Citrix NetScaler Zero-Days Under Active Attack; CISA Sets September 30 Patch Deadline
Citrix published a security bulletin (CTX697096) covering eight newly disclosed vulnerabilities in its NetScaler ADC and NetScaler Gateway products, the appliances many organizations use as the front door for VPN and application delivery. Two of them, CVE-2026-88771 and CVE-2026-88772, are rated critical at 9.5 under CVSS v4.0 and both allow remote code execution without authentication. Citrix has confirmed both are being exploited in the wild, meaning they were used as zero-days before a fix existed.
The technical details matter for defenders. CVE-2026-88771 is an input validation flaw that lets an unauthenticated attacker run arbitrary commands on the appliance. CVE-2026-88772 is a memory overflow that can cause remote code execution or denial of service whenever DTLS is enabled — and DTLS is on by default for virtual VPN servers, so a large share of deployments are exposed without any configuration mistake. A third critical flaw, CVE-2026-88773 (9.3), enables HTTP request smuggling that can bypass front-end security controls.
CISA added both exploited flaws to its Known Exploited Vulnerabilities catalog on September 27, issued an alert the same day stating that threat actors are exploiting them globally, and gave federal civilian agencies until Wednesday, September 30, 2026 to patch and check for signs of compromise. CISA's advice: if you suspect compromise, preserve forensic evidence before patching, because updating can destroy the visibility you need for incident response.
This is a demonstrated, ongoing attack — not a theoretical risk. Citrix has released fixed builds (including 14.1-73.37 and 13.1-64.23, plus fixed FIPS/NDcPP builds) that address all eight vulnerabilities, and there is no workaround. The complication is operational: patching NetScaler appliances can require downtime, which is exactly why CISA attached a hard deadline rather than leaving it to prioritization.
Why it matters: NetScaler sits at the network edge for enterprises, universities, and government networks, and edge appliances have become a preferred initial-access target for ransomware and espionage groups. If you operate one, the practical checklist is short — review Citrix's indicators of compromise in NetScaler Console, forensically triage before updating if compromise is suspected, and get to a fixed build before September 30.
Source: CISA. This article summarizes the linked reporting and distinguishes announced plans from demonstrated results.