Citrix issued emergency updates on 27 September for eight vulnerabilities affecting NetScaler ADC and NetScaler Gateway. Two of them, CVE-2026-88771 and CVE-2026-88772, were already being exploited before the fixes were published. Citrix reports no mitigation. Administrators must update the appliances and check them for compromise.

CVE-2026-88771 is an input-validation flaw classified as CWE-20. It allows unauthenticated attackers to execute arbitrary commands and carries a CVSS score of 9.5. Every NetScaler ADC and NetScaler Gateway deployment is affected, including default configurations. No optional feature needs to be enabled, so the installed version is the relevant check.

CVE-2026-88772 is a memory overflow classified as CWE-19. It also has a CVSS score of 9.5 and can lead to arbitrary code execution or denial of service. Exploitation requires DTLS to be enabled, which is the default state. A gateway remains vulnerable unless DTLS is disabled with the `-dtls OFF` option. Other virtual servers are affected when they use the DTLS type.

Citrix lists these affected versions: NetScaler ADC and NetScaler Gateway 14.1 before 14.1 - 73.37; NetScaler ADC and NetScaler Gateway 13.1 before 13.1 - 64.23; NetScaler ADC FIPS before 14.1 - 73.37 FIPS; and NetScaler ADC, FIPS and NDcPP before 13.1 - 37.279.

The updates also fix six other vulnerabilities. CVE-2026-88773 has a CVSS score of 9.3 and involves HTTP Request Smuggling caused by inconsistent request parsing. There is no indication that this flaw is being actively exploited. The remaining issues have CVSS scores from 7 to 8.8.

Installing the updates blocks new attacks but does not remove an existing compromise. Administrators should retain the appliance memory image and logs for at least one month, then continue monitoring. NetScaler 14.1 - 73.36 or later can scan for indicators from its security page when telemetry is enabled. Citrix support can also provide the indicators. Citrix warns that this method does not cover every compromise. watchTowr advises replacing all secrets and certificates stored on affected appliances. Bleeping Computer recommends reducing internet exposure when an immediate update is impossible.

The Dutch National Cyber Security Centre, or NCSC, was reportedly the first public authority to alert organizations about the two exploited flaws. Its information came through the European CERT, which published its own notice on 27 September. The Dutch alert preceded the CVE assignments and said Citrix had found the attacks while investigating incidents in customer environments. Early signs appeared on Reddit on 26 September. The situation was already being discussed on social media that same day, including by security researcher Kevin Beaumont on Mastodon.

The NCSC did not explicitly confirm sending the initial notice. In comments to Bleeping Computer, it said that monitoring relevant developments and threats and advising organizations were part of its role, while declining further details because the publication was outside its constituency. The Dutch bulletin later became public.

This was the third exploited NetScaler wave in about two months. Tenable notes that CISA added CVE-2026-8452 to its catalog in August and CVE-2026-19490 on 9 September. Both were critical vulnerabilities under active exploitation. Tenable estimates that state-backed APT groups caused about two thirds of malicious NetScaler activity over the past seven years, with ransomware groups and their affiliates responsible for the rest. The Cyber Resilience Act has required vulnerability reports to national CERTs since 11 September. Its product-security liability regime is scheduled to begin at the end of 2027, and the reporting rule helped the NCSC warn organizations before Citrix published its bulletin.