Citrix published bulletin CTX697096 on September 27 confirming that two remote code execution bugs in NetScaler ADC and NetScaler Gateway, CVE-2026-88771 and CVE-2026-88772, were being exploited before a patch existed. Both score 9.5 on CVSS 4.0. Neither needs credentials. The first one works against a default configuration. And according to Kevin Beaumont, attackers had been using them for most of September.

If you run a NetScaler that answers on a public IP, the order of operations today is: preserve logs, check for compromise, then upgrade. Not the other way round. The reason is in the second section.

What Citrix shipped, and when

The bulletin covers eight CVEs. Two are the exploited zero-days. The other six range from 7.0 to 9.3 and include an HTTP request smuggling bug (CVE-2026-88773, scored 9.3), a policy bypass through URL expressions, three memory overflows in different modules, and predictable TCP sequence numbers. Rapid7's writeup has the full table. None of those six has been seen in attacks yet. That will change now that fixed builds exist and can be diffed against the old ones.

Fixed builds are 14.1-73.37 and 13.1-64.23, plus 14.1-73.37 FIPS and 13.1-37.279 for the FIPS and NDcPP variants. There is no workaround. Citrix's only mitigation for anyone who can't patch is to "reduce Internet-facing exposure where operationally feasible," which is a polite way of saying pull it off the internet.

The 13.1 branch hit end of maintenance on September 15, twelve days before the bulletin. Citrix patched it anyway. If you're on 12.1 or 13.0, there is no fix and no promise of one. Those boxes are done.

Most of the timeline happened before the vendor said a word. Help Net Security and BleepingComputer report the same sequence. Posts on the r/Citrix subreddit on September 25 described odd behavior on appliances. On September 26 watchTowr publicly warned of "rumors that multiple unpatched Citrix NetScaler RCE vulnerabilities are circulating in the wild," and Beaumont confirmed the exploitation was real. The Dutch NCSC gave organizations in the Netherlands advance notice over the same weekend, and IT providers and national CERTs were phoning customers directly. Citrix's bulletin landed on September 27. CISA added both CVEs to the Known Exploited Vulnerabilities catalog the same day, with a federal remediation deadline of September 30.

Three days. For an appliance upgrade that CISA's own alert describes as complex and likely to require downtime.

Patching does not remove the attacker

Put this at the top of any internal ticket. Citrix's guidance says upgrading does not remove anyone already on the box. Anything dropped during the exposure window survives the upgrade.

And the exposure window was long. Beaumont's findings, as summarized by Help Net Security, describe attackers deploying a different webshell to each compromised appliance and then running cleanup commands to delete the artifacts they left behind. A webshell that differs on every device defeats hash matching. Deleted artifacts defeat the log review most teams would reach for first. He assesses the activity as probably aligned with a nation state.

Citrix has published an indicator of compromise scan through NetScaler Console, version 14.1-73.36 or later. Beaumont notes one limit: the scan reads the appliance's own logs, and NetScaler rotates those. If the intrusion happened three weeks ago on a busy box, the evidence may be gone. His advice is to search whatever SIEM you ship logs to for base64 strings appearing directly after the User-Agent field with no space, and for log lines containing "pitboss" followed by "IFS" or "b64decode".

CISA's alert says the same thing in bureaucratic language: preserve forensic evidence before applying updates, because the update may destroy it. Take a support bundle. Copy the logs off. Then upgrade.

If the scan or the SIEM search turns up anything, the upgrade is not the remediation. Rebuild the appliance from a clean image, restore configuration from a backup taken before September, and rotate every credential and certificate the box ever held. A NetScaler Gateway terminates VPN sessions and often sits in front of an identity provider. Anyone who owned it for three weeks has had a comfortable seat.

Who is exposed

Shadowserver counts more than 23,000 NetScaler instances reachable from the internet, around 22,000 of them ADC and about 1,500 Gateway. Cybernews reports the country split: roughly 8,800 in the United States, 3,000 in Germany, 1,000 in the Netherlands. That is exposure, not a count of vulnerable or compromised boxes. But CVE-2026-88771 needs no special feature enabled, so the vulnerable share of that population is whatever fraction hadn't upgraded, which on September 27 was all of it.

CVE-2026-88772 is narrower. It needs DTLS enabled, and DTLS is on by default on VPN virtual servers. So for Gateway deployments both bugs apply out of the box.

Both bugs require only network access, per the Rapid7 and watchTowr writeups. There is no user interaction, no phishing step, no stolen session. A scanner finds the login page and the exploit runs. That makes the exposure count the triage number, and 8,800 US boxes is a bad one.

Third exploited edge appliance in two weeks

I wrote about the F5 BIG-IP APM zero-day on September 24 and the Cisco ISE bugs on September 19. NetScaler makes three vendors of perimeter appliances with exploited zero-days in two weeks. The pattern is the same each time. The box sits on a public IP, terminates TLS, holds credentials, and runs a vendor firmware image the customer cannot inspect or instrument. Attackers have worked out that this is the softest target with the most value on most networks. Vendors have not worked out how to ship these products with telemetry that lets a customer know they've been hit without waiting for the vendor to tell them.

NetScaler in particular has a history. CitrixBleed in 2023 (CVE-2023-4966) and its 2025 sequel both ended in ransomware. watchTowr's FAQ notes that NetScaler flaws have been exploited by state groups and by ransomware operators. The usual order is state groups first, while the exploit is private, then ransomware crews once it leaks or gets reconstructed from the patch. We are in the first phase. The second phase follows the patch by days, not months.

My own take on the product category is unchanged from the F5 post. If a device's only job is to sit at the edge and authenticate people, and its vendor can't tell you it was compromised until three weeks after the fact, that device should be behind something else. A cloud proxy, a bastion, an allowlist, anything that means a scanner doesn't land on the login page. Most shops won't do that. Upgrades are hard enough.

Prediction: the first public ransomware incident traced to CVE-2026-88771 lands before October 15, and it hits an organization that upgraded on time but never checked its logs.