Critical Vulnerability in Citrix netscaler zero-day prompts emergency shutdowns (cve-2026-88771 & cve-2026-88772)
On September 26th, 2026, security researchers publicly warned of multiple unpatched remote code execution vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway, as organizations began taking the appliances offline on the advice of national authorities. On September 27th, Citrix confirmed active exploitation of CVE-2026-88771 & CVE-2026-88772, which enable unauthenticated Remote Code Execution (RCE) and impact the default configuration of Citrix Netscaler appliances.
Executive Summary
Update 2: September 27th, 2026: Citrix has now released an advisory confirming active in the wild exploitation of two unauthenticated Remote Code Execution (RCE) vulnerabilities that impact the default configuration of Citrix NetScaler appliances. Beazley Security strongly recommends that all organizations apply available patches immediately and leverage the Indicator of Compromise (IOC) scanner that Citrix has made available on the Citrix console.
Update: September 27th, 2026: Citrix has privately confirmed exploitation and has made a patch publicly available to organizations. Links to the patch are available below in the "patches" section of this advisory.
On September 26th, 2026, security researchers and threat intelligence publicly warned that it had verified reports of multiple unpatched remote code execution vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway, as organizations began taking the appliances offline on the advice of national authorities. The reported flaws have not been assigned CVE identifiers, and as of publication Citrix has not yet released an advisory confirming them. NetScaler ADC and NetScaler Gateway are internet-facing application delivery and VPN appliances that serve as the remote-access entry points for enterprise environments. While reports have not been confirmed by Citrix and NCSC-NL, the potential impact is severe, and the affected product sits at the network perimeter.
Beazley Security strongly recommends affected organizations apply the fixed versions listed in this advisory immediately, restrict external access to NetScaler appliances where possible, and monitor closely for signs of compromise.
Affected Systems or Products
Update September 27th, 2026: Citrix has released an advisory that confirms that the default configuration of Citrix NetScaler is vulnerable to these Remote Code Execution (RCE) vulnerabilities. In order to be impacted, an appliance must be running a build earlier than the fixed versions listed below.
CVE-2026-88771 affects all NetScaler ADC and NetScaler Gateway deployments with no additional features required. CVE-2026-88772 additionally requires DTLS to be enabled, which is the default on NetScaler Gateway (VPN) virtual servers unless it has been explicitly disabled.
Citrix NetScaler ADC and NetScaler Gateway are the products named in the current reports. No specific affected firmware builds or configurations have been confirmed, so the full scope is not yet established. Any internet-facing NetScaler ADC or Gateway deployment should be treated as potentially in scope until Citrix publishes details.
Mitigations / Workarounds
Update: September 27th, 2026: Citrix has now made patches available. Please review the "patches" section of this advisory for more details and a link to download and apply the patch.
With no patch available and the reports unconfirmed, remediation is not yet possible, and the priority is to reduce exposure and preserve the ability to investigate. Beazley Security suggests the following interim steps:
- Consider taking internet-facing NetScaler ADC and Gateway appliances offline, or restricting their access to trusted and administrative networks, until Citrix confirms the issue and releases a fix.
- Increase monitoring and retention of authentication and administrative logs to support later investigation.
Patches
Update September 27th, 2026: Citrix has made a patch available to confirmed clients. Organizations with active Citrix subscriptions should download and apply the latest patches available via the link below:
https://www.citrix.com/downloads/citrix-adc/virtual-appliances/vpx-release-14-1-73-37.html
At the time of writing, no patch is available for the vulnerabilities described in these reports, and Citrix has not published an advisory addressing them. Organizations should watch for an official Citrix advisory and apply any fix as soon as it is released.
Indicators of Compromise
Beazley Security has Threat Hunted across our MXDR Client environments for privately shared (TLP AMBER-STRICT) Indicators of Compromise. Organizations that may have been impacted have already been notified.
Citrix has also begun to make a tool available in the Citrix Console which searches for potential IOCs. This feature requires that telemetry be enabled on Citrix appliances.
Threat Intelligence
Beazley Security is aware of a likely attack campaign targeting Citrix Netscaler systems which begun on September 20th, 2026. Beazley Security recommends that organizations retain HTTP access logs (including the "VPN" error and access logs) and crash dumps from internet exposed Citrix NetScaler systems if possible.
Technical Details
On September 27th, 2026, Citrix published security bulletin CTX697096, which addresses eight vulnerabilities in NetScaler ADC and NetScaler Gateway. The bulletin included confirmation that exploitation of CVE-2026-88771 and CVE-2026-88772 has been observed in the wild.
CVE-2026-88771 (CVSS score 9.5) is an improper input validation flaw that allows an unauthenticated attacker to execute arbitrary commands. Citrix states that all NetScaler ADC and NetScaler Gateway deployments are affected, including the default configuration, and no additional features need to be enabled.
CVE-2026-88772 (CVSS 9.5) is a memory overflow that can lead to remote code execution or denial of service. It requires DTLS to be enabled, which is the default on NetScaler Gateway (VPN) virtual servers. Administrators can check their configuration (/nsconfig/ns.conf or show ns runningConfig) for the following:
- add vpn vserver <name> SSL <ip> 443 with no -dtls OFF flag means DTLS is enabled by default, and the precondition is met. - add vpn vserver <name> SSL <ip> 443 -dtls OFF means DTLS is explicitly disabled, and the precondition is not met. - add vpn vserver <name> DTLS ... or add lb vserver <name> DTLS ... means DTLS is enabled.
Citrix has not released root-cause details or proof-of-concept code for either vulnerability. Beazley Security will continue to update this advisory as additional details are available.
How Beazley Security is responding
Beazley Security is monitoring client perimeter devices through our Exposure Management Platform to identify impacted devices and support organizations in remediation of any issues found. Beazley Security has also searched for known Indicators of Compromise (IOCs) across our MXDR client base. Organizations that may have been impacted have already received notifications. If you believe your organization may have been impacted by this attack campaign and need support, please contact our Incident Response team
Sources
Vous êtes au courant d'un incident qui a un impact sur votre secteur d'activité ? Faites-nous savoir :