Just two weeks after this site covered a Citrix NetScaler authentication bypass, Citrix is back with a bulletin for two new zero-day vulnerabilities, and this pair is arguably more dangerous. Security researchers at watchTowr first warned on 26 September that unpatched NetScaler remote code execution flaws were being exploited in the wild. Citrix confirmed it the next day, publishing bulletin CTX697096 with fixed builds and two CVE numbers: CVE-2026-88771 and CVE-2026-88772.

If your business, or your IT provider, runs NetScaler ADC or NetScaler Gateway to handle remote access or load balancing, this is not a patch to schedule for next month. Security researchers have been blunt about the urgency, with some publicly advising admins to consider shutting exposed appliances down until they’re patched.

Why this one is different

CVE-2026-88771 is an improper input validation flaw that lets an unauthenticated attacker run arbitrary commands on the appliance, and it affects every NetScaler ADC and Gateway deployment on an affected version, including a completely default configuration. No optional feature needs to be switched on for it to be exploitable, which is what separates this from a lot of the vendor advisories that only bite if you’ve enabled something unusual. CVE-2026-88772 is a memory overflow issue that can lead to remote code execution or denial of service when DTLS is enabled. Both carry a CVSS v4 score of 9.5, which puts them near the top of the severity scale.

NetScaler is the kind of internet-facing appliance that sits at the edge of a network handling VPN and remote access traffic, exactly the position an attacker wants to compromise first. A successful exploit here doesn’t just take down one service, it can hand over a foothold into everything behind it.

What to do this week

Two things settle whether this affects you. First, confirm whether your business runs NetScaler ADC or NetScaler Gateway at all, directly or through a managed IT provider, since it’s easy to assume “someone else handles that” without ever confirming it. Second, if you do run it, check the version against Citrix’s fixed builds: NetScaler ADC and Gateway 14.1-73.37 or 13.1-64.23, or the FIPS and NDcPP equivalents. Anything older needs patching immediately, and if patching can’t happen today, restricting internet exposure to the appliance’s management interface in the meantime is the recommended stopgap.

If an outsourced IT provider manages this for you, send them a direct question today: “Are we running NetScaler, and is CVE-2026-88771 patched?” This is precisely the kind of infrastructure question that’s easy to assume is someone else’s job until an incident proves otherwise, which is the blind spot ongoing external monitoring from a service like KeepSafe exists to catch, flagging exposed or unpatched systems before an attacker finds them first.

The pattern worth noticing

This is the third Citrix NetScaler security event covered on this site this year, and the gap between each one has been shrinking. Internet-facing edge devices, VPN gateways, and load balancers keep turning up as the entry point in real incidents because they’re built to be reachable from the outside, which makes them a permanent target rather than an occasional one. Treating every NetScaler bulletin as background noise is how a business ends up as one of the exposed appliances still running an old build months after researchers already flagged it.

It’s also worth remembering that patching alone doesn’t undo a compromise that already happened. Citrix and independent researchers have both noted that some exploitation may predate the public disclosure, so organisations that find they were running an unpatched, internet-facing appliance should also check logs for signs of prior unauthorised access rather than assuming a clean patch closes the matter entirely.

The takeaway

If NetScaler sits anywhere in your infrastructure, confirm today it’s on a patched build, not next week. If you’re not certain whether you run it, get that answer now rather than after it shows up in an incident report.