Citrix NetScaler Vulnerability: CVE-2026-88771 and CVE-2026-88772

On 27 September 2026, Citrix disclosed unauthenticated remote code execution vulnerabilities in NetScaler ADC and NetScaler Gateway. For CVE-2026-88771 and CVE-2026-88772, advisory CTX697096 gives a CVSS v4.0 score of 9.5. Citrix says it has observed exploitation on unpatched…
Summary
On 27 September 2026, Citrix disclosed unauthenticated remote code execution vulnerabilities in NetScaler ADC and NetScaler Gateway. For CVE-2026-88771 and CVE-2026-88772, advisory CTX697096 gives a CVSS v4.0 score of 9.5. Citrix says it has observed exploitation on unpatched devices. The US Cybersecurity and Infrastructure Security Agency (CISA) added both flaws to the Known Exploited Vulnerabilities (KEV) catalog on 27 September 2026, described the exploitation as global, and set 30 September 2026 as the due date for US federal agencies.
- CVE-2026-88771: Improper input validation in the default configuration. The result is unauthenticated remote code execution.
- CVE-2026-88772: A memory overflow when DTLS is enabled, leading to remote code execution or denial of service. Citrix says DTLS is on by default on a VPN virtual server (vServer).
- Solution status: Patches are available for the builds named below. The sources do not describe a workaround.
- Other issues in the same advisory: CVE-2026-88773 through CVE-2026-88778 are additional issues in CTX697096. Only CVE-2026-88771 and CVE-2026-88772 are confirmed exploited. This bulletin does not assign scores or exploitation status to the other IDs.
What it is
Both vulnerabilities allow an unauthenticated attacker to run code remotely on NetScaler ADC and Gateway. CVE-2026-88771 is an input-validation flaw in the default configuration, so it does not depend on an extra feature being turned on. CVE-2026-88772 is a memory overflow that can lead to code execution or a denial of service when DTLS is enabled. According to Citrix, DTLS is the default on a VPN vServer.
Public disclosure was on 27 September 2026. Citrix reported exploits against devices that had not been patched. CISA added both CVEs to the KEV catalog the same day.
Who is affected
Deployments of NetScaler ADC or NetScaler Gateway that are still on a build older than the patch levels below are affected. These products are often exposed to the internet for remote access (VPN) and application delivery, so the lack of an authentication requirement applies directly to the edge device.
On 27 September 2026, Palo Alto Networks Unit 42 estimated that about 50,277 exposed instances could be vulnerable. That figure is a third-party estimate from Unit 42. It is not a Doğa Network measurement, and it is not a count of confirmed vulnerable devices.
This bulletin does not treat NetScaler branches that the sources do not name as either affected or unaffected.
Affected versions
| Line | Affected | Patch build |
|---|---|---|
| 14.1 | Before 14.1-73.37 | 14.1-73.37 |
| 13.1 | Before 13.1-64.23 | 13.1-64.23 |
| FIPS | Before 14.1-73.37 FIPS | 14.1-73.37 FIPS |
| FIPS/NDcPP | Before 13.1-37.279 | 13.1-37.279 |
What to do
- Confirm the build. Compare the build running on each ADC and Gateway appliance with the table above. If you use a VPN vServer, also note whether DTLS is enabled; CVE-2026-88772 depends on that condition.
- Preserve evidence before you patch. CISA says the update can wipe forensic evidence. Keep the relevant logs and other evidence, following your own incident-response process, before you apply the update.
- Apply the patch. Move the 14.1 line to 14.1-73.37, the 13.1 line to 13.1-64.23, the FIPS line to 14.1-73.37 FIPS, and the FIPS/NDcPP line to 13.1-37.279. The sources do not offer a workaround in place of these updates.
- Check the appliance after patching. Confirm that the running build is the one you intended. If you suspect exploitation, review configuration and session records as part of incident response. This bulletin does not list attack-specific indicators, because the sources used here do not provide one.
How Doğa Network can help
Our team can help with a NetScaler build inventory, planning the patch window, and preserving evidence before the update. Call +90 850 888 3642 or email hi@doga.network.



