Daily Top · Vulnerabilities / Edge

CISA put two NetScaler RCEs on KEV. Default config is the precondition.

CVE-2026-88771 is unauthenticated command execution on every customer-managed ADC and Gateway. The August 19490 build is still in.

RWP Ventures · 2026-09-28 · event 2026-09-27 · 15 min read · priority 9.0

Bottom line up front

CONFIRMED CISA added CVE-2026-88771 and CVE-2026-88772 to the Known Exploited Vulnerabilities catalog on 27 September 2026. Catalog version 2026.09.27 (released 27 September 21:30 UTC, count 1728). Two new rows since [yesterday’s PeopleSoft Daily Top](/posts/2026-09-27-peoplesoft-cve-2026-35273-waf-bypass/), which still saw freeze 2026.09.25 / 1726. Federal due date is 30 September 2026. Ransomware-campaign use is Unknown. Forensic triage is Yes on both rows.

The product is Citrix NetScaler ADC and NetScaler Gateway. The lead bug is unauthenticated arbitrary command execution on every customer-managed deployment, including default configuration. Citrix’s CNA score is 9.5 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H (CWE-20). There is no extra feature to turn off for CVE-2026-88771. Citrix has not published a workaround. The fix is a build.

Do not collapse four facts.

  1. This is not yesterday’s rumor. [Yesterday’s Daily Top](/posts/2026-09-27-peoplesoft-cve-2026-35273-waf-bypass/) sequenced watchTowr’s 26 September “unpatched NetScaler RCE” note because Citrix was silent and there was no CVE. CTX697096 (created 27 September 15:22, last modified 17:10) and CISA’s same-day KEV add are the material development. The rumor is now a catalog row.
  2. 88771 and 88772 are not the same precondition. CVE-2026-88771 is all ADC/Gateway deployments. CVE-2026-88772 is a memory overflow (CWE-119, also 9.5) that needs DTLS enabled. Citrix’s own note: DTLS is on by default on VPN virtual servers. add vpn vserver … SSL … without -dtls OFF meets the precondition. Turning DTLS off does not close 88771.
  3. The August NetScaler patch does not close this. [CVE-2026-19490](/posts/2026-09-10-cisco-fmc-cve-2026-20079-exploitation/) (KEV due 12 September) fixed in 14.1-73.32 / 13.1-63.21. Those builds sit inside today’s affected ranges. A box that took the SAML/auth-bypass update is still in for 88771/88772 unless it is on 14.1-73.37, 13.1-64.23, or the matching FIPS/NDcPP floor.
  4. A firmware ISO is not forensic triage. CISA’s dedicated 27 September alert: check for compromise before patching; an update can remove evidence. Citrix’s IoC scan in NetScaler Console (14.1-73.36+, telemetry on) is the vendor’s first-pass tool. Citrix’s own caveat: the IoCs do not cover every TTP; a clean scan is not proof.

This is not a re-run of [PeopleSoft CVE-2026-35273](/posts/2026-09-27-peoplesoft-cve-2026-35273-waf-bypass/). PeopleSoft was an old KEV row with a new WAF bypass. NetScaler is two new KEV rows, zero-day until Sunday, default-config RCE on the perimeter.

FactRecord
CVECVE-2026-88771 (lead); CVE-2026-88772 (second KEV)
ProductCitrix NetScaler ADC / NetScaler Gateway (customer-managed)
KEV catalog2026.09.27, count 1728
Added / due27 September / 30 September 2026
Vendor advisoryCTX697096; created 27 September 15:22
Vendor scoreCVSS 4.0 9.5 on both KEV CVEs
CWECWE-20 (88771, Citrix/CVE.org); CWE-119 (88772). KEV JSON lists CWE-119 on both rows — treat the vendor CNA as the technical class for 88771
ExploitationCONFIRMED as KEV; Citrix: exploits “have been observed”; CISA: “actively exploiting these vulnerabilities globally”
Ransomware useUnknown
Named CISA actorNone
WorkaroundNone published for 88771/88772
OT / process impactNone claimed

What happened

Saturday 26 September, NetScaler administrators reported on Reddit that suppliers, MDR teams, and CERTs were telling them to shut appliances down with no CVE. watchTowr publicly called the information credible and said patches were expected early the following week. A circulating NCSC-NL pre-notification (TLP:AMBER per SecurityWeek; BleepingComputer says NCSC-NL declined to confirm the text to them) is REPORTED, not a primary we can hang the story on.

Sunday 27 September the primary record arrived.

Citrix CTX697096 covers eight CVEs, CVE-2026-88771 through CVE-2026-88778. Two sentences in the bulletin matter more than the table: “Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed.” And: all ADC/Gateway deployments, “including those deployed with the default configuration. No additional features or settings need to be enabled” for 88771.

Affected supported trains:

Secure Private Access Hybrid deployments that use NetScaler instances are in. The bulletin applies to customer-managed appliances. Citrix says it is upgrading Citrix-managed cloud services and Citrix-managed Adaptive Authentication.

CISA published two products the same day: the two-row KEV add, and a dedicated alert that names all eight CVEs and states CISA has “received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally.” Both KEV rows: due 30 September, ransomware Unknown, forensic triage Yes. Notes point at CTX697096, the community bulletin, CTX694799 (suspected-compromise steps), and BOD 26-04. The 88771 notes block copy-pastes the NVD URL for 88772 — a catalog typo, not a merge of the two bugs.

CERT-EU SA 2026-014 (27 September 17:40 UTC, v1.0) independently restated Citrix’s exploitation confirmation, the same version floors, and “strongly” advised a compromise assessment on any internet-facing affected build. NZ NCSC’s 28 September alert is the same technical table.

The other six CVEs in CTX697096 are not on KEV. They are configuration-gated (HTTP smuggling, URL-expression policy bypass, three more memory overflows, TCP ISN prediction). CVE-2026-88778 is closed by enabling Enhanced ISN Generation, not by the upgrade alone. Do not treat “we took 14.1-73.37” as closing 88778.

RWP is not reproducing request bodies, DTLS packet structure, or shellcode. Citrix published enough version floors, DTLS config strings, and a Console IoC path for a hunt. That is the defensive cut.

Why it matters

NetScaler ADC and Gateway sit on the WAN side of the identity and application path: SSL VPN, ICA/CVPN, AAA, load balancing in front of internal apps. Unauthenticated command execution there is not “a reverse-proxy CVE.” It is code execution on the box that terminates staff remote access and often holds certificates, session state, and a view of what is behind it.

Two operational lies show up in every NetScaler incident, and both are already in this week’s ticket queue.

  1. “We patched NetScaler in August.” CVE-2026-19490 was real, KEV, and due 12 September. The fixed builds for that bug are below 14.1-73.37 / 13.1-64.23. Patch history is not inventory. watchTowr says the same: appliances patched for 19490 remain vulnerable unless they run one of this bulletin’s floors.
  2. “We will disable DTLS / lock the management IP.” 88772 is the DTLS bug. 88771 is not. Citrix’s precondition for 88771 is the default configuration. Closing 443 on the management NSIP does not close the VPN or LB virtual server.

CISA’s three-day clock and forensic-triage flag are the federal instruction, not an optional extra. BOD 26-04 wants evidence captured on publicly exposed assets that grant total control post-exploitation before the patch wipes it. Citrix’s Console IoC feature requires 14.1-73.36 or later and an enabled telemetry channel. Teams still on 13.1 cannot use that UI path; Citrix says contact Support for the generic IoCs. Citrix also says those IoCs “might fail to identify actual compromises.”

BleepingComputer, citing Shadowserver dashboards, reports more than 23,000 internet IPs with NetScaler fingerprints (about 22,000 ADC, about 1,500 Gateway). That is a banner census, not a count of unpatched 88771 boxes, not a count of honeypots, and not a victim list. Treat it as exposure scale, not as a campaign size.

No public victim names. No named actor in CISA, Citrix, or CERT-EU. Ransomware field is Unknown. Do not import last year’s NetScaler ransomware history onto this CVE.

Who / what is affected

AssetWhat to assumeStatus
Customer-managed ADC/Gateway 14.1 before 14.1-73.37, 13.1 before 13.1-64.23In for CVE-2026-88771 (all deployments)CONFIRMED vendor / CNA
Same trains, VPN vServer without -dtls OFF, or any DTLS vServerAlso in for CVE-2026-88772CONFIRMED vendor
ADC 14.1-FIPS before 14.1-73.37 FIPS; 13.1-FIPS/NDcPP before 13.1-37.279InCONFIRMED vendor
Secure Private Access Hybrid using those NetScaler instancesIn; upgrade the instanceCONFIRMED vendor
Citrix-managed cloud / Adaptive AuthenticationVendor says it is applying updatesCONFIRMED vendor statement; verify with Citrix if you consume the service
Builds that closed CVE-2026-19490 (14.1-73.32 / 13.1-63.21)Still in for 88771/88772CONFIRMED by version math against CTX697096
12.1 and other EoTS trainsNot listed in this bulletinUNKNOWN; do not treat as safe
Management interface firewalled, data-plane VIP on the internetStill in for 88771CONFIRMED vendor (default config, no extra feature)
Named victims / named actorNone in CISA, Citrix, CERT-EUUNKNOWN
OT / ICS / processNot claimed. A NetScaler in front of an industrial remote-access path is still an IT perimeter compromise until evidence says otherwiseNo evidence
CISA ransomware fieldUnknownCONFIRMED catalog

The DTLS check Citrix published is configuration, not a PoC:

Technical context

RWP is not reproducing packets, heap offsets, or command strings.

What the primary record actually says:

Citrix credits Michael Tucker, Chew Keong Tan and Alex Bernier of the JPMorgan Chase XOR Team, and Maxim Suhanov. That is coordinated disclosure credit, not attribution of the in-the-wild exploits.

CISA KEV JSON lists CWE-119 on the 88771 row. Citrix and CVE.org list CWE-20. Use the CNA for the bug class; use KEV for the clock and the forensic-triage flag.

watchTowr (28 September update) reports a 13.1 upgrade foot-gun: run show ns variable first; if it returns any variables, install 13.1-64.24 rather than 64.23 to avoid a known reboot loop. That instruction is not in CTX697096 as we retrieved it. Treat it as REPORTED by watchTowr. Confirm with Citrix Support before you pick 64.24 over 64.23.

ATT&CK mapping for defenders, not a kill chain we observed:

TechniqueIDWhy it is on the ticket
Exploit Public-Facing ApplicationT1190Unauthenticated RCE on internet ADC/Gateway
Command and Scripting InterpreterT105988771 is arbitrary command execution
Unsecured CredentialsT1552Post-compromise: keys, certs, and secrets on the appliance
Valid AccountsT1078Session/VPN identity store after the box is owned

Threat / exploitation status

ClaimStatusSource
Exploits of 88771 and 88772 observed on unmitigated deploymentsCONFIRMEDCitrix CTX697096
Active exploitation globallyCONFIRMED as CISA statementCISA 27 Sep dedicated alert (“reports and partner threat intelligence”)
Both CVEs on KEV, due 30 Sep, forensic triage Yes, ransomware UnknownCONFIRMEDCatalog 2026.09.27, count 1728
Zero-day until 27 Sep bulletinASSESSED high confidenceNo public CVE/patch before CTX697096; watchTowr 26 Sep warning
NCSC-NL private pre-notification; Citrix found the bugs in customer-incident investigation; CRA filingREPORTEDCirculating notice via BleepingComputer / SecurityWeek; NCSC-NL declined to confirm the text to BC
Named threat actorUNKNOWNNone in Citrix, CISA, CERT-EU
Ransomware use of these two CVEsUNKNOWNKEV field Unknown
~23k internet NetScaler fingerprintsREPORTEDBleepingComputer citing Shadowserver; not a vulnerable-version census
Public exploit / PoCUNKNOWN in the primary record we retrievedRWP is not hunting one

Confidence on the KEV fact and the default-config RCE: high. Confidence on campaign size, actor, and ransomware: low — the public record does not support those claims yet.

What defenders should do

  1. Inventory every customer-managed NetScaler ADC and Gateway, including HA pairs, FIPS, NDcPP, and Secure Private Access Hybrid instances. Record current build. Anything below 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, or 13.1-37.279 FIPS/NDcPP is in for 88771. Do not skip boxes that already took the August 19490 build.
  2. Preserve evidence first on internet-facing appliances. Support bundle, logs, snapshot, core dump. CISA: an update can destroy forensic visibility. Then run Citrix’s IoC path (NetScaler Console Security Advisory, 14.1-73.36+, telemetry enabled) or ask Support for the generic IoCs. A clean result is not clearance. If compromise is suspected, CTX694799: isolate, revoke, hunt systems the ADC talked to, rebuild, rotate local passwords and KEK, replace restored SSL certificates.
  3. Install the fixed build. There is no published workaround for 88771/88772. On 13.1, confirm the target build with Citrix if show ns variable is non-empty (watchTowr: 13.1-64.24). After upgrade, enable Enhanced ISN Generation to close 88778.
  4. Hunt past the appliance. A NetScaler that ran attacker commands is a beachhead. Session replay, new admin accounts, cert issuance, and lateral movement off the SNIP/VIP path are the rest of the ticket. Rotate secrets the box held.
  5. Keep the management plane off the internet. That does not close 88771. It does stop the next management-plane KEV from stacking on this one.
  6. Sequence the rest of this window. Due today, 28 September: [SharePoint CVE-2026-65660](/posts/2026-09-26-sharepoint-cve-2026-65660-kev/), WordPress CVE-2026-87902, MikroTik CVE-2026-67279. Due 30 September: these two NetScaler CVEs. [WSO2 CVE-2026-5430](/posts/2026-09-25-wso2-cve-2026-5430-kev/) and Adobe CVE-2026-71362 were due yesterday. Internet-facing NetScaler is today’s interrupt; those clocks do not pause.

RWP assessment

Score 9.0.

Highest-leverage development since yesterday’s PeopleSoft WAF-bypass piece is a new KEV pair for unauthenticated RCE on the default NetScaler configuration, with vendor-confirmed in-the-wild use, a CISA global-exploitation alert, a three-day federal clock, and forensic triage Yes. Evidence quality is high: Citrix bulletin, CISA JSON, CISA dedicated alert, CERT-EU, NVD/CVE.org.

It outranks a second day on PeopleSoft CVE-2026-35273 because yesterday already shipped Mandiant’s encoded-path campaign; there is no new freeze on that CVE. It outranks SharePoint CVE-2026-65660, WordPress CVE-2026-87902, and MikroTik CVE-2026-67279 (all due today) because those are clocks on stories already assessed 24–26 September. It outranks the six non-KEV CVEs in the same Citrix bulletin because CISA did not put them on the catalog. It outranks Cloudflare’s Containers/Sandboxes residual-data fix (27 September) because that is a cloud-tenant isolation story, not an internet-edge RCE with a Wednesday due date.

What we are not saying: that ransomware is using 88771 (Unknown); that a named APT owns this (no one has claimed it in the primary record); that pulling DTLS is a fix for the lead CVE; that Citrix-managed cloud tenants must patch themselves (vendor says it is rolling the update); that a NetScaler in an industrial DMZ is confirmed OT impact.

What we are watching

Sources

Sources

  1. CISA — Adds two KEV CVE-2026-88771 CVE-2026-88772
  2. CISA — Critical zero-day vulnerabilities exploited in Citrix NetScaler ADC, Gateway
  3. CISA — KEV JSON feed catalog 2026.09.27
  4. CISA — Known Exploited Vulnerabilities Catalog
  5. CISA — BOD 26-04
  6. Citrix — CTX697096 NetScaler CVE-2026-88771 through CVE-2026-88778
  7. Citrix — Community bulletin CVE-2026-88771 through CVE-2026-88778
  8. Citrix — CTX694799 steps if NetScaler ADC is suspected compromised
  9. CVE — CVE-2026-88771
  10. CVE — CVE-2026-88772
  11. NVD — CVE-2026-88771
  12. NVD — CVE-2026-88772
  13. CERT-EU — Security Advisory 2026-014
  14. NZ NCSC — Multiple vulnerabilities affecting Citrix NetScaler
  15. BleepingComputer — Citrix confirms two NetScaler RCE zero-days
  16. BleepingComputer — CISA orders feds to patch exploited Citrix flaws by Wednesday
  17. The Hacker News — CISA says attackers exploiting two critical Citrix NetScaler flaws
  18. SecurityWeek — Citrix confirms 2 NetScaler zero-days
  19. watchTowr — CVE-2026-88771 NetScaler RCE