UK’s trusted IT infrastructure partner since 2003
Servnet
FinanceToolsConfiguratorGet in Touch
Cyber security

Citrix NetScaler Zero-Days 2026: UK Patch Deadline

London · Servnet News Desk · IT infrastructure analysis4 min read
Share

Citrix has confirmed active exploitation of two critical NetScaler flaws rated 9.5 on the CVSS scale, prompting a CISA alert and a global scramble to patch. For UK organisations running NetScaler ADC or Gateway at the network edge, vulnerability management services need to move from routine to emergency mode within hours, not weeks.

Severity of the newly disclosed NetScaler flaws
10 CVSS8 CVSS5 CVSS3 CVSS0 CVSS9.5 CVSSCVE-887719.5 CVSSCVE-887729.3 CVSSCVE-887738.8 CVSSTCP ISN BugCVSS v4.0 score
View the data behind this chart
Severity of the newly disclosed NetScaler flaws
CVE-88771CVE-88772CVE-88773TCP ISN Bug
CVSS v4.0 scoreCVSS9.5CVSS9.5CVSS9.3CVSS8.8

What Citrix and CISA have confirmed

Citrix's security bulletin, published on Sunday, discloses eight CVEs affecting NetScaler ADC and NetScaler Gateway, including customer-managed appliances and Secure Private Access Hybrid deployments that use NetScaler instances. Citrix has stated that two of these — CVE-2026-88771 and CVE-2026-88772, both rated 9.5 on the CVSS scale — are already being exploited against unmitigated deployments.

CVE-2026-88771 allows an unauthenticated attacker to execute arbitrary commands remotely. CVE-2026-88772 is a memory overflow bug that can lead to remote code execution or denial of service, and notably requires DTLS to be enabled — a configuration commonly used for VPN virtual servers. CISA issued its own alert on Sunday, saying it "has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally."

The full list of eight flaws — not just two

Beyond the headline pair, Citrix's bulletin discloses six further issues that buyers should factor into risk assessments rather than dismiss as secondary. A third critical bug, CVE-2026-88773 (CVSS 9.3), enables HTTP request smuggling — a technique that can bypass or confuse security controls on front-end servers. Three further bugs are rated 8.8 and relate to memory overflow conditions that can destabilise NetScaler appliances, alongside another 8.8-rated flaw involving TCP Initial Sequence Number prediction. A lower-severity 7.0-rated issue involves a feature policy bypass tied to improper handling of HTTP URL-based expressions.

Citrix has published fixed builds covering the affected range: NetScaler ADC and Gateway 14.1-73.37 and later, 13.1-64.23 and later, 14.1-73.37 FIPS and later, and 13.1-37.279 and later for the 13.1-FIPS and 13.1-NDcPP branches. There is no need to wait for a future release — the remediation already exists.

Why UK buyers can't treat this as routine patching

NetScaler devices typically sit at the network edge as VPN gateways and application delivery controllers, which is precisely where unauthenticated remote code execution flaws do the most damage. CISA's own alert acknowledges that "updating Citrix NetScaler appliances can be complex and may require downtime," which is exactly the excuse many admins have used historically to defer patching — but with confirmed in-the-wild exploitation, that calculus no longer holds.

There is also a governance angle worth noting: a Reddit thread alleges that at least one Citrix channel partner knew of these flaws on Saturday and told customers to take NetScalers offline a day before Citrix's public disclosure. Whatever the truth of that claim, it underlines how UK buyers relying solely on vendor bulletins may be a step behind partners and threat intelligence feeds — reinforcing the case for layered network security solutions that don't depend on any single notification channel.

Illustration: Citrix NetScaler Zero-Days 2026: UK Patch Deadline

A pattern UK infrastructure teams have seen before

This is not an isolated event. Citrix disclosed critical NetScaler vulnerabilities that were quickly exploited in March 2026, twice in 2025, and again in 2023. According to The Register's reporting, NetScaler flaws featured on the Five Eyes alliance's annual most-exploited vulnerabilities list every year from 2020 to 2023. More recently, Citrix issued a batch of six NetScaler fixes in July 2026, which The Hacker News reported was followed by reports of active exploitation. Anyone who has followed previous Citrix NetScaler vulnerabilities will recognise the shape of this incident immediately.

The uncomfortable truth for procurement and security teams is that NetScaler's exposure is now a predictable, recurring line item in the risk register rather than a one-off crisis. In our assessment — an editorial recommendation rather than an established finding — this pattern should prompt a review of how contracts, support windows and change-management processes are built around the platform.

What to do in the next 48 hours

CISA set a 30 September 2026 deadline for U.S. federal civilian agencies to patch under Binding Operational Directive 26-04; UK organisations are not bound by it. As a matter of editorial guidance rather than sourced requirement, that date is nonetheless a sensible practical benchmark for private-sector exposure windows, especially for internet-facing VPN gateways.

Before applying fixed builds, admins should confirm which CVEs apply to their specific version and configuration — Citrix's advisory details detection steps for each flaw. Where a change window genuinely cannot be found in time, compensating controls and zero trust segmentation can reduce exposure temporarily, but they are a bridge, not a substitute for patching. Teams unsure how to weigh CVSS severity against real-world exploitation should first understand CVE and CVSS scores and how CISA's KEV listing changes urgency.

  • •Identify every NetScaler ADC/Gateway instance, including Secure Private Access Hybrid deployments using NetScaler
  • •Check DTLS status on VPN virtual servers — it's on by default and relevant to CVE-2026-88772
  • •Apply fixed builds: 14.1-73.37+, 13.1-64.23+, 14.1-73.37 FIPS+, and 13.1-37.279+ (for 13.1-FIPS/13.1-NDcPP)
  • •Suggested prioritisation, to be adjusted for your own exposure and asset criticality: internet-facing gateways first, internal-only appliances second
  • •Where patching is delayed, layer in compensating controls and monitor for exploitation attempts
Exploitation to federal patch deadline (27–30 Sept 2026)
W0W1W2W3W4Active exploitation observed1wCitrix bulletin published1wCISA KEV listing and alert1wUS federal patch deadline1wTotal: 4 weeks end-to-end
View the data behind this chart
Exploitation to federal patch deadline (27–30 Sept 2026)
PhaseStarts (week)Duration (weeks)
Active exploitation observed01
Citrix bulletin published11
CISA KEV listing and alert11
US federal patch deadline31

Longer-term: rethinking edge device resilience

Given NetScaler's exploitation history, UK buyers should treat this incident as a prompt to review broader edge-security posture rather than a one-time fire drill. That includes evaluating managed detection & response coverage on edge appliances, checking ransomware protection readiness given that RCE flaws on VPN gateways can be a ransomware entry point, and considering third-party maintenance for network hardware where ageing or unsupported NetScaler hardware complicates patch cycles.

None of this replaces patching the two critical bugs immediately — but organisations that keep getting caught out by NetScaler's recurring vulnerabilities are usually the ones without a repeatable, tested emergency-patch process for edge infrastructure.

Sources
  1. 01Citrix — Security Bulletin for NetScaler ADC and NetScaler Gateway · 27 September 2026
  2. 02The Register — Certainties in life: death, taxes, and critical Citrix vulns under attack · 28 September 2026
  3. 03The Stack — Citrix confirms ongoing NetScaler zero day exploitation · 27 September 2026
  4. 04BleepingComputer — CISA orders feds to patch exploited Citrix flaws by Wednesday · 27 September 2026
  5. 05BleepingComputer — Citrix admins warned to shut down NetScalers over 2 exploited zero-days · 27 September 2026
  6. 06The Hacker News — Warning: Two unpatched Citrix NetScaler vulnerabilities · 27 September 2026
  7. 07The Hacker News — CISA says attackers are exploiting two Citrix NetScaler flaws · 28 September 2026
  8. 08The Hacker News — Citrix patches six NetScaler flaws · 15 July 2026
  9. 09The Register — Citrix NetScaler bug may be multiple flaws in one · 30 March 2026
Share
Key takeaways
  • ✓Citrix has confirmed active exploitation of CVE-2026-88771 and CVE-2026-88772, both rated 9.5 CVSS, alongside six other disclosed flaws.
  • ✓CISA issued an alert and added both bugs to its KEV catalogue, setting a 30 September 2026 deadline for U.S. federal civilian agencies under BOD 26-04; this deadline does not apply to UK organisations.
  • ✓CVE-2026-88772 requires DTLS, which is enabled by default on VPN virtual servers — a configuration commonly used for VPN gateways.
  • ✓Fixed builds already exist (14.1-73.37+, 13.1-64.23+, 14.1-73.37 FIPS+, and 13.1-37.279+ for 13.1-FIPS/13.1-NDcPP); there is no need to wait for a future patch.
Frequently asked

FAQs — Citrix NetScaler Zero-Days 2026

What is CVE-2026-88771 in the Citrix NetScaler disclosure?

It's a critical, 9.5-CVSS remote code execution flaw that lets an unauthenticated attacker execute arbitrary commands on affected NetScaler ADC and Gateway appliances. Citrix has confirmed it is being actively exploited.

How is CVE-2026-88772 different from CVE-2026-88772... 88771?

CVE-2026-88772 is a memory overflow vulnerability, also rated 9.5 CVSS, that can lead to remote code execution or denial of service. It requires DTLS to be enabled, which is the default setting for VPN virtual servers.

Do UK organisations have to meet the CISA patch deadline?

The 30 September 2026 deadline under Binding Operational Directive 26-04 applies to U.S. federal civilian agencies, not UK organisations. As editorial guidance rather than a sourced requirement, however, UK teams running NetScaler may still find it useful as a practical urgency benchmark for their own vulnerability management services.

What should I do if I can't patch NetScaler immediately?

Identify exposure, check whether DTLS or other affected configurations apply, and use compensating controls such as network segmentation and zero trust policies as a temporary bridge until a change window allows the fixed build to be applied.

Related

Turning this into a buying decision?

One conversation with an engineer who's specced this before. No sales script.

Talk to Servnet →

Talk to a UK specialist

Get expert advice or a no-obligation quote — servers, storage, networking, maintenance, finance and cloud. We reply the same working day.

or call 0800 987 4111