• Sources: analysis, BOD 26-04, CISA KEV catalog, coverage, discussion, discussion
  • Summary: CVE-2026-88771 affects all NetScaler ADC and Gateway deployments in their default configurations and lets an unauthenticated attacker run commands as root, while CVE-2026-88772 is a memory overflow reachable when DTLS is enabled, which Citrix notes is the default on VPN virtual servers, and both are rated CVSS 9.5 among the eight CVEs in bulletin CTX697096. watchTowr traces CVE-2026-88771 to a Perl script that interpolated attacker-controlled log text into a backtick find command, so any endpoint or port that writes a request field such as a login name or User-Agent into the appliance log can reach it, and nearly everything on a NetScaler runs as root. Fixed builds are 14.1-73.37, 13.1-64.23, 14.1-FIPS 14.1-73.37, and 13.1-37.279 for 13.1-FIPS and 13.1-NDcPP, and because community.citrix.com returned 403 and support.citrix.com rendered only a JavaScript shell, that table rests on watchTowr's transcription of the bulletin rather than on the vendor page.
  • Why it matters: Two unauthenticated remote code execution paths are being exploited on an appliance that terminates remote access, Shadowserver tracks over 23,000 IP addresses with NetScaler fingerprints, and patching alone is not sufficient because the appliance may already be compromised, which is why the 2026-09-30 date follows from the KEV listing under BOD 26-04's three-day timeline for publicly exposed assets, a timeline that also requires a forensic triage of the asset rather than remediation alone.
  • Follow-up: Watch for the Citrix bulletin and the NVD entries becoming directly fetchable, which would confirm the eight-CVE table and the fixed builds against the vendor rather than a third-party transcription, and for published indicators of compromise covering the pre-patch exploitation window.

send feedback on this story