Security Intelligence
Loading table of contents...
September 28, 2026 | Security intelligence
At a glance:
Citrix disclosed eight NetScaler vulnerabilities on September 27, 2026, including two actively exploited flaws that were added to the CISA KEV catalogue.
On September 27, 2026, Citrix disclosed eight vulnerabilities affecting NetScaler ADC and NetScaler Gateway, two of which had already been exploited before patches became available. The same day, CISA added both vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalogue after receiving reports of active exploitation.
NetScaler ADC and NetScaler Gateway commonly sit at the edge of enterprise networks, where they provide application delivery, load balancing, authentication, remote access, and VPN services. Because they process inbound connections before traffic reaches internal applications, they are frequently exposed directly to the internet and often hold a trusted position within enterprise environments.
The two actively exploited vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, each received a CVSS v4 score of 9.5.
CVE-2026-88771 is described as an improper input validation vulnerability. Input validation is intended to verify that information received from a remote user contains only expected values before it is processed by the appliance. The vulnerability allows a remote unauthenticated threat actor to execute arbitrary commands on affected systems.
Citrix identified all vulnerable NetScaler ADC and NetScaler Gateway deployments to be affected, including systems running the default configuration. Exploitation is remote, does not require authentication, and does not require user interaction.
CVE-2026-88772 is described as a memory overflow vulnerability affecting DTLS processing. DTLS is used to improve VPN communications by allowing encrypted traffic over connectionless network protocols. The flaw could lead to remote code execution or denial of service.
Exposure depends on DTLS being enabled on the appliance. This configuration is common on NetScaler Gateway deployments because DTLS is enabled by default on VPN virtual servers. Exploitation is remote and does not require authentication or user interaction.
Warnings about active exploitation emerged on September 26, 2026, before patches became publicly available, demonstrating that threat actors possessed working exploits before disclosure.
Citrix has released indicators of compromise (IOCs) to help administrators quickly identify NetScaler appliances that may show signs of malicious activity associated with the vulnerabilities.
Organizations using NetScaler Console can run IOC scans directly from the Security Advisory workflow. Citrix notes that IOC results alone do not confirm or rule out a compromise because threat actors may use techniques that are not covered by the published indicators.
NetScaler appliances have a long history of attracting threat actor attention because they are commonly exposed to the internet and often sit between remote users and internal business systems.
Previous NetScaler vulnerabilities, including CitrixBleed, were actively exploited to gain initial access to enterprise networks, steal session information, bypass authentication, and support follow-on intrusion activity. Many threat actors already have a good understanding of NetScaler environments and actively monitor for newly disclosed vulnerabilities affecting the platform.
From an exploitation perspective, CVE-2026-88771 is the more concerning of the two vulnerabilities as the attack complexity is low, suggesting few environmental prerequisites beyond a reachable vulnerable appliance. CVE-2026-88772 requires DTLS to be enabled and relies on a memory corruption condition that may lead to remote code execution or denial of service, making exposure more dependent on deployment configuration.
A successful attack could allow full control of the NetScaler appliance, placing a threat actor on a trusted system that handles VPN connections, user authentication, application delivery, and traffic flowing between external users and internal resources. The value of that position often extends beyond the appliance because it can provide visibility into authentication activity, user sessions, and access paths into business applications.
The downstream impact depends on how the appliance is deployed. In some environments, compromise may be limited to the appliance itself. In others, the appliance serves as the entry point for remote employees, contractors, and administrators connecting to internal systems.
A threat actor that gains control of such a device could potentially use that access to target authentication infrastructure, move toward sensitive business applications, collect credentials, establish persistence, or support ransomware and data theft operations. These outcomes have not been reported in the current activity but represent realistic follow-on risks because of the role NetScaler commonly plays within enterprise environments.
The most significant concern is that exploitation occurred before disclosure and patch availability. Organizations may already have been exposed before defenders were aware of the vulnerabilities or had an opportunity to deploy updates.
Review the Citrix security bulletin and apply the appropriate updates for affected NetScaler ADC and NetScaler Gateway deployments. Citrix has published fixed versions, indicators of compromise, compromise assessment guidance, and product-specific remediation instructions for supported release branches.
Prioritize internet-facing appliances that provide VPN, remote access, authentication, or application delivery services. Because exploitation occurred before public disclosure and patch availability, patching alone may not determine whether a device was accessed during the vulnerable period. Review available logs, administrative activity, authentication records, and other forensic evidence for signs of unauthorized access.
Forward NetScaler logs to a centralized logging or security information and event management platform if this is not already in place. Preserving logs outside the appliance improves visibility into authentication events, administrative activity, and post-compromise behavior while supporting incident response and forensic investigations. Citrix also recommends enabling file integrity monitoring capabilities available through NetScaler Console to help identify unauthorized changes to monitored files.
Review the role of each NetScaler deployment within the environment and identify the business services, authentication systems, and internal applications accessible through the appliance. Internet-facing appliances frequently act as gateways to trusted resources, making them a high-priority asset during compromise assessments. Where unauthorized access is identified, incident response activities can extend beyond the appliance to include credentials, certificates, sessions, and systems that may have been accessible from the compromised device.
Sign up to receive a weekly roundup of our security intelligence feed. You'll be the first to know of emerging attack vectors, threats, and vulnerabilities.

