“Exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments has been observed,” Citrix said in a blog post on 27 September.
The two urgent zero-days: CVE-2026-88771 and CVE-2026-88772
Citrix published updates on 27 September for eight vulnerabilities in Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway). The vendor identified two critical zero-day flaws that had been observed in active exploitation.
CVE-2026-88771 is described as a remote code execution (RCE) flaw caused by improper input validation that allows an unauthenticated attacker to execute arbitrary commands. Citrix said it affects “all NetScaler ADC and NetScaler Gateway deployments with default configuration.”
CVE-2026-88772 is a memory‑overflow vulnerability that can lead to remote code execution or denial of service; it affects any deployment with DTLS configuration enabled. Citrix notes DTLS is enabled by default on VPN vServers. Citrix strongly urged affected customers “to install the relevant updated versions as soon as possible.”
HTTP request smuggling and the remaining five CVEs
Also flagged as critical was CVE-2026-88773, an HTTP request smuggling flaw present when the HTTP configuration is enabled on NetScaler ADC or NetScaler Gateway; Citrix assigned it a CVSS score of 9.3. Overall, the eight new CVEs reported by Citrix carry CVSS scores ranging from 7 to 9.5.
Citrix’s bulletin lists the five other vulnerabilities as:
- CVE-2026-88774: a feature policy bypass due to improper HTTP URL based expression usage (CVSS 7)
- CVE-2026-88775: a memory overflow vulnerability leading to unpredictable or erroneous behavior or denial of service (CVSS 8.8)
- CVE-2026-88776: a memory overflow vulnerability leading to unpredictable or erroneous behavior or denial of service (CVSS 8.8)
- CVE-2026-88777: a memory overflow vulnerability leading to unpredictable or erroneous behavior or denial of service (CVSS 8.8)
- CVE-2026-88778: a TCP Initial Sequence Number (ISN) prediction flaw (CVSS 8.8)

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleObserved exploitation and international alerts: ACSC, CISA, and NCSC-NL
Reports of exploitation of the zero-day bugs circulated before Citrix’s bulletin. On 28 September the Australian Signals Directorate’s Australian Cyber Security Centre (ACSC) issued a critical alert urging organizations to patch. Reports also suggested the Dutch National Cyber Security Center (NCSC-NL) had issued alerts to local organizations.
In the United States, the Cybersecurity and Infrastructure Security Agency (CISA) ordered federal agencies to apply the patches by Wednesday, 30 September. Citrix confirmed that exploitation of the two most urgent CVEs had been observed on unmitigated deployments.
Customer‑managed deployments versus Citrix‑managed services
Citrix made a specific scope statement: “This bulletin only applies to customer-managed Citrix NetScaler ADC and Citrix NetScaler Gateway.” The vendor also said that Cloud Software Group upgrades the Citrix‑managed cloud services and Citrix‑managed Adaptive Authentication with the necessary software updates, indicating a distinction in who must act.
How technologists, federal agencies, and Citrix‑managed cloud customers are likely to respond
- Technologists and security teams: teams running customer‑managed NetScaler ADC or NetScaler Gateway will be under immediate pressure to install the “relevant updated versions” Citrix released, and to confirm whether default configurations (including DTLS on VPN vServers and HTTP configuration) expose their installations to CVE-2026-88771, CVE-2026-88772, or CVE-2026-88773.
- Federal agencies: CISA’s directive sets a near-term compliance deadline—patches must be applied by 30 September—creating an operational sprint for federal IT and security operations to inventory NetScaler instances and deploy Citrix’s updates.
- Citrix‑managed cloud customers: according to Citrix, Cloud Software Group will upgrade Citrix‑managed cloud services and Citrix‑managed Adaptive Authentication with the fixes, shifting the immediate remediation burden away from customers whose services are Citrix‑managed.
Two further facts complicate the context: Citrix confirmed exploitation has been observed, and reporting in the source material notes that in 2025 a cyber intrusion linked to a China‑based group called Salt Typhoon targeted a Citrix zero day. The current bulletins and international alerts make clear the clock is short for organizations that run customer‑managed NetScaler appliances.
Link to original story: https://www.infosecurity-magazine.com/news/citrix-patches-critical-zero-days/




