CISA put two NetScaler RCEs on KEV. Default config is the precondition.
CVE-2026-88771 is unauthenticated command execution on every customer-managed ADC and Gateway. The August 19490 build is still in.
Bottom line up front
CONFIRMED CISA added CVE-2026-88771 and CVE-2026-88772 to the Known Exploited Vulnerabilities catalog on 27 September 2026. Catalog version 2026.09.27 (released 27 September 21:30 UTC, count 1728). Two new rows since [yesterday’s PeopleSoft Daily Top](/posts/2026-09-27-peoplesoft-cve-2026-35273-waf-bypass/), which still saw freeze 2026.09.25 / 1726. Federal due date is 30 September 2026. Ransomware-campaign use is Unknown. Forensic triage is Yes on both rows.
The product is Citrix NetScaler ADC and NetScaler Gateway. The lead bug is unauthenticated arbitrary command execution on every customer-managed deployment, including default configuration. Citrix’s CNA score is 9.5 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H (CWE-20). There is no extra feature to turn off for CVE-2026-88771. Citrix has not published a workaround. The fix is a build.
Do not collapse four facts.
- This is not yesterday’s rumor. [Yesterday’s Daily Top](/posts/2026-09-27-peoplesoft-cve-2026-35273-waf-bypass/) sequenced watchTowr’s 26 September “unpatched NetScaler RCE” note because Citrix was silent and there was no CVE. CTX697096 (created 27 September 15:22, last modified 17:10) and CISA’s same-day KEV add are the material development. The rumor is now a catalog row.
- 88771 and 88772 are not the same precondition. CVE-2026-88771 is all ADC/Gateway deployments. CVE-2026-88772 is a memory overflow (CWE-119, also 9.5) that needs DTLS enabled. Citrix’s own note: DTLS is on by default on VPN virtual servers.
add vpn vserver … SSL …without-dtls OFFmeets the precondition. Turning DTLS off does not close 88771. - The August NetScaler patch does not close this. [CVE-2026-19490](/posts/2026-09-10-cisco-fmc-cve-2026-20079-exploitation/) (KEV due 12 September) fixed in 14.1-73.32 / 13.1-63.21. Those builds sit inside today’s affected ranges. A box that took the SAML/auth-bypass update is still in for 88771/88772 unless it is on 14.1-73.37, 13.1-64.23, or the matching FIPS/NDcPP floor.
- A firmware ISO is not forensic triage. CISA’s dedicated 27 September alert: check for compromise before patching; an update can remove evidence. Citrix’s IoC scan in NetScaler Console (14.1-73.36+, telemetry on) is the vendor’s first-pass tool. Citrix’s own caveat: the IoCs do not cover every TTP; a clean scan is not proof.
This is not a re-run of [PeopleSoft CVE-2026-35273](/posts/2026-09-27-peoplesoft-cve-2026-35273-waf-bypass/). PeopleSoft was an old KEV row with a new WAF bypass. NetScaler is two new KEV rows, zero-day until Sunday, default-config RCE on the perimeter.
| Fact | Record |
|---|---|
| CVE | CVE-2026-88771 (lead); CVE-2026-88772 (second KEV) |
| Product | Citrix NetScaler ADC / NetScaler Gateway (customer-managed) |
| KEV catalog | 2026.09.27, count 1728 |
| Added / due | 27 September / 30 September 2026 |
| Vendor advisory | CTX697096; created 27 September 15:22 |
| Vendor score | CVSS 4.0 9.5 on both KEV CVEs |
| CWE | CWE-20 (88771, Citrix/CVE.org); CWE-119 (88772). KEV JSON lists CWE-119 on both rows — treat the vendor CNA as the technical class for 88771 |
| Exploitation | CONFIRMED as KEV; Citrix: exploits “have been observed”; CISA: “actively exploiting these vulnerabilities globally” |
| Ransomware use | Unknown |
| Named CISA actor | None |
| Workaround | None published for 88771/88772 |
| OT / process impact | None claimed |
What happened
Saturday 26 September, NetScaler administrators reported on Reddit that suppliers, MDR teams, and CERTs were telling them to shut appliances down with no CVE. watchTowr publicly called the information credible and said patches were expected early the following week. A circulating NCSC-NL pre-notification (TLP:AMBER per SecurityWeek; BleepingComputer says NCSC-NL declined to confirm the text to them) is REPORTED, not a primary we can hang the story on.
Sunday 27 September the primary record arrived.
Citrix CTX697096 covers eight CVEs, CVE-2026-88771 through CVE-2026-88778. Two sentences in the bulletin matter more than the table: “Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed.” And: all ADC/Gateway deployments, “including those deployed with the default configuration. No additional features or settings need to be enabled” for 88771.
Affected supported trains:
- NetScaler ADC and Gateway 14.1 before 14.1-73.37
- NetScaler ADC and Gateway 13.1 before 13.1-64.23
- ADC FIPS before 14.1-73.37 FIPS
- ADC FIPS and NDcPP before 13.1-37.279 (the fix list writes the same build as 13.1.37.279 — confirm the filename with Citrix Support before you plan around the hyphen)
Secure Private Access Hybrid deployments that use NetScaler instances are in. The bulletin applies to customer-managed appliances. Citrix says it is upgrading Citrix-managed cloud services and Citrix-managed Adaptive Authentication.
CISA published two products the same day: the two-row KEV add, and a dedicated alert that names all eight CVEs and states CISA has “received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally.” Both KEV rows: due 30 September, ransomware Unknown, forensic triage Yes. Notes point at CTX697096, the community bulletin, CTX694799 (suspected-compromise steps), and BOD 26-04. The 88771 notes block copy-pastes the NVD URL for 88772 — a catalog typo, not a merge of the two bugs.
CERT-EU SA 2026-014 (27 September 17:40 UTC, v1.0) independently restated Citrix’s exploitation confirmation, the same version floors, and “strongly” advised a compromise assessment on any internet-facing affected build. NZ NCSC’s 28 September alert is the same technical table.
The other six CVEs in CTX697096 are not on KEV. They are configuration-gated (HTTP smuggling, URL-expression policy bypass, three more memory overflows, TCP ISN prediction). CVE-2026-88778 is closed by enabling Enhanced ISN Generation, not by the upgrade alone. Do not treat “we took 14.1-73.37” as closing 88778.
RWP is not reproducing request bodies, DTLS packet structure, or shellcode. Citrix published enough version floors, DTLS config strings, and a Console IoC path for a hunt. That is the defensive cut.
Why it matters
NetScaler ADC and Gateway sit on the WAN side of the identity and application path: SSL VPN, ICA/CVPN, AAA, load balancing in front of internal apps. Unauthenticated command execution there is not “a reverse-proxy CVE.” It is code execution on the box that terminates staff remote access and often holds certificates, session state, and a view of what is behind it.
Two operational lies show up in every NetScaler incident, and both are already in this week’s ticket queue.
- “We patched NetScaler in August.” CVE-2026-19490 was real, KEV, and due 12 September. The fixed builds for that bug are below 14.1-73.37 / 13.1-64.23. Patch history is not inventory. watchTowr says the same: appliances patched for 19490 remain vulnerable unless they run one of this bulletin’s floors.
- “We will disable DTLS / lock the management IP.” 88772 is the DTLS bug. 88771 is not. Citrix’s precondition for 88771 is the default configuration. Closing 443 on the management NSIP does not close the VPN or LB virtual server.
CISA’s three-day clock and forensic-triage flag are the federal instruction, not an optional extra. BOD 26-04 wants evidence captured on publicly exposed assets that grant total control post-exploitation before the patch wipes it. Citrix’s Console IoC feature requires 14.1-73.36 or later and an enabled telemetry channel. Teams still on 13.1 cannot use that UI path; Citrix says contact Support for the generic IoCs. Citrix also says those IoCs “might fail to identify actual compromises.”
BleepingComputer, citing Shadowserver dashboards, reports more than 23,000 internet IPs with NetScaler fingerprints (about 22,000 ADC, about 1,500 Gateway). That is a banner census, not a count of unpatched 88771 boxes, not a count of honeypots, and not a victim list. Treat it as exposure scale, not as a campaign size.
No public victim names. No named actor in CISA, Citrix, or CERT-EU. Ransomware field is Unknown. Do not import last year’s NetScaler ransomware history onto this CVE.
Who / what is affected
| Asset | What to assume | Status |
|---|---|---|
| Customer-managed ADC/Gateway 14.1 before 14.1-73.37, 13.1 before 13.1-64.23 | In for CVE-2026-88771 (all deployments) | CONFIRMED vendor / CNA |
Same trains, VPN vServer without -dtls OFF, or any DTLS vServer | Also in for CVE-2026-88772 | CONFIRMED vendor |
| ADC 14.1-FIPS before 14.1-73.37 FIPS; 13.1-FIPS/NDcPP before 13.1-37.279 | In | CONFIRMED vendor |
| Secure Private Access Hybrid using those NetScaler instances | In; upgrade the instance | CONFIRMED vendor |
| Citrix-managed cloud / Adaptive Authentication | Vendor says it is applying updates | CONFIRMED vendor statement; verify with Citrix if you consume the service |
| Builds that closed CVE-2026-19490 (14.1-73.32 / 13.1-63.21) | Still in for 88771/88772 | CONFIRMED by version math against CTX697096 |
| 12.1 and other EoTS trains | Not listed in this bulletin | UNKNOWN; do not treat as safe |
| Management interface firewalled, data-plane VIP on the internet | Still in for 88771 | CONFIRMED vendor (default config, no extra feature) |
| Named victims / named actor | None in CISA, Citrix, CERT-EU | UNKNOWN |
| OT / ICS / process | Not claimed. A NetScaler in front of an industrial remote-access path is still an IT perimeter compromise until evidence says otherwise | No evidence |
| CISA ransomware field | Unknown | CONFIRMED catalog |
The DTLS check Citrix published is configuration, not a PoC:
add vpn vserver … SSL …with no-dtls OFF→ DTLS on (default) → 88772 precondition metadd vpn vserver … SSL … -dtls OFF→ 88772 precondition not met; 88771 still inadd vpn vserver … DTLS …oradd lb vserver … DTLS …→ 88772 precondition met
Technical context
RWP is not reproducing packets, heap offsets, or command strings.
What the primary record actually says:
- CVE-2026-88771 — CWE-20 improper input validation. Unauthenticated attacker executes arbitrary commands. Precondition: none beyond an affected build. CVSS 4.0 9.5 with
AT:P(Attacker Required Present in the v4 string Citrix published). NVD has no 3.x score yet. - CVE-2026-88772 — CWE-119 buffer restriction. RCE or denial of service. Precondition: DTLS enabled; default-on for VPN vServers. Same 9.5. Citrix vector uses
AC:H. - Same bulletin, not KEV: 88773 HTTP request smuggling (CWE-444, 9.3); 88774 URL-expression policy bypass (CWE-16, 7.0) — Citrix says this class was already addressed from 14.1-72.x and is URL-normalization related; 88775/88776/88777 additional CWE-119 overflows (8.8) on Gateway/AAA, Oracle LB, and non-HTTP L7; 88778 TCP ISN prediction (CWE-342, 8.8) if Enhanced ISN Generation is disabled.
Citrix credits Michael Tucker, Chew Keong Tan and Alex Bernier of the JPMorgan Chase XOR Team, and Maxim Suhanov. That is coordinated disclosure credit, not attribution of the in-the-wild exploits.
CISA KEV JSON lists CWE-119 on the 88771 row. Citrix and CVE.org list CWE-20. Use the CNA for the bug class; use KEV for the clock and the forensic-triage flag.
watchTowr (28 September update) reports a 13.1 upgrade foot-gun: run show ns variable first; if it returns any variables, install 13.1-64.24 rather than 64.23 to avoid a known reboot loop. That instruction is not in CTX697096 as we retrieved it. Treat it as REPORTED by watchTowr. Confirm with Citrix Support before you pick 64.24 over 64.23.
ATT&CK mapping for defenders, not a kill chain we observed:
| Technique | ID | Why it is on the ticket |
|---|---|---|
| Exploit Public-Facing Application | T1190 | Unauthenticated RCE on internet ADC/Gateway |
| Command and Scripting Interpreter | T1059 | 88771 is arbitrary command execution |
| Unsecured Credentials | T1552 | Post-compromise: keys, certs, and secrets on the appliance |
| Valid Accounts | T1078 | Session/VPN identity store after the box is owned |
Threat / exploitation status
| Claim | Status | Source |
|---|---|---|
| Exploits of 88771 and 88772 observed on unmitigated deployments | CONFIRMED | Citrix CTX697096 |
| Active exploitation globally | CONFIRMED as CISA statement | CISA 27 Sep dedicated alert (“reports and partner threat intelligence”) |
| Both CVEs on KEV, due 30 Sep, forensic triage Yes, ransomware Unknown | CONFIRMED | Catalog 2026.09.27, count 1728 |
| Zero-day until 27 Sep bulletin | ASSESSED high confidence | No public CVE/patch before CTX697096; watchTowr 26 Sep warning |
| NCSC-NL private pre-notification; Citrix found the bugs in customer-incident investigation; CRA filing | REPORTED | Circulating notice via BleepingComputer / SecurityWeek; NCSC-NL declined to confirm the text to BC |
| Named threat actor | UNKNOWN | None in Citrix, CISA, CERT-EU |
| Ransomware use of these two CVEs | UNKNOWN | KEV field Unknown |
| ~23k internet NetScaler fingerprints | REPORTED | BleepingComputer citing Shadowserver; not a vulnerable-version census |
| Public exploit / PoC | UNKNOWN in the primary record we retrieved | RWP is not hunting one |
Confidence on the KEV fact and the default-config RCE: high. Confidence on campaign size, actor, and ransomware: low — the public record does not support those claims yet.
What defenders should do
- Inventory every customer-managed NetScaler ADC and Gateway, including HA pairs, FIPS, NDcPP, and Secure Private Access Hybrid instances. Record current build. Anything below 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, or 13.1-37.279 FIPS/NDcPP is in for 88771. Do not skip boxes that already took the August 19490 build.
- Preserve evidence first on internet-facing appliances. Support bundle, logs, snapshot, core dump. CISA: an update can destroy forensic visibility. Then run Citrix’s IoC path (NetScaler Console Security Advisory, 14.1-73.36+, telemetry enabled) or ask Support for the generic IoCs. A clean result is not clearance. If compromise is suspected, CTX694799: isolate, revoke, hunt systems the ADC talked to, rebuild, rotate local passwords and KEK, replace restored SSL certificates.
- Install the fixed build. There is no published workaround for 88771/88772. On 13.1, confirm the target build with Citrix if
show ns variableis non-empty (watchTowr: 13.1-64.24). After upgrade, enable Enhanced ISN Generation to close 88778. - Hunt past the appliance. A NetScaler that ran attacker commands is a beachhead. Session replay, new admin accounts, cert issuance, and lateral movement off the SNIP/VIP path are the rest of the ticket. Rotate secrets the box held.
- Keep the management plane off the internet. That does not close 88771. It does stop the next management-plane KEV from stacking on this one.
- Sequence the rest of this window. Due today, 28 September: [SharePoint CVE-2026-65660](/posts/2026-09-26-sharepoint-cve-2026-65660-kev/), WordPress CVE-2026-87902, MikroTik CVE-2026-67279. Due 30 September: these two NetScaler CVEs. [WSO2 CVE-2026-5430](/posts/2026-09-25-wso2-cve-2026-5430-kev/) and Adobe CVE-2026-71362 were due yesterday. Internet-facing NetScaler is today’s interrupt; those clocks do not pause.
RWP assessment
Score 9.0.
Highest-leverage development since yesterday’s PeopleSoft WAF-bypass piece is a new KEV pair for unauthenticated RCE on the default NetScaler configuration, with vendor-confirmed in-the-wild use, a CISA global-exploitation alert, a three-day federal clock, and forensic triage Yes. Evidence quality is high: Citrix bulletin, CISA JSON, CISA dedicated alert, CERT-EU, NVD/CVE.org.
It outranks a second day on PeopleSoft CVE-2026-35273 because yesterday already shipped Mandiant’s encoded-path campaign; there is no new freeze on that CVE. It outranks SharePoint CVE-2026-65660, WordPress CVE-2026-87902, and MikroTik CVE-2026-67279 (all due today) because those are clocks on stories already assessed 24–26 September. It outranks the six non-KEV CVEs in the same Citrix bulletin because CISA did not put them on the catalog. It outranks Cloudflare’s Containers/Sandboxes residual-data fix (27 September) because that is a cloud-tenant isolation story, not an internet-edge RCE with a Wednesday due date.
What we are not saying: that ransomware is using 88771 (Unknown); that a named APT owns this (no one has claimed it in the primary record); that pulling DTLS is a fix for the lead CVE; that Citrix-managed cloud tenants must patch themselves (vendor says it is rolling the update); that a NetScaler in an industrial DMZ is confirmed OT impact.
What we are watching
- Whether CISA or Citrix names an actor, a ransomware affiliate, or a victim sector.
- Whether the KEV ransomware field flips from Unknown.
- Whether 88773–88778 pick up exploitation and join the catalog.
- Citrix clarification on the 13.1-37.279 / 13.1.37.279 filename and on 13.1-64.24 versus 64.23.
- Console IoC coverage expanding beyond “generic,” and whether independent hunters publish hashes Citrix will stand behind.
- SharePoint 65660 / WordPress 87902 / MikroTik 67279 due-today outcomes — clocks, not this story.
Sources
- CISA — Adds two known exploited vulnerabilities (27 September 2026)
- CISA — Critical zero-day vulnerabilities exploited in Citrix NetScaler ADC, Gateway
- CISA — KEV JSON catalog
2026.09.27 - CISA — Known Exploited Vulnerabilities Catalog
- CISA — BOD 26-04
- Citrix CTX697096 — NetScaler ADC and Gateway security bulletin
- Citrix Community — bulletin for CVE-2026-88771 through CVE-2026-88778
- Citrix CTX694799 — steps if NetScaler ADC is suspected compromised
- CVE-2026-88771 · NVD
- CVE-2026-88772 · NVD
- CERT-EU SA 2026-014
- NZ NCSC — multiple Citrix NetScaler vulnerabilities
- BleepingComputer — Citrix confirms two NetScaler RCE zero-days
- BleepingComputer — CISA orders feds to patch by Wednesday
- The Hacker News — CISA says attackers exploiting two Citrix flaws globally
- SecurityWeek — Citrix confirms 2 NetScaler zero-days
- watchTowr — CVE-2026-88771 / 88772
Sources
- CISA — Adds two KEV CVE-2026-88771 CVE-2026-88772
- CISA — Critical zero-day vulnerabilities exploited in Citrix NetScaler ADC, Gateway
- CISA — KEV JSON feed catalog 2026.09.27
- CISA — Known Exploited Vulnerabilities Catalog
- CISA — BOD 26-04
- Citrix — CTX697096 NetScaler CVE-2026-88771 through CVE-2026-88778
- Citrix — Community bulletin CVE-2026-88771 through CVE-2026-88778
- Citrix — CTX694799 steps if NetScaler ADC is suspected compromised
- CVE — CVE-2026-88771
- CVE — CVE-2026-88772
- NVD — CVE-2026-88771
- NVD — CVE-2026-88772
- CERT-EU — Security Advisory 2026-014
- NZ NCSC — Multiple vulnerabilities affecting Citrix NetScaler
- BleepingComputer — Citrix confirms two NetScaler RCE zero-days
- BleepingComputer — CISA orders feds to patch exploited Citrix flaws by Wednesday
- The Hacker News — CISA says attackers exploiting two critical Citrix NetScaler flaws
- SecurityWeek — Citrix confirms 2 NetScaler zero-days
- watchTowr — CVE-2026-88771 NetScaler RCE