Cyber Security

Citrix NetScaler zero-days under attack: a brutal week for the network edge

Published
Read time3 min read
Cyber Security

On 27 September 2026 Citrix confirmed that two critical remote code execution vulnerabilities in NetScaler ADC and NetScaler Gateway were being exploited in the wild, and published fixed builds the same day. CISA added one of them to its Known Exploited Vulnerabilities catalogue within hours. It was the second time in a week that internet-facing network appliances from major vendors turned up on that list.

What was disclosed

Citrix security bulletin CTX697096 covers both flaws, alongside six others. CVE-2026-88771 is an improper input validation issue carrying a CVSS v4 score of 9.5 that lets an unauthenticated attacker run arbitrary commands. It affects all NetScaler ADC and NetScaler Gateway deployments, with no particular feature needing to be enabled. CVE-2026-88772, also 9.5, is a memory overflow that can lead to remote code execution or denial of service, and affects appliances with DTLS enabled — which, as watchTowr notes, is the default for VPN virtual servers, so a NetScaler Gateway is in scope unless DTLS has been explicitly turned off.

CISA added CVE-2026-88771 to its Known Exploited Vulnerabilities catalogue on 27 September 2026, citing evidence of active exploitation. Researchers at watchTowr reported observing exploitation of both issues against unmitigated deployments.

The week before it

On 22 September CISA had already added four other actively exploited vulnerabilities, every one of them in an internet-facing appliance:

  • CVE-2026-85102 — Check Point multiple products, improper certificate validation
  • CVE-2026-93616 — Check Point multiple products, path traversal
  • CVE-2026-93952 — Arista VeloCloud Orchestrator, improper input validation
  • CVE-2026-94127 — F5 BIG-IP APM, heap-based buffer overflow
Key points
Common thread
Six actively exploited flaws in one week, all in appliances that sit at the network perimeter.
Why attackers like them
They are internet-facing by design, hold credentials and sessions, and are rarely covered by endpoint tooling.
Practical risk
These devices often terminate VPN and remote access, so compromise is rarely contained to the device.

Why the pattern matters more than the CVEs

Every organisation with a NetScaler should be patching this week, and that part needs no analysis. The more useful question is why the same category of device keeps appearing.

Perimeter appliances are attractive because they are, by definition, reachable. They frequently hold authentication material, they broker access to everything behind them, and they sit outside the reach of the EDR and logging that covers servers and laptops. They are also the devices least likely to appear on a software asset register, because they were bought as hardware and treated as infrastructure rather than as software that needs a patch cycle.

Four things worth checking

  • Know what you actually expose. Most organisations can name their applications. Far fewer can produce a current list of every appliance with a public interface, its firmware version and who owns patching it.
  • Treat mitigations as temporary. Vendor workarounds buy time; they are not fixes, and attackers routinely find ways around them.
  • Assume compromise where exploitation predates your patch. For an actively exploited flaw, patching closes the door but does not evict anyone already inside. Hunt for web shells, new accounts and configuration changes.
  • Ask your suppliers the same question. If your payroll provider or managed service partner runs an unpatched gateway, that is your exposure too, and their patching cadence is a reasonable thing to put in a questionnaire.

Where testing fits

Annual penetration testing will not catch a zero-day published in September if the test ran in March. What testing does establish is whether you would notice: whether exploitation of an edge device produces an alert someone acts on, and whether the device is segmented well enough that reaching it does not hand over the network. Both are questions about your detection and architecture rather than about any individual CVE, and both are answerable now rather than at the next disclosure.

Find out what an attacker can reach from your perimeter, before they do.

Explore penetration testing

Common questions

Citrix NetScaler ADC and NetScaler Gateway. CVE-2026-88771 affects all deployments with no feature prerequisite; CVE-2026-88772 affects appliances with DTLS enabled, which is the default for VPN virtual servers. Citrix published fixed builds in bulletin CTX697096 on 27 September 2026.

No. Patching prevents further exploitation but does not remove access an attacker already established. Where a vulnerability was exploited before you patched, treat it as a possible intrusion and hunt for web shells, unexpected accounts, credential theft and configuration changes.

Inventory every internet-facing appliance with its firmware version and a named owner, subscribe to vendor advisories for each, and hold them to a shorter patch window than internal systems. Extend the same questions to suppliers whose gateways provide access to your data.

Sources

  1. Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway — CISA, 27 September 2026
  2. CISA Adds Four Known Exploited Vulnerabilities to Catalog — CISA, 22 September 2026
  3. Citrix NetScaler Zero-Day RCE FAQ: CVE-2026-88771 and CVE-2026-88772 — watchTowr, 27 September 2026
  4. Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation — The Hacker News, 27 September 2026