Citrix NetScaler Zero Day Vulnerabilities – Patch Now

Mike Dent

Field CTO - Hybrid Data Center

Attackers are already taking advantage of these vulnerabilities. Use this guide to assess risk, patch affected systems, and verify appliance integrity.


The Short Version 

If you run Citrix NetScaler ADC or NetScaler Gateway in any form, physical appliance or virtual instance, upgrade today and check your appliances for signs of compromise. On September 27, 2026, Citrix published security bulletin CTX697096 covering eight vulnerabilities in customer-managed NetScaler appliances. The same day, CISA added the two most serious, CVE-2026-88771 and CVE-2026-88772, to its Known Exploited Vulnerabilities (KEV) catalog and confirmed that attackers are exploiting them globally. 

NetScaler sits at the edge of the network, handling remote access, load balancing and authentication. That makes it one of the most valuable targets an attacker can reach from the internet. We’ve seen this pattern before with NetScaler, and the organizations that moved fastest came out in the best shape. 


What’s Affected 

Two of the eight vulnerabilities allow unauthenticated remote code execution and are under active attack. The other six depend on specific configurations but are still rated high to critical. 

CVE Impact Applies When CVSS v4 
CVE-2026-88771 Unauthenticated remote code execution (actively exploited) All deployments, including default configuration 9.5 
CVE-2026-88772 Memory overflow leading to remote code execution or denial of service (actively exploited) DTLS enabled, which is the default on Gateway/VPN virtual servers 9.5 
CVE-2026-88773 HTTP request smuggling HTTP or SSL virtual servers configured 9.3 
CVE-2026-88774 Feature policy bypass Policies using HTTP URL-based expressions 7.0 
CVE-2026-88775 Memory overflow leading to denial of service Configured as a Gateway or AAA virtual server 8.8 
CVE-2026-88776 Memory overflow leading to denial of service Oracle-type load balancing virtual server 8.8 
CVE-2026-88777 Memory overflow leading to denial of service LB/CS or CGNAT/NAT64 with non-HTTP L7 features such as FTP, RTSP or DNS64 8.8 
CVE-2026-88778 TCP initial sequence number prediction TCP virtual servers with Enhanced ISN Generation disabled 8.8 

These supported builds are vulnerable: 

  • NetScaler ADC and Gateway 14.1 before 14.1-73.37 
  • NetScaler ADC and Gateway 13.1 before 13.1-64.23 
  • NetScaler ADC 14.1-FIPS before 14.1-73.37 FIPS 
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP before 13.1-37.279 

Secure Private Access hybrid deployments that use NetScaler instances are affected too. Citrix-managed cloud services and Citrix-managed Adaptive Authentication are being updated by Citrix. 


Physical & Virtual Deployments Are Both Affected

These vulnerabilities live in the NetScaler firmware, so exposure depends on the build you’re running, not the form factor. If a NetScaler instance runs an affected build, it’s vulnerable, whether it’s a hardware appliance or a virtual machine. 

Form Factor Deployment What To Patch 
MPX Physical hardware appliance The appliance firmware 
SDX Physical appliance hosting multiple instances Every VPX instance running on the SDX; upgrade each one individually 
VPX Virtual appliance on VMware ESXi, Nutanix AHV, Hyper-V, KVM, or in AWS, Azure or Google Cloud Each VPX instance, including HA peers and DR copies 
CPX Containerized NetScaler Container images, redeployed on a fixed build 
BLX NetScaler on bare-metal Linux The BLX package 

Virtual instances are the ones most likely to be missed. Test, lab and DR instances, cloud marketplace deployments, and VPX instances spun up for a single project often sit outside normal patch cycles. Build a complete inventory before you call this done. 


Why This One Deserves Urgency

Three things set this disclosure apart from a routine patch cycle. 

  • No special configuration required. Many critical CVEs only matter if a particular feature is turned on. CVE-2026-88771 affects every NetScaler ADC and Gateway deployment, including a default configuration, and requires no credentials or user interaction. 
  • Exploitation started before disclosure. Security researchers reported attacks in the wild for weeks before Citrix published fixes. An unpatched, internet-facing appliance may already be compromised, so patching alone may not be enough. 
  • Recent patching doesn’t cover you. Appliances updated for the earlier NetScaler vulnerability, CVE-2026-19490, are still exposed unless they run one of the fixed builds listed above. 

CISA has given U.S. federal civilian agencies until September 30, 2026 to remediate. That’s a reasonable deadline for everyone else as well. 


What To Do Now

  1. Upgrade to a fixed build. Move to 14.1-73.37 or 13.1-64.23 or later, or the matching FIPS/NDcPP release. This applies to MPX and SDX hardware, VPX instances on-premises and in the cloud, and CPX and BLX deployments alike. Upgrade HA pairs one node at a time so you keep remote access up during the window. If you’re on a release outside the supported versions above, plan the move to a supported release now. 
  1. Enable Enhanced ISN Generation. The upgrade alone does not close CVE-2026-88778. Check the current setting with show ns tcpparam | grep “Enhanced ISN Generation”, and if it returns DISABLED, apply the TCP configuration change in Citrix’s documentation. 
  1. Check for compromise. Treat any unpatched NetScaler that was internet-facing this month as potentially compromised. Run Citrix’s indicator-of-compromise checks and follow CTX694799, Citrix’s guidance for suspected compromise. A clean IOC result is not proof of a clean appliance, so also review for unexpected files, configuration changes, new accounts and unusual authentication activity. Before you patch, preserve evidence: take VM snapshots of VPX instances and collect technical support bundles from physical appliances. If you find signs of compromise, follow CTX694799 for recovery, which generally means rebuilding rather than cleaning: redeploying fresh VPX instances, or reimaging MPX appliances, and restoring from a known-good backup. 
  1. Reduce exposure if you can’t patch immediately. Limit internet reachability to the appliance where possible and prioritize a maintenance window as soon as you can get one. 
  1. Confirm your DTLS and feature exposure. Review your configuration against the preconditions in CTX697096 so you know which of the eight CVEs actually applied to you. That context matters for the compromise review. 

How eGroup Can Help

Our team can take this off your plate or work alongside yours. We can confirm your current builds and exposure, plan and execute upgrades across standalone and HA deployments, apply the TCP configuration change, and help with a compromise assessment if anything looks off. Reach out to us and we’ll get you scheduled. 


Team of IT Technicians Collaborating in Office

Ensure Ongoing Performance & Reliability Of Your Virtual Environments

Ensure that your IT environment remains secure, updated, and optimized for business continuity. Our experts can provide proactive monitoring, patch management, and infrastructure health checks for workstations, servers, domain controllers, SQL environments, and more. 

Sources
Get in Touch with Us

Connect with an expert to learn what we can do for your business.

One More Step!

Your Win Wires registration is complete. Request Microsoft access to open the customer documents.

Access may take a few minutes to activate.
After completing the Microsoft access request, there may be a short delay before you can open Win Wire files.

Use the same work email you registered with. Microsoft access is only requested once, unless it expires or is revoked.

Get Access to Win Wires

Enter your name and work email to set up your Win Wires account.

Next, you’ll request access to the Win Wires documents through Microsoft. You’ll only need to complete registration once.

October 21, 2026 • Cloud, AI, and Security Virtual Workshop • 1–5 PM ET