Citrix has confirmed active exploitation of two critical NetScaler flaws rated 9.5 on the CVSS scale, prompting a CISA alert and a global scramble to patch. For UK organisations running NetScaler ADC or Gateway at the network edge, vulnerability management services need to move from routine to emergency mode within hours, not weeks.
View the data behind this chart
| CVE-88771 | CVE-88772 | CVE-88773 | TCP ISN Bug | |
|---|---|---|---|---|
| CVSS v4.0 score | CVSS9.5 | CVSS9.5 | CVSS9.3 | CVSS8.8 |
What Citrix and CISA have confirmed
Citrix's security bulletin, published on Sunday, discloses eight CVEs affecting NetScaler ADC and NetScaler Gateway, including customer-managed appliances and Secure Private Access Hybrid deployments that use NetScaler instances. Citrix has stated that two of these — CVE-2026-88771 and CVE-2026-88772, both rated 9.5 on the CVSS scale — are already being exploited against unmitigated deployments.
CVE-2026-88771 allows an unauthenticated attacker to execute arbitrary commands remotely. CVE-2026-88772 is a memory overflow bug that can lead to remote code execution or denial of service, and notably requires DTLS to be enabled — a configuration commonly used for VPN virtual servers. CISA issued its own alert on Sunday, saying it "has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally."
The full list of eight flaws — not just two
Beyond the headline pair, Citrix's bulletin discloses six further issues that buyers should factor into risk assessments rather than dismiss as secondary. A third critical bug, CVE-2026-88773 (CVSS 9.3), enables HTTP request smuggling — a technique that can bypass or confuse security controls on front-end servers. Three further bugs are rated 8.8 and relate to memory overflow conditions that can destabilise NetScaler appliances, alongside another 8.8-rated flaw involving TCP Initial Sequence Number prediction. A lower-severity 7.0-rated issue involves a feature policy bypass tied to improper handling of HTTP URL-based expressions.
Citrix has published fixed builds covering the affected range: NetScaler ADC and Gateway 14.1-73.37 and later, 13.1-64.23 and later, 14.1-73.37 FIPS and later, and 13.1-37.279 and later for the 13.1-FIPS and 13.1-NDcPP branches. There is no need to wait for a future release — the remediation already exists.
Why UK buyers can't treat this as routine patching
NetScaler devices typically sit at the network edge as VPN gateways and application delivery controllers, which is precisely where unauthenticated remote code execution flaws do the most damage. CISA's own alert acknowledges that "updating Citrix NetScaler appliances can be complex and may require downtime," which is exactly the excuse many admins have used historically to defer patching — but with confirmed in-the-wild exploitation, that calculus no longer holds.
There is also a governance angle worth noting: a Reddit thread alleges that at least one Citrix channel partner knew of these flaws on Saturday and told customers to take NetScalers offline a day before Citrix's public disclosure. Whatever the truth of that claim, it underlines how UK buyers relying solely on vendor bulletins may be a step behind partners and threat intelligence feeds — reinforcing the case for layered network security solutions that don't depend on any single notification channel.

A pattern UK infrastructure teams have seen before
This is not an isolated event. Citrix disclosed critical NetScaler vulnerabilities that were quickly exploited in March 2026, twice in 2025, and again in 2023. According to The Register's reporting, NetScaler flaws featured on the Five Eyes alliance's annual most-exploited vulnerabilities list every year from 2020 to 2023. More recently, Citrix issued a batch of six NetScaler fixes in July 2026, which The Hacker News reported was followed by reports of active exploitation. Anyone who has followed previous Citrix NetScaler vulnerabilities will recognise the shape of this incident immediately.
The uncomfortable truth for procurement and security teams is that NetScaler's exposure is now a predictable, recurring line item in the risk register rather than a one-off crisis. In our assessment — an editorial recommendation rather than an established finding — this pattern should prompt a review of how contracts, support windows and change-management processes are built around the platform.
What to do in the next 48 hours
CISA set a 30 September 2026 deadline for U.S. federal civilian agencies to patch under Binding Operational Directive 26-04; UK organisations are not bound by it. As a matter of editorial guidance rather than sourced requirement, that date is nonetheless a sensible practical benchmark for private-sector exposure windows, especially for internet-facing VPN gateways.
Before applying fixed builds, admins should confirm which CVEs apply to their specific version and configuration — Citrix's advisory details detection steps for each flaw. Where a change window genuinely cannot be found in time, compensating controls and zero trust segmentation can reduce exposure temporarily, but they are a bridge, not a substitute for patching. Teams unsure how to weigh CVSS severity against real-world exploitation should first understand CVE and CVSS scores and how CISA's KEV listing changes urgency.
- •Identify every NetScaler ADC/Gateway instance, including Secure Private Access Hybrid deployments using NetScaler
- •Check DTLS status on VPN virtual servers — it's on by default and relevant to CVE-2026-88772
- •Apply fixed builds: 14.1-73.37+, 13.1-64.23+, 14.1-73.37 FIPS+, and 13.1-37.279+ (for 13.1-FIPS/13.1-NDcPP)
- •Suggested prioritisation, to be adjusted for your own exposure and asset criticality: internet-facing gateways first, internal-only appliances second
- •Where patching is delayed, layer in compensating controls and monitor for exploitation attempts
View the data behind this chart
| Phase | Starts (week) | Duration (weeks) |
|---|---|---|
| Active exploitation observed | 0 | 1 |
| Citrix bulletin published | 1 | 1 |
| CISA KEV listing and alert | 1 | 1 |
| US federal patch deadline | 3 | 1 |
Longer-term: rethinking edge device resilience
Given NetScaler's exploitation history, UK buyers should treat this incident as a prompt to review broader edge-security posture rather than a one-time fire drill. That includes evaluating managed detection & response coverage on edge appliances, checking ransomware protection readiness given that RCE flaws on VPN gateways can be a ransomware entry point, and considering third-party maintenance for network hardware where ageing or unsupported NetScaler hardware complicates patch cycles.
None of this replaces patching the two critical bugs immediately — but organisations that keep getting caught out by NetScaler's recurring vulnerabilities are usually the ones without a repeatable, tested emergency-patch process for edge infrastructure.
- 01Citrix — Security Bulletin for NetScaler ADC and NetScaler Gateway · 27 September 2026
- 02The Register — Certainties in life: death, taxes, and critical Citrix vulns under attack · 28 September 2026
- 03The Stack — Citrix confirms ongoing NetScaler zero day exploitation · 27 September 2026
- 04BleepingComputer — CISA orders feds to patch exploited Citrix flaws by Wednesday · 27 September 2026
- 05BleepingComputer — Citrix admins warned to shut down NetScalers over 2 exploited zero-days · 27 September 2026
- 06The Hacker News — Warning: Two unpatched Citrix NetScaler vulnerabilities · 27 September 2026
- 07The Hacker News — CISA says attackers are exploiting two Citrix NetScaler flaws · 28 September 2026
- 08The Hacker News — Citrix patches six NetScaler flaws · 15 July 2026
- 09The Register — Citrix NetScaler bug may be multiple flaws in one · 30 March 2026
