Citrix patches eight NetScaler flaws as two zero-days are exploited
CISA has given US federal agencies until 30 September to act and the National Cyber Security Centre is telling UK defenders to isolate affected appliances, while some IT suppliers told customers to pull the plug
- Citrix released fixes for eight NetScaler ADC and Gateway CVEs, CVE-2026-88771 to CVE-2026-88778, on 27 September.
- The two exploited flaws each score 9.5 on CVSS v4; the other six range from 7.0 to 9.3.
- CISA added both exploited flaws to its KEV catalog on 27 September with a 30 September due date for federal agencies.
- Palo Alto Networks’ Cortex Xpanse counted more than 50,277 exposed instances potentially vulnerable to the two CVEs as of 27 September, its Unit 42 threat brief says.
For MSPs and managed security service providers (MSSPs) with NetScaler in a customer estate this is a forensic job before it is a patch job: CISA and the NCSC both say check for compromise first, and that is incident-response work most managed-service contracts price separately or not at all. Partners that phoned customers before the bulletin have banked trust a patch cycle never earns; those who learned of it from the news will be asked why. Expect NetScaler Console licenses and hardware refreshes to sell off the back of this, and public-sector buyers to ask at renewal who is accountable for the edge appliance between patches.
“CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally.”Cybersecurity and Infrastructure Security Agency, alert, US Cybersecurity and Infrastructure Security Agency
Citrix confirmed on 27 September that two critical flaws in NetScaler ADC and NetScaler Gateway, CVE-2026-88771 and CVE-2026-88772, are being exploited as zero-days, and released fixes for them and six further vulnerabilities in one bulletin. Both score 9.5 on the Common Vulnerability Scoring System (CVSS) v4. The first lets an unauthenticated attacker run commands against a default configuration; the second is a memory overflow that needs Datagram Transport Layer Security (DTLS) switched on, which it is by default on VPN virtual servers.
The US Cybersecurity and Infrastructure Security Agency (CISA) added both to its Known Exploited Vulnerabilities (KEV) catalog the same day and gave federal agencies until 30 September to apply the vendor’s mitigations and carry out forensic triage. Its alert says to look for signs of compromise before patching, because an update can wipe the forensic trail.
Isolate first, patch second
The National Cyber Security Centre (NCSC) published its own alert on 28 September and is still assessing the impact on UK organizations. Its priority list puts patching fifth: identify affected systems, isolate them and where possible replace them with a new, fully updated build, hunt for compromise and report anything found, then update. The fixed builds are 14.1-73.37 and 13.1-64.23.
Administrators posting on Reddit, as reported by BleepingComputer, said IT suppliers, CERTs and national cyber agencies had contacted them before disclosure, in at least one case with advice to shut NetScalers down immediately. As reported by The Stack, Citrix’s guidance for any appliance suspected of compromise is to change every service account password and secret stored on it.
