Citrix NetScaler is broken twice, both times pre-auth
On September 26, 2026, NetScaler operators started getting calls from vendors and national response teams telling them to power the appliances off. There was no patch to install and isolating the management interface would not close the exposure. The Dutch National Cyber Security Centre had privately warned a small group of organisations the day before, and watchTowr picked the story up publicly the same weekend, saying forensic evidence tied multiple unpatched NetScaler RCEs to active in the wild abuse, per Cyber Kendra. On September 27, Citrix shipped fixed builds under bulletin CTX697096 covering eight CVEs, and CISA issued an emergency advisory the same day, adding CVE-2026-88771 and CVE-2026-88772 to KEV with a federal remediation deadline of September 30, 2026.
The two IDs score identically for a reason. Each is an unauthenticated RCE, and each runs off a code path an internet exposed NetScaler already advertises to the world.
Two CVEs, two paths, one appliance
CVE-2026-88771 is a CWE-20 improper input validation flaw with a CVSS v4.0 base score of 9.5, per TheHackerWire. Every NetScaler ADC and Gateway on an affected build is exposed including the default configuration, with no additional features required, per Cyber Kendra. An attacker sends one crafted request, the appliance treats user controlled input as command data instead of rejecting it, and the appliance runs the attacker's command with the privileges of the NetScaler service.
CVE-2026-88772 is a memory overflow scored 9.5 as well. The vulnerable code path runs whenever DTLS is enabled, and DTLS listens on UDP/443 by default on any VPN virtual server unless an operator has explicitly turned it off, per Cybersecurity News. A crafted DTLS record delivered to that VPN VIP overruns a buffer inside the packet handler; a well shaped payload yields code execution, a rougher one crashes the process. A public reconnaissance PoC by murrez on GitHub fingerprints exposed Gateways over UDP/443 with a benign DTLS ClientHello and parses build strings against the fix line, but stops short of the memory overflow trigger, which the readme flags as weaponized in the wild.
Neither bug needs a login or a cookie. Both are reachable through the same edge address a real client already uses.
Why the default configuration is the exposure
NetScaler hardening guidance for the last decade has trained operators to guard the management interface with ACLs and jump hosts. Neither of these bugs touches management. CVE-2026-88771 sits on input handled by a code path present on every deployment, and the phrase "including the default configuration" is Citrix's own. The population at risk is every NetScaler ADC and Gateway on the affected branches, and the priority sits with any Gateway, VPN vserver, or AAA vserver reachable from the internet.
CVE-2026-88772 lands on the second half of the same statement. DTLS is on by default on VPN vservers, so any Gateway that terminates workforce VPN traffic is running the vulnerable path by design. An attacker scanning UDP/443 can enumerate the exposed population silently, because a plain DTLS ClientHello is what a real VPN client sends.
The August patch does not close either door
Operators who installed August's NetScaler patch for CVE-2026-19490 already have the muscle memory for a fast upgrade cycle. Neither of these CVEs is that bug. The Windows Forum cross reference is explicit that appliances already on the August fix line still need the September update to close 88771 and 88772. Fixed builds are 14.1-73.37 and 13.1-64.23 on the general branches, 14.1-73.37 FIPS, and 13.1-37.279 for FIPS and NDcPP, per Windows Forum's fixed builds table. CTX697096 also names six further CVEs (CVE-2026-88773 through CVE-2026-88778) in the same drop; CVE-2026-88778 requires the operator to enable Enhanced ISN Generation on top of the upgrade.
The pattern matters. A scanner that recorded the August upgrade as green will not tell the on call which boxes are still on a pre 73.37 build tonight.
How TRIS scores this appliance by appliance
TRIS is the Threat and Risk Intelligence Scoring engine inside CVEasy AI. For CVE-2026-88771 and CVE-2026-88772 it walks four layers against the running inventory rather than stamping the same 9.5 label on every NetScaler in the estate.
Exploitation evidence, split by CVE. Citrix confirms in the wild exploitation of both IDs on unmitigated deployments before the advisory shipped, and CISA added both to KEV on September 27 with a three day federal deadline. TRIS keeps the IDs separate; a NetScaler with DTLS disabled drops 88772 and needs the 88771 story on its own.
Reachability from the exposure surface. 88771 is reachable on any NetScaler in the affected build range with no prerequisite. 88772 needs DTLS reachable on UDP/443, on by default on VPN virtual servers. TRIS reads the running configuration off the appliance in addition to the build banner, so an internet exposed Gateway with DTLS on stays top band on both, an internal ADC drops on 88771 by exposure and drops 88772 entirely if DTLS was disabled at build time.
Blast radius given a foothold. Code execution on a NetScaler at the perimeter collapses the identity layer behind it: SSL private keys, AAA session bindings, LDAP or SAML service credentials, and outbound reachability to stage a second payload. A Gateway that fronts a workforce VPN and a customer identity broker at the same time carries an order of magnitude more blast radius than a spare lab box with the same CVE.
Fix availability against the running build. 14.1-73.37 and 13.1-64.23 close both CVEs on the general branches; 14.1-73.37 FIPS and 13.1-37.279 cover FIPS and NDcPP. Boxes on a branch outside the fix ranges show clean on the CVE match, but the same query surfaces the appliance that is out of support and needs a decommission ticket instead of a patch ticket.
The same pair of CVEs lands at top band ACT on an internet exposed Gateway with DTLS on and no September patch, one band lower on a NetScaler that only fronts internal apps, and clean once the fixed build is deployed. A queue that reads 9.5 across the board cannot produce that split.
Patch, isolate, and hunt what may already be inside
Upgrade to the fixed build for the branch. 14.1 to 14.1-73.37 or later, 13.1 to 13.1-64.23 or later; FIPS to 14.1-73.37 FIPS or 13.1-37.279; NDcPP to 13.1-37.279. Any NetScaler outside those fix lines is unfixed until Citrix ships a build for it. If a build cannot land before the KEV clock runs out, take the appliance offline or restrict inbound reachability as an interim; turning DTLS off on VPN vservers closes CVE-2026-88772, and nothing short of a fixed build closes CVE-2026-88771.
Do not patch a running compromise. Snapshot the appliance before upgrading. Review process listings, cron entries, and the /netscaler configuration tree against a known good reference for the same build. Pull the last 48 hours of packet logs and look for anomalous requests in the exposure window, and check DTLS listeners on VPN VIPs for unexpected client fingerprints and repeated connection resets.
Rotate what the appliance held. SSL private keys on affected VIPs, AAA session tokens for the workforce VPN, LDAP or SAML service credentials the appliance used, and any RADIUS or TACACS shared secrets on the device; if the appliance held CA material, rotate that too.
How CVEasy AI surfaces this
CVEasy AI is the number one local first CTEM (Continuous Threat Exposure Management) platform. When Citrix publishes CTX697096 and CISA adds the CVEs to KEV, the ingest reads the affected branches, the fix builds, and the exploitation signal, and TRIS runs the four layer scoring against the NetScaler inventory that already lives on your hardware. A Gateway with DTLS on and 88771 unpatched on an internet exposed VIP gets a top band ACT with a workflow that names the fix build, cites the DTLS opt out as an interim on 88772, and pre stages the hunt against the packet log and configuration tree. A lab appliance that only fronts internal traffic gets a lower band with a version note. Inventory and packet logs stay on your hardware; the answer to which NetScaler you take offline before September 30 does not travel through a cloud SaaS.
Sources: Citrix CTX697096, CISA emergency advisory, Cyber Kendra patch coverage, Cybersecurity News confirmation, Windows Forum fixed builds, murrez CVE-2026-88772 PoC