Skip to content
InYourGeek
visiteur@inyourgeek — shell
↹ compléter↑↓ historique⏎ ouvrirhelp
FR
Security· 3 min read

Two critical NetScaler flaws exploited before Citrix had a patch

On 27 September, Citrix confirmed two remote code execution flaws scored 9.5 in NetScaler ADC and Gateway, both already exploited before the fix shipped. An exposed appliance was reachable for days while no patch existed at all.

A NetScaler appliance at the edge of a corporate network, its door wide open, with two red 9.5 severity badges and a calendar page showing the weekend before the patch.

Two scores of 9.5, and exploitation already seen

On 27 September 2026, Citrix published security bulletin CTX697096, confirming two remote code execution vulnerabilities in NetScaler ADC and NetScaler Gateway: CVE-2026-88771 and CVE-2026-88772, both carrying a severity score of 9.5. The first stems from an input validation failure and lets an unauthenticated attacker run arbitrary commands. The second is a memory overflow that can lead to code execution or a denial of service. According to Bleeping Computer’s report, the vendor says exploitation of both flaws has been observed on unprotected deployments. These appliances normally sit right at the network edge to provide remote access: compromise one and you get a foothold on the perimeter itself, with no need to phish your way onto an internal desktop first.

The default configuration is enough

This is the first thing to check, before you start reassuring yourself that your particular setup is unusual. Citrix states that CVE-2026-88771 affects every NetScaler ADC and NetScaler Gateway deployment, including those left in their default configuration, and that no extra feature needs to be switched on for the flaw to be exploitable.

CVE-2026-88772 is exploitable when DTLS is enabled — and DTLS is enabled by default on VPN virtual servers. Which means the answer to “am I affected?” is not something you recall from the day you racked the thing. It is something you read off the current state of DTLS, virtual server by virtual server.

The perimeters nobody thinks to count

The list of fixed versions does not stop at two lines. Affected are the 14.1 branch before 14.1-73.37 and the 13.1 branch before 13.1-64.23, but also NetScaler ADC FIPS before 14.1-73.37 FIPS, and NetScaler ADC FIPS and NDcPP before 13.1-37.279. Take inventory from the first two lines alone and your certified appliances — which ship their own builds — quietly sit this one out.

Add to that Secure Private Access Hybrid deployments that rely on NetScaler instances: also affected, also due for an upgrade. The bulletin covers customer-managed equipment only. Cloud Software Group says it is handling Citrix-managed cloud services and Citrix-managed Adaptive Authentication itself, so working out which side of that line each instance falls on is part of the job. And the same update fixes six further NetScaler vulnerabilities — eight in total. The maintenance window you are about to schedule covers eight fixes, not two.

Before the patch, there was a weekend

The timeline matters as much as the patch does. The first signals came from administrators reporting that their IT provider or a security team had called them with no details whatsoever, advising them to shut their NetScalers down immediately. Others said they had been contacted by law enforcement, CERTs and national cybersecurity agencies. The firm watchTowr then said publicly that it was responding to rumours of several unpatched NetScaler RCEs, which it judged credible after checking with what it describes as authoritative sources. Ahead of disclosure, the Dutch NCSC reportedly sent a pre-notification to organisations in the country, based on information from a partner European CERT, mentioning two vulnerabilities that independently led to code execution: one allowed shellcode to be written straight into memory, the second was still being analysed. No CVE identifiers had been assigned at that point.

The practical upshot: between those weekend warnings and the 27 September release, an exposed appliance was reachable and no patch existed to close it. The public material so far offers no indicators of compromise.

Updating bolts the door. It tells you nothing about who is already on the other side of it.

Sources (1)

Written with AI assistance from the sources cited above, then reviewed and approved before publication by Sébastien Soulier.