The warning now has CVEs, affected builds, and vendor fixes

Citrix's bulletin confirms that exploits of CVE-2026-88771 and CVE-2026-88772 have been observed against unmitigated, customer-managed NetScaler deployments. Both vulnerabilities carry a CVSS v4 base score of 9.5 and can lead to unauthenticated remote code execution.

CVE-2026-88771 is an improper-input-validation flaw that affects all vulnerable NetScaler ADC and NetScaler Gateway deployments, including default configurations. CVE-2026-88772 is a memory-overflow flaw that can produce remote code execution or denial of service when DTLS is enabled; Citrix notes that DTLS is enabled by default on VPN virtual servers.

The operational position has changed

The original article advised defenders to act while the flaws were still unconfirmed publicly and no fixes were available. Citrix has now supplied the authoritative scope and fixed builds. Emergency patching should begin immediately, alongside investigation of the period before remediation.

Match the running appliance to the correct release branch

Deployment branchFixed build or laterDefender note
NetScaler ADC and Gateway 14.114.1-73.37Verify the running build on every active, standby, and disaster-recovery instance.
NetScaler ADC and Gateway 13.113.1-64.23Use Citrix’s current upgrade guidance and test service and authentication dependencies.
NetScaler ADC 14.1-FIPS14.1-73.37 FIPSUse the FIPS-specific package; a similarly numbered standard build is not interchangeable.
NetScaler ADC 13.1-FIPS and 13.1-NDcPP13.1-37.279Confirm the specialised edition and exact installed branch before change approval.

Secure Private Access Hybrid deployments that use NetScaler instances are also affected and require those instances to be upgraded. Citrix says it has updated Citrix-managed cloud services and Citrix-managed Adaptive Authentication; the bulletin's customer action applies to customer-managed appliances.

DTLS matters for one flaw, but disabling it does not resolve both

CVEPreconditionWhat not to assume
CVE-2026-88771No additional feature or non-default configuration is required.A device is not safe merely because VPN, DTLS, or a particular optional role is disabled.
CVE-2026-88772DTLS is enabled; it is on by default for a VPN virtual server unless explicitly disabled.Turning off DTLS may remove this precondition, but it does not remediate CVE-2026-88771 or replace installation of the fixed build.

Citrix's bulletin covers six additional vulnerabilities with other configuration conditions, including HTTP request smuggling and several memory-safety issues. Review the complete bulletin against the appliance's roles rather than treating the release as only a two-CVE update.

Run remediation and compromise assessment as parallel workstreams

  1. 1

    Inventory every customer-managed instance. Include ADC, Gateway, FIPS, NDcPP, Secure Private Access Hybrid, HA peers, warm standbys, disaster-recovery systems, templates, and appliances that are powered off but may return to service.

  2. 2

    Preserve evidence before disruptive actions where practical. Retain central authentication, VPN, firewall, DNS, proxy, network-flow, management, and application logs. Coordinate volatile collection or snapshots with incident responders because some collection and upgrade actions can change the evidence.

  3. 3

    Install and verify the correct fixed build. Use Citrix's package for the exact release and edition, follow the supported HA sequence, test application delivery and authentication, and confirm the running version on each node after restart.

  4. 4

    Assess the pre-patch exposure window. Review unexpected administrator sessions, configuration changes, unfamiliar files or processes, new accounts, suspicious child activity, abnormal outbound traffic, and anomalies in connected identity and application systems.

  5. 5

    Treat indicator checks as evidence, not proof of safety. Use Citrix's current detection guidance and support channels, but do not let one negative scan overrule unexplained activity or missing telemetry on an internet-facing appliance.

  6. 6

    Recover trust when compromise is suspected. Isolate the appliance, investigate reachable systems, rotate affected credentials and stored secrets, review certificates and authentication integrations, and rebuild from current firmware plus a known-good configuration when required.

Patching answers the exposure question, not the integrity question

Teams should track two separate completion statements: every affected appliance is running a fixed build, and the organisation has a documented basis for its confidence that exposed systems and connected trust relationships remain intact. The first can be verified from version and configuration evidence. The second depends on the quality of retained telemetry, observed anomalies, forensic work, and recovery decisions.

The public sources confirm exploitation but do not establish a victim count, identify the operators, or show that every exposed device was compromised. Keep those uncertainties visible in executive and incident reporting.

How this analysis changed as the disclosure matured

The original analysis was prepared from a Cyber Security News report, watchTowr's public warning, Tenable's pre-disclosure FAQ, and Citrix's bulletin for separate August vulnerabilities. A new Cyber Security Hub newsletter surfaced Citrix's 27 September advisory. Threat Field Notes reviewed that advisory and CERT-EU's response, then replaced the earlier provisional guidance with the confirmed CVEs, affected branches, fixed builds, and configuration conditions while preserving the distinction between remediation and compromise assessment.