Citrix confirms active NetScaler exploitation: patching alone may not be enough
CVE-2026-88771 and CVE-2026-88772 allow unauthenticated remote code execution. Here are the fixed versions and a practical compromise-assessment plan.
- AUTHOR
- Karol Rapacz / CEO Breachroad · OSCP · PNPT
- PUBLISHED
- 2 October 2026
- READING TIME
- 10 min read
- TOPIC
- Vulnerabilities and CVEs
Citrix has released fixes for eight vulnerabilities in NetScaler ADC and NetScaler Gateway and confirmed that attackers are exploiting the two most severe flaws in the wild. CVE-2026-88771 and CVE-2026-88772 both have a CVSS 4.0 score of 9.5 and can lead to remote code execution without authentication.
The first vulnerability affects every NetScaler ADC and Gateway deployment, including the default configuration. The second requires DTLS, which is enabled by default on a VPN virtual server. For an internet-facing appliance, an appropriate response means both installing the update urgently and checking whether an attacker gained access before it was applied.
Which versions need to be updated
Supported NetScaler ADC and NetScaler Gateway 14.1 releases before 14.1-73.37 are vulnerable, as are 13.1 releases before 13.1-64.23. NetScaler 14.1-FIPS requires at least 14.1-73.37 FIPS, while 13.1-FIPS and 13.1-NDcPP require 13.1-37.279.
The bulletin covers customer-managed appliances. It also applies to hybrid Secure Private Access deployments that use NetScaler instances. Citrix-managed cloud services have been patched by the vendor. Organisations should still confirm their service model rather than assume that every product carrying the word “cloud” is updated automatically.
In addition to the two actively exploited remote-code-execution flaws, the release addresses HTTP request smuggling, a policy bypass, several memory-safety issues that can cause denial of service or code execution, and a problem involving predictable TCP sequence numbers. The precise prerequisites vary by feature and configuration.
What is known about exploitation of CVE-2026-88771
CERT-EU analysed activity affecting NetScaler appliances. Attackers inserted encoded commands into HTTP logs and then attempted to have them executed through incorrect processing in a diagnostic script. After gaining command execution, they modified the HTTP server configuration and delivered an internet-accessible web shell.
That observation has two consequences. First, an update closes the path used to exploit the vulnerability, but it does not remove a file left by an earlier intruder. Second, repeated unsuccessful requests may form part of an attempt to hit the required execution condition rather than ordinary scanning.
CERT-EU recommends searching authentication logs for PPE missed too many heartbeats, correlating this with the INDEX marker in HTTP logs, looking for base64 content in the User-Agent field and checking the integrity of httpd.conf. These indicators come from an observed attack chain, but their absence is not definitive proof that the appliance was not compromised.
A practical order of operations
First, identify every instance, including standby appliances, test systems, HA nodes and equipment operated by a supplier. Confirm the version on the appliance itself, not only in documentation. Restrict exposure of management interfaces and preserve evidence before restarting systems or clearing logs.
Next, install the appropriate vendor release. Environments using the relevant TCP configuration should also review the Enhanced ISN Generation guidance. Follow the correct procedure for a cluster or HA pair and verify the state of every node.
At the same time, begin a compromise assessment for any appliance that was internet-accessible while running a vulnerable version. Review configuration changes, new web files, accounts, scheduled activity, outbound connections and events in identity systems behind NetScaler. If the gateway provided remote access, consider invalidating sessions and rotating credentials or secrets that may have been reachable.
Finally, examine the path into the internal network. A VPN gateway or reverse proxy sits on a trust boundary, so a compromise may extend beyond the appliance itself. The investigation scope should reflect permissions, routes, identity integrations and the logs available.
Our guide to vulnerability management explains how to prioritise remediation. If there are signs of code execution, activate the incident response plan and preserve evidence before rebuilding. Teams can test their readiness through an incident-response tabletop exercise.
Source facts and Breachroad’s conclusions
Citrix security bulletin CTX697096 confirms eight vulnerabilities, active exploitation of CVE-2026-88771 and CVE-2026-88772, their prerequisites, affected products and fixed releases. CERT-EU’s advisory calls for immediate patching and compromise assessment of internet-facing devices. CERT-EU’s technical analysis describes the observed mechanism and evidence in the logs.
The order of operations, the recommended scope around the appliance and the caution against treating a negative indicator search as proof of safety are Breachroad’s conclusions. The exact update process should be adapted to the architecture and vendor instructions.


