If you have a Citrix NetScaler ADC or NetScaler Gateway on your perimeter, this is a patch-today situation. Over the weekend the story moved from “two unpatched zero-days being exploited before any fix existed” to “CISA confirms global exploitation, CVEs assigned, added to the catalog, patches out.” Both flaws are unauthenticated remote code execution on a device that by definition faces the internet and sits in front of your entire internal network.

How this unfolded
On September 26, the firm watchTowr reported that during forensic investigations it had found two unpatched RCE vulnerabilities in NetScaler, both already being exploited in the wild, both with no patch at the time. That is the classic zero-day pattern: the hole is in use before a fix exists.
A day later it closed out officially. CISA confirmed that threat actors are actively exploiting these vulnerabilities globally, assigned CVE numbers, and on September 27 added both to its Known Exploited Vulnerabilities catalog. US federal civilian agencies were ordered to apply the fixes by September 30. CISA sets a deadline like that only for things being hit right now.
The two flaws
Both are rated CVSS 9.5, the top of the scale:

- CVE-2026-88771 (9.5): improper input validation, lets an unauthenticated attacker execute arbitrary commands. Affects all NetScaler ADC and NetScaler Gateway deployments.
- CVE-2026-88772 (9.5): improper memory buffer restriction, leads to remote code execution or denial of service. Requires DTLS configuration enabled, which is the default on VPN virtual servers.
Note the word “unauthenticated” in the first one. The attacker needs no account, no session, no prior access. Network reachability of the device is enough. The second hits exactly the configuration most deployments run by default when NetScaler is used as a VPN gateway, and that is how it is used almost everywhere.
Fixed versions
Update to at least these builds on the line you run:
- NetScaler ADC/Gateway 14.1-73.37 and later
- NetScaler ADC/Gateway 13.1-64.23 and later
- NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later
- NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.279 and later
A separate note on 13.1: it reached End of Maintenance on September 15, just a couple of weeks before all this. If you are on 13.1, confirm you are pulling the fixed build specifically, and keep in mind that this line will not get updates going forward. That is a reason to plan a migration, not just a one-off patch. If your infrastructure is managed by someone else, this is exactly the kind of detail server management done properly is supposed to catch before it becomes a deadline.
Why the patch is only half the job
This is the part that matters most on NetScaler-class devices. Installing the patch closes the hole going forward, but it does not answer whether someone already got in. If an attacker gained access before you updated, they could have persisted in a way the patch does not evict: stolen keys, added accounts, a web shell on the appliance itself. Both flaws were exploited before the fix shipped, and the first wave was found during forensic investigations in the first place. That means for some devices the patch arrives after the compromise.
So on any NetScaler that sat exposed on a vulnerable version, it is reasonable to assume possible compromise and work through the steps Citrix itself recommends:
- Preserve evidence before you touch anything: VPX snapshots, logs, technical support bundles, core dumps. Without them there is nothing to investigate later.
- Isolate the device from the network while you check it.
- Change service account passwords, revoke and reissue certificates and keys, replace SSL certificates. If the device was reachable, treat everything on it as compromised.
- Check the systems NetScaler had access to, not just the gateway itself. A perimeter foothold is rarely the final target.
- Rebuild the device on updated firmware rather than trying to clean it in place if there are any signs of access. If you need that confirmed rather than assumed, that’s exactly what our emergency compromise response team checks for.
- The NetScaler management interface should never face the public internet. If it was exposed, that is the first thing to close.
The takeaway
In a single day these two flaws went from an anonymous post on X to a CISA catalog entry with a federal deadline, and that pace is one to get used to: the gap from disclosure to confirmed mass exploitation is now hours, not weeks. NetScaler is a high-value target precisely because it sits at the boundary and holds the way into the internal network, and both flaws give unauthenticated RCE at that boundary. Update to a fixed build immediately, and on any device that was exposed on a vulnerable version, do not stop at the patch: check whether someone already got in. If you would rather have an outside team confirm your perimeter appliances are actually patched and clean, that is what our penetration testing and managed security hardening services are for.
