Citrix Patches NetScaler Zero-Days CVE-2026-88771, -88772
Citrix patched CVE-2026-88771 and CVE-2026-88772 in NetScaler ADC and Gateway. CISA orders federal agencies to apply by September 30.

Citrix has confirmed and patched the two NetScaler zero-days that were being exploited before fixes existed. As reported by SecurityWeek on September 28, 2026, the flaws are now tracked as CVE-2026-88771 and CVE-2026-88772.
CVE-2026-88771 is an improper input validation flaw in NetScaler ADC and Gateway that allows unauthenticated remote code execution. CVE-2026-88772 is a memory buffer mishandling flaw in the same products that can enable remote code execution or denial of service. Both were added to CISA’s Known Exploited Vulnerabilities catalog on September 27, 2026.
What to do now
Patch immediately. CISA has ordered U.S. federal agencies to apply fixes by September 30, which is also the KEV catalog due date. For everyone else, confirmed in-the-wild exploitation makes this a P1 regardless of sector.
Check the Citrix security advisory for the specific patched build versions before applying. Citrix’s official bulletin is the authoritative source for build numbers; do not rely on press coverage for that detail.
Before patching, check for signs of compromise. These flaws were exploited before CVE IDs were assigned, so attackers had time before defenders knew what to look for. As covered in yesterday’s initial report, watchTowr’s forensic guidance identifies artifacts to inspect: unusual administrative sessions, unexpected configuration changes, and web shell indicators. Doing this while the attacker footprint is fresher will produce more reliable results than running the same checks post-patch.
If your appliances are not yet current on CVE-2026-19490, the NetScaler auth bypass patched in August, resolve that at the same time. Running behind on two open NetScaler CVEs is compounding exposure.
Current status
- CVE-2026-88771: high severity, improper input validation, unauthenticated RCE
- CVE-2026-88772: high severity, memory buffer mishandling, RCE or DoS
- Affected: Citrix NetScaler ADC and NetScaler Gateway (check Citrix advisory for version ranges)
- Patch available: yes, as of September 28, 2026
- Exploitation: active in the wild, confirmed by watchTowr; CISA KEV listed
- Federal patching deadline: September 30, 2026
Context
NetScaler has appeared in CISA’s KEV catalog three times in six weeks. CVE-2026-8452 was listed in late August. CVE-2026-19490 was patched in August and confirmed exploited by early September. Organizations running NetScaler should treat the appliance fleet as a high-priority recurring target and stay subscribed to Citrix’s security advisory feed directly.
- [ HIGH ]CVE-2026-88771Citrix NetScaler ADC/Gateway Unauthenticated RCE via Input Validation Flaw
- [ HIGH ]CVE-2026-88772Citrix NetScaler ADC/Gateway RCE via Memory Buffer Mishandling
Found this useful? Share it.


