(TLP:CLEAR) Vulnerability Notification – Citrix NetScaler Zero-Days Actively Exploited
Created: Monday, September 28, 2026 - 14:05
Categories: Cybersecurity, Federal & State Resources, Security Preparedness
ACTION MAY BE REQUIRED for utilities using customer-managed Citrix NetScaler ADC or NetScaler Gateway appliances, including Secure Private Access Hybrid deployments that rely on NetScaler instances. Utilities that outsource technology support may need to consult their service providers for assistance with remediation actions.
Summary: Two critical remote code execution vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway are being actively exploited in the wild. They are tracked as CVE-2026-88771 (CVSS v4 9.5) and CVE-2026-88772 (CVSS v4 9.5), attackers have exploited both as zero days. CVE-2026-88771 allows an unauthenticated attacker to execute arbitrary commands. It affects all NetScaler deployments, including those running the default configuration. CVE-2026-88772 is a memory overflow that can lead to remote code execution or denial of service on appliances with DTLS enabled, which is the default on NetScaler Gateway VPN virtual servers.
CISA has added both vulnerabilities to its Known Exploited Vulnerabilities Catalog and reports that threat actors are actively exploiting them globally. CISA also notes that updating NetScaler appliances can be complex and may require downtime. Citrix’s bulletin addresses six additional high- and critical-severity NetScaler vulnerabilities (CVE-2026-88773 through CVE-2026-88778).
Analyst Note: NetScaler appliances sit at the network edge. They often provide VPN, remote access, and authentication services for staff, contractors, and critical support systems. Successful exploitation could give attackers a foothold inside trusted network environments, potentially enabling lateral movement, credential theft, or access to systems supporting OT environments.
Citrix is updating Citrix-managed cloud services and Citrix-managed Adaptive Authentication directly.
WaterISAC strongly encourages members to review Citrix’s advisory and the CISA alert, and to take the following actions:
- Where possible, check for indications of compromise before patching, using the indicators of compromise (IOCs) Citrix provides through NetScaler Console and its related blog post. Citrix notes that IOC scanning alone may not detect every compromise.
- If compromise is suspected, preserve forensic evidence before applying updates, as updating may result in loss of forensic visibility. Then follow Citrix’s Steps to Take if NetScaler ADC is Suspected to be Compromised.
- Upgrade affected appliances immediately to the following fixed versions or later:
- NetScaler ADC and NetScaler Gateway 14.1-73.37
- NetScaler ADC and NetScaler Gateway 13.1-64.23
- NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS
- NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279
- Apply the TCP configuration change for CVE-2026-88778, which the upgrade alone does not address.
Additional Reading
