Build3 publishers3 min readPublished
Default NetScaler Gateway configurations meet the conditions for both exploited pre-auth RCE bugs
Citrix confirmed attackers are exploiting two CVSS 9.5 pre-auth RCE flaws in NetScaler ADC and Gateway, one of them present in default configurations. Self-managed appliances need the fixed build, installed after evidence is saved, since an upgrade can erase signs of intrusion.
The Engineer · Build desk

What happened
- NetScaler administrators were told to shut appliances down on September 26, 2026, after a private Dutch NCSC pre-notification, and Citrix published bulletin CTX697096 with fixed builds the next day.
- CISA added CVE-2026-88771 to its Known Exploited Vulnerabilities catalog on September 27, 2026.
- The fixed releases are 14.1-73.37 and 13.1-64.23 or later, plus 14.1-73.37 FIPS and 13.1.37.279 for FIPS and NDcPP appliances.
- Appliances already patched for the earlier CVE-2026-19490 remain vulnerable unless they run one of the new fixed builds.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- constraint Self-managed Gateway owners cannot defer the upgrade on the grounds that a vulnerable feature is off, because factory defaults satisfy both bugs and exploitation needs no login.
- contradiction The sources split on mitigation: the dev.to summary offers disabling DTLS as an interim step for CVE-2026-88772, while watchTowr says Citrix has published no workaround for either bug.
- decision An emergency NetScaler change has to include time for evidence capture before the upgrade, and a clean IOC scan is not grounds to skip credential rotation.
- exposure A compromised appliance puts its stored LDAP service accounts, RADIUS shared secrets, OAuth tokens and certificates in scope for rotation, along with every user who logged in through it.
A NetScaler Gateway running a VPN virtual server on factory settings meets the preconditions for both bugs [24]. CVE-2026-88771 needs no feature enabled [2]. CVE-2026-88772, a memory overflow, needs DTLS, and DTLS is on by default for VPN virtual servers [3]. The attacker needs network access and no account [7].
Only the DTLS bug can be switched off by configuration. On a VPN virtual server the setting is `-dtls OFF`, and DTLS-type virtual servers have to be found and handled separately, according to a summary of the bulletin published on dev.to [4]. The same summary says to weigh the operational impact before turning DTLS off [25]. I think the change is worth making where the VPN can run without DTLS, as a stopgap while the upgrade is staged. It does nothing for CVE-2026-88771 [4]. Taking the appliance off the internet has a similar limit, because an unpatched device stays reachable from the internal network [5].
On 13.1, run `show ns variable` before upgrading. If it returns any variables, install 13.1-64.24, because 13.1-64.23 has a known reboot loop during the upgrade [9]. So the first fixed 13.1 build needed a fix of its own [9]. The bulletin also covers six configuration-dependent bugs, and one of them, CVE-2026-88778, closes only once Enhanced ISN Generation is enabled; the upgrade alone leaves it open [11]. The bulletin applies to customer-managed appliances, and Citrix updates its own managed cloud services [12].
I would run evidence capture and the upgrade as one emergency change. CISA advises checking for compromise and preserving forensic evidence before updating, because an update can remove that evidence [13]. watchTowr's capture list is logs, a snapshot, a support bundle and a core dump from each exposed appliance [13]. The dev.to summary lists what to look for: abnormal requests, unexpected configuration or file changes, outbound connections from the device, and suspicious administrative or VPN logins [15]. The IOC scan on the NetScaler Console Security Advisory page needs Console 14.1-73.36 or later with telemetry enabled [14]. Citrix warns its IOCs do not cover every technique, so a clean scan is not proof [14].
A positive finding extends the work past the appliance. Citrix says to investigate every system the NetScaler connected to, particularly authentication servers, web tier systems and management jump hosts, and to erase and reinstall MPX appliances [17].
CISA said: "Both are critical, zero-day vulnerabilities that can independently enable remote code execution. CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally." [18]
According to the dev.to summary, the public documentation does not say which user the injected code runs as or what privileges it gains [23]. An unattributed post on the sh3llc0d3 threat intel site claimed the exploits target nsppe, the native packet processing engine, and give "immediate execution under the nobody or root service context" [22]. The Stack, which reported the post, could not confirm it [22]. The Stack also reported that a large customer disclosed the bugs to Citrix before they were exploited, and that Citrix did not push an emergency fix until attacks started [21].
What to watch
- Whether CISA adds CVE-2026-88772 to the KEV catalog, given its own statement that both bugs are being exploited.
- Whether Citrix expands the NetScaler Console IOC scan beyond its current coverage, which it says does not include every technique.
- Whether Citrix answers The Stack's report that a customer disclosed the bugs before exploitation began.