Trending News

Industry News - Security - Technology Insights

Two Critical NetScaler Zero-Days Are Being Exploited Right Now

Patching Alone Won’t Save You

On September 27, 2026, Citrix disclosed and patched two critical zero-day vulnerabilities in NetScaler ADC and NetScaler Gateway. Both carry a CVSS score of 9.5. Both are already being exploited in the wild. And CISA added both to its Known Exploited Vulnerabilities catalog the same day it happened.

If your organization runs NetScaler in front of remote-access or critical applications, and most regulated organizations do, this is not a “get to it next maintenance window” event. But here is the part that gets lost in the rush to patch: applying the update is necessary, and it is not sufficient. An appliance that sits on the internet edge and may already have been compromised does not become trustworthy again the moment you install a new build.

What was actually disclosed

CVE-2026-88771 (CVSS 9.5) is an improper-input-validation flaw that lets an unauthenticated attacker run arbitrary commands. It affects the default configuration, there is no exotic setup required to be exposed.

CVE-2026-88772 (CVSS 9.5) is a memory-overflow flaw that can lead to remote code execution or denial of service when DTLS is enabled, which is the default for VPN virtual servers.

The fixes ship in NetScaler ADC and Gateway builds 14.1-73.37 and 13.1-64.23 and later, with corresponding FIPS and NDcPP builds, documented in Citrix bulletin CTX697096. One detail deserves emphasis: appliances that were already patched for the earlier CVE-2026-19490 — the authentication-bypass flaw added to CISA’s catalog on September 9, remain vulnerable to these new zero-days unless they are running the latest fixed builds. Being current a month ago does not mean you are current today.

Why the edge appliance is the wrong place to get comfortable

NetScaler ADC and Gateway do an enormous amount of quiet, trusted work: they terminate sessions, broker authentication, and stand between the public internet and the applications your business runs on. That is exactly what makes them a prize target. A remote code execution flaw on that box is not a single-server problem — it is a foothold with a view of everything behind it.

This is where an architecture-first mindset separates a real response from a checkbox. When a device that holds session secrets and authentication material may have been reachable by an attacker before you patched, the honest question is not “have we updated?” It is “what could an attacker have taken while the door was open, and what do we do about it?”

The response that actually restores trust

For organizations in credit unions, healthcare, financial services, government, and education where a compromised access gateway can become a reportable incident under HIPAA, PCI, GLBA, or NCUA expectations, a disciplined response looks like this:

  • Confirm real exposure, not assumed exposure. Inventory every NetScaler instance, its exact build, and whether it is internet-facing. Shadow appliances and forgotten test gateways are where these events turn into breaches.
  • Patch to the fixed builds in CTX697096 — and verify the version after, rather than trusting the change ticket.
  • Assume the secrets are burned. Rotate credentials, session keys, and certificates that lived on or passed through the appliance. If an attacker had code execution, the material on that box is no longer private.
  • Hunt before you declare victory. Review logs for signs of pre-patch exploitation and unexpected sessions. Zero-days are, by definition, exploited before the fix exists.
  • Reduce the blast radius for next time. Segment what the gateway can reach, enforce least privilege on the identities behind it, and put a Zero Trust boundary between the edge and your critical systems.

This is a Zero Trust story, not a patching story

The uncomfortable lesson of every NetScaler event over the past few years is the same: a single trusted appliance should never be the thing standing between an attacker and your entire environment. Zero Trust is not a product you buy after the fact — it is an architecture that assumes the edge will eventually be breached and limits what that breach can touch. Organizations that had already segmented, enforced least privilege, and instrumented their identity layer are having a very different week than those who are discovering their NetScaler inventory for the first time.

Business outcomes come before products. The outcome here is not “we installed a patch.” It is “we can demonstrate, to an auditor and to ourselves, that this appliance is trustworthy again and that a future edge compromise cannot become an enterprise compromise.”

Where LKMethod fits

As a Citrix Partner and Microsoft Cloud Solution Provider, LKMethod helps regulated organizations respond to events like this without guesswork, confirming exposure, remediating to fixed builds, rotating what needs rotating, and then closing the architectural gaps that let an edge flaw become a full-environment risk. We advise; we don’t just resell.

If you run NetScaler and want a second set of eyes on your exposure or a Zero Trust architecture review so the next zero-day is a patch, not a crisis, talk to our advisory team about a NetScaler exposure check and Zero Trust assessment.