on the next scheduled maintenance window.
- Verify: check your current build number against the fixed versions above on every appliance, including any standby or disaster-recovery unit that might have been missed in a first pass.
- If you cannot patch immediately, restrict management and Gateway interface exposure to trusted networks only and disable DTLS on VPN virtual servers where it is not operationally required, as an interim reduction of the CVE-2026-88772 attack surface. Treat this only as a stopgap until the appliance is actually patched.
- Monitor for unexpected processes, unfamiliar scripts, or unusual outbound connections originating from NetScaler appliances, and treat any exposed appliance that was unpatched before September 27 as a candidate for forensic review, consistent with CISA’s BOD 26-04 guidance. Upgrading the build tells you nothing about whether the box was already touched.
If a specific detection signature is not yet available from your monitoring vendor, say so explicitly to your SOC rather than assuming coverage exists, given how recently these builds were released.
DIESEC Perspective
We’ve flagged the same BOD 26-04 forensic-triage language on Check Point, F5 and Arista advisories in the past month alone. That repetition is the signal: CISA now treats pre-authentication gateway-plane vulnerabilities as presumed-breach events by default, not edge cases. DACH organizations that only track “is it patched” in their vendor-risk dashboards are missing half of what this guidance actually asks for.
Not sure whether your NetScaler estate has already been quietly exposed since before the patch shipped? Contact DIESEC for a rapid edge-device exposure assessment and forensic triage review.
Sources: Citrix Security Bulletin CTX697096 | The Hacker News
Published: 2026-09-29 | Category: Vulnerabilities & Patches | ~4 min read

