INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Citrix Zero-Day Vulnerabilities Exploited in NetScaler RCE
| 2026-09-28 08:30 CRITICAL HIGHExecutive Summary AI-generated
The US Cybersecurity and Infrastructure Security Agency has ordered federal agencies to patch by Wednesday, 30 September due to a critical vulnerability in Citrix NetScaler ADC and Gateway deployments. The flaw, CVE-2026-88771, enables an unauthenticated attacker to execute arbitrary commands via remote code execution (RCE). With CVSS scores ranging from 7 to 9.5, the vulnerabilities pose significant risks to organizations with default configuration enabled for DTLS. Citrix has issued a bulletin warning of the potential exploitation and urging patching before disclosure by federal agencies. The Australian Signals Directorate's alert on September 28 also highlights the urgent need for immediate action.
Technical Mitigations AI-generated
* Implement secure coding practices and input validation mechanisms to prevent exploitation of CVE-2026-88771 and CVE-2026-88772.
* Configure Citrix NetScaler ADC and Citrix NetScaler Gateway with default configuration settings disabled or set to DTLS (Domain-Tolerant Security System) mode, which reduces the attack surface.
* Regularly update and patch operating systems, applications, and services that are not managed by Citrix, as these can be vulnerable to exploitation of CVE-2026-88771 and CVE-2026-88772.
* Monitor network traffic for suspicious activity related to NetScaler appliances and take immediate action if any signs of exploitation are detected.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Salt TyphoonSalt Typhoon
CVE-2026-88775CVE-2026-88775
CVE-2026-88771CVE-2026-88771
CVE-2026-88777CVE-2026-88777
CVE-2026-88776CVE-2026-88776
CVE-2026-88773CVE-2026-88773
CVE-2026-88778CVE-2026-88778
CVE-2026-88772CVE-2026-88772
CVE-2026-88774CVE-2026-88774
Target & Sectors
BENELUX
BENELUX
Incident Timeline
September 27
Threat actors exploited an eight new flaws in Citrix NetScaler ADC and Citrix NetScaler Gateway.
Click on any entity below to view its context and source!
organisation
Citrix NetScaler ADC
In a bulletin on September 27 the vendor confirmed eight new flaws in Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway).
organisation
Citrix ADC
In a bulletin on September 27 the vendor confirmed eight new flaws in Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway).
September 28
The Australian Signals Directorate's Australian Cyber Security Centre issued a critical alert on September 28 urging organizations to patch the Citrix NetScaler RCE zero-day vulnerability.
Click on any entity below to view its context and source!
organisation
The Australian Signals Directorate’s
The Australian Signals Directorate’s Australian Cyber Security Centre (ACSC) issued a critical alert on September 28 urging organizations to patch.
2026/09/28
Threat actors exploited a memory overflow vulnerability in Citrix NetScaler RCE zero-day CVE-2026-88771 to target all NetScaler ADC and NetScaler Gateway deployments with default configuration.
Click on any entity below to view its context and source!
threat_actor
Salt Typhoon
It’s not clear who is behind the exploitation attempts but in 2025, a cyber intrusion linked to
China-based group Salt Typhoon
targeted a Citrix zero day.
organisation
NetScaler
“Exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments has been observed,” Citrix said in a blog post.
Citrix confirms two NetScaler RCE zero-days exploited in attacks.
organisation
CVE-2026
Citrix has confirmed that two critical NetScaler remote code execution vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks and that it has released security updates to fix the flaws.
a memory overflow vulnerability leading to unpredictable or erroneous behavior or denial of service (CVSS 8.8)
CVE-2026-88776: a memory overflow vulnerability leading to unpredictable or erroneous behavior or denial of service (CVSS 8.8)
CVE-2026-88777: a memory overflow vulnerability leading to unpredictable or erroneous behavior or denial of service (CVSS 8.8)
CVE-2026-88778: a TCP Initial Sequence Number (ISN) prediction flaw with a (CVSS 8.8)
“This bulletin only applies to customer-managed Citrix NetScaler ADC and Citrix NetScaler Gateway,” the vendor confirmed.
organisation
NetScaler Console
Citrix has made indicators of compromise available through NetScaler Console and published additional guidance in their recent publication,
Security Bulletin for CVE-2026-88771 through CVE-2026-88778
, to support organizations in assessing potential compromise.
organisation
Citrix NetScaler
Cybersecurity firm watchTowr later publicly warned that it was "rapidly reacting to rumors" that multiple unpatched Citrix NetScaler remote code execution vulnerabilities were being exploited in the wild after verifying the information with "authoratitive sources.
organisation
NetScaler ADC
It affects all NetScaler ADC and NetScaler Gateway deployments with default configuration
CVE-2026-88772: a memory overflow vulnerability leading to RCE or denial of service.
Citrix confirms active exploitation
Citrix has now
published security bulletin CTX697096
, confirming the vulnerabilities and releasing patches for affected NetScaler ADC and NetScaler Gateway appliances.
organisation
NetScaler Gateway
It affects all NetScaler ADC and NetScaler Gateway deployments with default configuration
CVE-2026-88772: a memory overflow vulnerability leading to RCE or denial of service.
Citrix confirms active exploitation
Citrix has now
published security bulletin CTX697096
, confirming the vulnerabilities and releasing patches for affected NetScaler ADC and NetScaler Gateway appliances.
organisation
RCE
It affects all NetScaler ADC and NetScaler Gateway deployments with default configuration
CVE-2026-88772: a memory overflow vulnerability leading to RCE or denial of service.
organisation
Citrix NetScaler ADC
Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway.
organisation
CVE-2026-88778
a memory overflow vulnerability leading to unpredictable or erroneous behavior or denial of service (CVSS 8.8)
CVE-2026-88776: a memory overflow vulnerability leading to unpredictable or erroneous behavior or denial of service (CVSS 8.8)
CVE-2026-88777: a memory overflow vulnerability leading to unpredictable or erroneous behavior or denial of service (CVSS 8.8)
CVE-2026-88778: a TCP Initial Sequence Number (ISN) prediction flaw with a (CVSS 8.8)
“This bulletin only applies to customer-managed Citrix NetScaler ADC and Citrix NetScaler Gateway,” the vendor confirmed.
organisation
Citrix NetScaler Gateway
a memory overflow vulnerability leading to unpredictable or erroneous behavior or denial of service (CVSS 8.8)
CVE-2026-88776: a memory overflow vulnerability leading to unpredictable or erroneous behavior or denial of service (CVSS 8.8)
CVE-2026-88777: a memory overflow vulnerability leading to unpredictable or erroneous behavior or denial of service (CVSS 8.8)
CVE-2026-88778: a TCP Initial Sequence Number (ISN) prediction flaw with a (CVSS 8.8)
“This bulletin only applies to customer-managed Citrix NetScaler ADC and Citrix NetScaler Gateway,” the vendor confirmed.
organisation
CVSS
They have CVSS scores ranging from 7 to 9.5.
organisation
DTLS
It affects any deployment with DTLS configuration enabled (which it is by default on VPN vServers)
This vulnerability can be exploited when DTLS is enabled on a NetScaler ADC or NetScaler Gateway.
organisation
the Dutch National Cyber Security Center
Reports online also suggested the Dutch National Cyber Security Center (NCSC-NL) had issued alerts to local organizations in the country.
NCSC warned organizations before disclosure
Before Citrix publicly disclosed the vulnerabilities, the Dutch National Cyber Security Center (NCSC-NL) reportedly sent a pre-notification to organizations in the Netherlands warning about two critical NetScaler zero-days.
organisation
NCSC-NL
Reports online also suggested the Dutch National Cyber Security Center (NCSC-NL) had issued alerts to local organizations in the country.
NCSC warned organizations before disclosure
Before Citrix publicly disclosed the vulnerabilities, the Dutch National Cyber Security Center (NCSC-NL) reportedly sent a pre-notification to organizations in the Netherlands warning about two critical NetScaler zero-days.
organisation
Adaptive Authentication
“Cloud Software Group upgrades the Citrix-managed cloud services and Citrix-managed Adaptive Authentication with the necessary software updates.”
Cloud Software Group is upgrading Citrix-managed cloud services and Citrix-managed Adaptive Authentication.
organisation
the National CSIRT
"As part of our role as the National CSIRT and sectoral CSIRT for designated organizations, the NCSC-NL monitors relevant developments and cyber threats affecting the Netherlands 24/7," the NCSC-NL told BleepingComputer.
infrastructure
14.1
Citrix says the following versions are affected:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
NetScaler ADC FIPS before 14.1-73.37 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.279
Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds.
infrastructure
14.1-73
Citrix says the following versions are affected:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
NetScaler ADC FIPS before 14.1-73.37 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.279
Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds.
infrastructure
13.1
Citrix says the following versions are affected:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
NetScaler ADC FIPS before 14.1-73.37 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.279
Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds.
infrastructure
13.1-64
Citrix says the following versions are affected:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
NetScaler ADC FIPS before 14.1-73.37 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.279
Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds.
infrastructure
13.1-37
Citrix says the following versions are affected:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
NetScaler ADC FIPS before 14.1-73.37 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.279
Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds.
organisation
NetScaler Gateway 14.1
Citrix says the following versions are affected:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
NetScaler ADC FIPS before 14.1-73.37 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.279
Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds.
organisation
NetScaler ADC FIPS
Citrix says the following versions are affected:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
NetScaler ADC FIPS before 14.1-73.37 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.279
Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds.
organisation
Secure Private Access Hybrid
Citrix says the following versions are affected:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
NetScaler ADC FIPS before 14.1-73.37 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.279
Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds.
financial
73.37 NetScaler ADC
Citrix says the following versions are affected:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
NetScaler ADC FIPS before 14.1-73.37 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.279
Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds.
infrastructure
13.1 NetScaler ADC FIPS
Citrix says the following versions are affected:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
NetScaler ADC FIPS before 14.1-73.37 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.279
Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds.
infrastructure
14.1 NetScaler ADC FIPS
Citrix says the following versions are affected:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
NetScaler ADC FIPS before 14.1-73.37 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.279
Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds.
infrastructure
73.37 NetScaler ADC FIPS
Citrix says the following versions are affected:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
NetScaler ADC FIPS before 14.1-73.37 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.279
Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds.
organisation
the European Union's
It also said Citrix submitted a notification under the European Union's Cyber Resilience Act after discovering the attacks.
organisation
NetScaler RCE
"
"We are currently rapidly reacting to rumors that multiple unpatched Citrix NetScaler RCE vulnerabilities are circulating in the wild.
organisation
NCSC
The NCSC said exploitation had been identified at multiple Citrix customers worldwide, although it did not know whether the attacks were widespread.
organisation
BleepingComputer
BleepingComputer contacted the Dutch NCSC to confirm whether the advisory circulating online was legitimate.
organisation
NFL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
CHANEL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
30 September
Threat actors exploited a previously unknown vulnerability in Citrix NetScaler, allowing them to gain unauthorized access.
Click on any entity below to view its context and source!
source_region
United States
The US Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch by Wednesday, 30 September.
Tactical Metrics
Metrics
infrastructure
14.1
Software Version
Click for context!
Citrix says the following versions are affected:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
NetScaler ADC FIPS before 14.1-73.37 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.279
Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds.
Metrics
infrastructure
14.1-73
Software Version
Citrix says the following versions are affected:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
NetScaler ADC FIPS before 14.1-73.37 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.279
Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds.
Metrics
infrastructure
13.1
Software Version
Citrix says the following versions are affected:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
NetScaler ADC FIPS before 14.1-73.37 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.279
Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds.
Metrics
infrastructure
13.1-64
Software Version
Citrix says the following versions are affected:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
NetScaler ADC FIPS before 14.1-73.37 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.279
Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds.
Metrics
infrastructure
13.1-37
Software Version
Citrix says the following versions are affected:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
NetScaler ADC FIPS before 14.1-73.37 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.279
Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds.
Metrics
financial
73
Netscaler Adc
Citrix says the following versions are affected:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
NetScaler ADC FIPS before 14.1-73.37 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.279
Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds.
Metrics
infrastructure
13
Netscaler Adc Fips
Citrix says the following versions are affected:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
NetScaler ADC FIPS before 14.1-73.37 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.279
Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds.
Metrics
infrastructure
14
Netscaler Adc Fips
Citrix says the following versions are affected:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
NetScaler ADC FIPS before 14.1-73.37 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.279
Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds.
Metrics
infrastructure
73
Netscaler Adc Fips
Citrix says the following versions are affected:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
NetScaler ADC FIPS before 14.1-73.37 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.279
Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds.
Intelligence Sources
BleepingComputer
2026-09-27
Citrix confirms two NetScaler RCE zero-days exploited in attacks
BleepingComputer
CISA
2026-09-27
Infosecurity-Magazine
2026-09-28
Citrix Patches Critical Zero Days Under Active Exploitation
Infosecurity-Magazine
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-09-28T10:31
Comprehensive Tactical Telemetry
Highly Correlated Entities
27x
organisation
Identified Entity
NetScaler ADC
entity
8x
attribution
Attributing Entity
The US Cybersecurity and Infrastructure Security Agency
authority
8x
vulnerability
Exploited CVE
CVE-2026-88771
cve
5x
infrastructure
Software Version
14.1
version
4x
timeline
Temporal Reference
30 September
date
3x
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
3x
infrastructure
Netscaler Adc Fips
13
netscaler adc fips
2x
source region
Origin Country
United States
country
2x
vulnerability
CVSS Score
9
score
2x
general metric
Netscaler Gateway
14
netscaler gateway
Contextual Telemetry
Context Block
7 METRICS
threat actor
APT Group
Salt Typhoon
actor
tactic
Cyber Operation Type
Remote Code Execution
tactic
general metric
Exploitation
88,772
exploitation
target region
Target Country
Netherlands
country
financial
Netscaler Adc
73
netscaler adc
target region
Target Region
EUROPE
region
general metric
Cve-2026
88,778
cve-2026
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.