Citrix released emergency updates on September 27 for eight vulnerabilities in customer-managed NetScaler ADC and NetScaler Gateway appliances. Two of them, CVE-2026-88771 and CVE-2026-88772, were already being exploited on unmitigated systems and can independently lead to remote code execution without authentication.
The first flaw affects every NetScaler ADC and Gateway deployment, including default configurations. The second is exposed when Datagram Transport Layer Security, or DTLS, is enabled; DTLS is on by default for VPN virtual servers. Both carry a 9.5 CVSS v4.0 score. The U.S. Cybersecurity and Infrastructure Security Agency added both to its Known Exploited Vulnerabilities catalog and set a September 30 remediation date for federal civilian agencies.
For administrators, this is not a patch-only event. Exploitation was observed before fixes became available, and researchers have documented an attack chain that plants an internet-accessible PHP web shell. Any affected appliance that was exposed should be checked for compromise after evidence is preserved, even if it has now been upgraded.

Which NetScaler builds need an update
Citrix’s security update lists the following fixed versions. Install the named build or a later release in the same branch:
- NetScaler ADC and NetScaler Gateway 14.1: 14.1-73.37 or later
- NetScaler ADC and NetScaler Gateway 13.1: 13.1-64.23 or later
- NetScaler ADC 14.1-FIPS: 14.1-73.37 FIPS or later
- NetScaler ADC 13.1-FIPS and 13.1-NDcPP: 13.1-37.279 or later
There is an important operational caveat for the 13.1 branch. Citrix warns that build 13.1-64.23 can enter a reboot loop on systems with configured NetScaler variables. Run show ns variable before the upgrade. If it returns a list of variables, plan for 13.1-64.24 rather than stopping at 13.1-64.23. Citrix also notes that NetScaler Console may temporarily mislabel 13.1-64.23 as vulnerable.
The bulletin applies to customer-managed appliances, including Secure Private Access Hybrid deployments that use NetScaler instances. Citrix-managed Gateway Service and Adaptive Authentication received updates from Citrix.
How CVE-2026-88771 becomes command execution
CERT-EU’s technical investigation shows why CVE-2026-88771 deserves a compromise hunt. The attack abuses logging and a maintenance script rather than a conventional application endpoint.
Attackers first send HTTP requests with Base64-encoded shell commands in the User-Agent field, placing the payload in NetScaler’s HTTP logs. In parallel, they inject a crafted entry into authentication logs containing the string PPE NSPPE missed too many heartbeats and a command that extracts, decodes and executes the payload.
The vulnerable ns_monuploadd_err.pl script searches NetScaler logs for that heartbeat message, takes the last matching result and interpolates it into a shell command without adequate quoting. That explains the repeated requests seen during exploitation: the attacker wants the malicious entry to remain the newest match when the script runs.
Observed post-compromise commands modified /etc/httpd.conf to enable PHP and delivered a web shell into a path reachable from the internet. That gives an intruder persistence on an edge appliance positioned between remote users and internal applications. A successful patch does not remove that access or prove the appliance was clean beforehand.
CVE-2026-88772 adds a second route to RCE
CVE-2026-88772 is a memory-overflow flaw that can cause remote code execution or denial of service when DTLS is enabled. VPN virtual servers enable DTLS by default unless administrators explicitly turn it off, so the absence of a dedicated DTLS virtual server is not enough to rule out exposure.
Citrix recommends inspecting the saved configuration. A VPN virtual server line without -dtls OFF meets the precondition, as do explicit DTLS VPN or load-balancing virtual servers. NetScaler Console can identify affected instances, but Citrix says the advisory scan may take several hours unless an administrator starts an on-demand scan.
Preserve evidence before changing the appliance
Where exploitation is possible, the order of operations matters. The Canadian Centre for Cyber Security recommends retaining evidence before shutdown, reboot, patching or rebuilding when operations allow it.
- Record time settings. Document the appliance time, timezone and NTP configuration so local events can be correlated with firewall, DNS, identity and endpoint telemetry.
- Capture the system. Snapshot virtual NetScaler VPX instances and generate a technical support bundle. Preserve local logs, NetScaler Console records and remote syslog data.
- Contain exposure. Isolate an appliance with suspicious findings. For a critical internet-facing system, weigh temporary shutdown against the operational impact rather than leaving an exposed build online while an investigation waits.
- Upgrade to a fixed build. Patch every affected customer-managed appliance, including systems that do not use DTLS because CVE-2026-88771 has no feature precondition.
- Run compromise checks. Use the NetScaler Console indicator-of-compromise scan where available, then supplement it with manual log and file-integrity review.
- Recover from trusted state. If compromise is confirmed or cannot be bounded, rebuild from known-good software and configuration. Reset exposed credentials, invalidate sessions and replace certificates as the investigation requires.
Citrix’s compromise-response guidance also calls for reviewing running processes, active network connections, startup scripts, scheduled tasks, web directories and crash-dump locations. Security teams should preserve suspicious files before removing them.
What to hunt for now
CERT-EU recommends searching authentication logs for PPE missed too many heartbeats, then correlating those events with HTTP requests containing INDEX and Base64 data. Defenders should also search User-Agent fields for encoded payloads and verify the integrity of /etc/httpd.conf.
Those checks are starting points, not proof of absence. Citrix cautions that its generic indicator set cannot cover every technique and that attackers can change infrastructure and persistence methods. Forwarding NetScaler logs to an external SIEM is especially valuable because an attacker with control of the appliance may alter local evidence.
NetScaler Console’s IoC scan requires its telemetry channel and is available through the Security Advisory workflow in the service and in on-premises Console deployments with Cloud Connect starting at version 14.1-73.36. Organizations that do not use Console can request the generic indicators through Citrix Support.
The other six flaws still matter
The emergency release also fixes HTTP request smuggling in CVE-2026-88773, a URL-normalization policy bypass in CVE-2026-88774, three memory-overflow issues in CVE-2026-88775 through CVE-2026-88777, and predictable TCP initial sequence numbers in CVE-2026-88778. Their exposure depends on enabled HTTP, gateway, AAA, Oracle load-balancing, non-HTTP Layer 7 or TCP configurations.
Administrators using TCP services should verify Enhanced ISN Generation with show ns tcpparam. The vulnerable condition exists when supported TCP virtual-server types are configured and the command reports Enhanced ISN Generation: DISABLED.
CISA’s three-day federal deadline reflects the combination of active exploitation, internet exposure and post-exploitation control, not the CVSS numbers alone. Private organizations are not bound by that date, but it is a sensible upper limit for triage. An internet-facing NetScaler on an affected build should be handled as a potential incident now, not placed into the next routine maintenance window.