Product2 publishers3 min readPublished
CISA wants NetScaler owners to check for intruders before installing Citrix's zero-day fixes
Citrix has fixed two NetScaler ADC and Gateway flaws, each rated 9.5 out of 10, that attackers were exploiting before any patch existed. CISA wants owners to look for signs of compromise first because the update can erase the evidence, so the upgrade comes second.
The Product Desk · Product desk

What happened
- CVE-2026-88771 lets an attacker run commands without logging in, and it affects every NetScaler ADC and Gateway deployment, including the default setup.
- CVE-2026-88772 is a memory overflow that can lead to code execution or a crash, and it needs DTLS, a setting that is on by default on VPN servers.
- CISA added both flaws to its known-exploited catalog on Sunday and gave federal civilian agencies until Wednesday, September 30, to patch.
- The fixed releases are 14.1-73.37 and 13.1-64.23, along with matching FIPS builds.
- Citrix's bulletin covers eight flaws in total, six beyond the two that attackers are known to be using.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- constraint Switching off optional features does not shrink the exposure, because the first flaw works on the default setup; an unpatched box drops out of scope only through the upgrade or by going offline.
- exposure A compromised gateway puts the internal network behind it in scope for incident response, since NCSC-NL says the first flaw gives attackers full control of the device and direct access past it.
- cost Shutting the appliance down while the check runs stops new exposure but cuts off the staff who reach internal systems through it, so the interim step needs a business owner's sign-off.
- decision Outside federal civilian agencies no mandated date applies, so each owner has to set its own deadline and defend it against the maintenance calendar.
"We got a call from our IT supplier's security team, they couldn't give any details but they advised to shut our Netscalers down immediately," one administrator wrote on Reddit, in a post reported by BleepingComputer and quoted by TechRadar [16]. Citrix had not yet gone public when those calls started [19]. The person reading that message had been told to switch off the box the company's staff use to reach internal networks [2], with no details to pass on to the managers who would hear from the people locked out.
Teams usually tell themselves that a gateway fix can wait for the next maintenance window, and that the ticket closes when the build number changes. The reporting on these two flaws points the other way. A pre-notification attributed to the Dutch National Cyber Security Centre said Citrix found the flaws while investigating incidents at customers, Lawrence Abrams reported for BleepingComputer, and NCSC-NL declined to confirm the notice [18]. Security researcher Kevin Beaumont wrote that the attacks have run all month, describing the attackers as "probably nation state aligned" [15]. Citrix has not said who is behind them [15]. Its bulletin says only that exploits "on unmitigated NetScaler deployments have been observed" [6].
If Beaumont's timeline is right, an upgrade this week closes a hole that was open for weeks [15]. The upgrade does not show whether anyone came through it, and CISA warns it can wipe the traces that would [10]. The check also falls on the kind of device teams watch least. TechRadar notes that organisations usually put extensive security tools on computers and servers and leave specialised networking appliances less monitored [17]. For many teams, whatever evidence exists may sit mostly on the gateway itself [17].
Waiting has its own cost. "CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally," the agency said in an alert [8]. Each hour spent capturing an appliance's state is an hour it stays reachable on a vulnerable build.
I'd sort appliances on two axes. One is whether the box ran a vulnerable build while reachable from the internet at any point this month. The other is whether anyone has captured its state yet. For an exposed box with no capture, I'd capture and then upgrade on the same day, accepting the extra exposure in exchange for knowing whether the gateway was used. Once a capture exists, the upgrade goes on immediately and the capture goes to whoever runs incident response. Appliances already on a fixed build need a confirmed build number and nothing more, captured or not. For the cloud services Citrix manages itself, Citrix is doing the upgrade, according to The Next Web [12].
What to watch
- Whether Citrix or CISA publishes indicators of compromise or a specific check procedure for CVE-2026-88771 and CVE-2026-88772.
- Whether Citrix or a government agency names the group Kevin Beaumont described as "probably nation state aligned".
- Confirmation from NCSC-NL of the pre-notification saying Citrix found the flaws while investigating incidents at customers.