On September 27, 2026, Citrix released a critical security bulletin (CTX697096) addressing eight vulnerabilities in customer-managed NetScaler ADC and NetScaler Gateway appliances.
Among these findings are two critical unauthenticated Remote Code Execution (RCE) zero-days—CVE-2026-88771 and CVE-2026-88772—that are actively being exploited in the wild.
The Cybersecurity and Infrastructure Security Agency (CISA) has added both flaws to its Known Exploited Vulnerabilities (KEV) catalog, underscoring the urgency for immediate remediation.
Breakdown of the vulnerabilities
The bulletin discloses eight total vulnerabilities, ranging from critical unauthenticated remote execution down to high-severity denial-of-service (DoS) conditions and HTTP request smuggling.
| CVE ID | Severity (CVSS v3) | Vulnerability type | Preconditions / affected setup |
|---|---|---|---|
| CVE-2026-88771 | Critical (9.5) | Unauthenticated RCE (Improper Input Validation) | Default configuration. Affects all instances on impacted versions. (Exploited in the wild) |
| CVE-2026-88772 | Critical (9.5) | Unauthenticated RCE / DoS (Memory Overflow) | DTLS enabled (default on NetScaler Gateway VPN vServers). (Exploited in the wild) |
| CVE-2026-88773 | High (9.3) | HTTP Request Smuggling | HTTP URL-based policy expressions configured |
| CVE-2026-88774 | High (7.0) | Policy Bypass | HTTP URL-based policy expressions configured |
| CVE-2026-88775 | High (8.8) | Memory Overflow / DoS | Gateway or AAA vServer configured |
| CVE-2026-88776 | High (8.8) | Memory Overflow / DoS | Load Balancing (LB) vServer of type Oracle configured |
| CVE-2026-88777 | High (8.8) | Memory Overflow / DoS | LB/CS or CGNAT-LSN/NAT64 with non-HTTP L7 protocol enabled |
| CVE-2026-88778 | Medium | Predictable TCP Initial Sequence Numbers (ISNs) | TCP configuration enabled (Requires manual mitigation configuration) |
Why this threat is severe
NetScaler appliances sit at the perimeter of many enterprise networks, serving as key gateways for authentication and load balancing. Vulnerabilities in these appliances offer attackers direct network access:
- No authentication required: An unauthenticated remote attacker can execute arbitrary commands on vulnerable perimeter devices without needing valid credentials.
- Default configurations exposed: CVE-2026-88771 requires no special feature toggles or non-default configurations—meaning any exposed appliance running a vulnerable build is vulnerable out-of-the-box.
- Widespread preconditions: CVE-2026-88772 triggers when DTLS is active. Because DTLS is enabled by default on NetScaler VPN virtual servers, most enterprise deployments meet this precondition.
Affected Citrix NetScaler products and immediate actions
1. Log into the ADC Portal
The Loadbalancer.org ADC Portal automatically scans for Common Vulnerabilities and Exposures (CVEs) affecting connected Application Delivery Controllers (ADCs) by querying the NIST National Vulnerability Database.
Once logged in to your ADC Portal account, navigate to Security > Insights.
From there, identify your affected NetScaler appliances.

2. Preserve logs and state evidence
Because updating software can overwrite volatile forensic traces, check for signs of potential compromise first if you manage internet-facing instances. Take snapshot logs and evaluate system activity before applying the patch.
3. Apply the official firmware patches
No configuration workarounds exist for RCEs so there are no functional workaround settings for CVE-2026-88771 or CVE-2026-88772.
Deploy the fixed software build (14.1-73.37 or 13.1-64.23 dependent on branch) across all customer-managed devices immediately by clicking 'Update ADC':

4. Enable enhanced ISN generation
Upgrading the software alone does not resolve CVE-2026-88778. For deployments utilizing TCP configurations, explicitly enable Enhanced ISN Generation within your NetScaler configuration settings to prevent predictable initial sequence numbers.
5. Contact our support team for a free load balancer health check
The ADC Portal can help you identify, mitigate, and resolve Common Vulnerabilities and Exposures (CVEs) across your NetScaler, F5, Progress Kemp and Loadbalancer.org fleet. To find out how, contact our support team.
Further reading
- How to connect and manage a Citrix NetScaler in the Loadbalancer ADC Portal
- How to (proactively) manage Citrix NetScaler vulnerabilities
What to do when your NetScaler becomes a liability.