Analysis · Exposure
NetScaler: three exploited flaws in eight days
From September 27 to October 4, 2026, three NetScaler flaws entered the KEV catalog. Fixed builds, patch cadence, and the edge inventory it takes.
By Sentrix · Published 2026-10-05
On September 27, 2026, Citrix published a bulletin covering eight vulnerabilities in NetScaler ADC and NetScaler Gateway, two of them already exploited. On October 3, a third one, also exploited, followed. In eight days, three NetScaler flaws entered CISA's KEV catalog, and the build that fixed the first two was no longer enough for the third.
What the sources say
The September 27 bulletin (CTX697096). It covers CVE-2026-88771 through CVE-2026-88778 on customer-managed appliances. CVE-2026-88771 lets an unauthenticated attacker run arbitrary commands through improper input validation, including in the default configuration. CVE-2026-88772 is a memory overflow that leads to code execution or denial of service when DTLS is enabled. Both are rated 9.5 under CVSS 4.0. The fixed builds are 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS and 13.1-37.279 FIPS and NDcPP. Citrix offers no workaround, and the 12.1 and 13.0 branches, which are end of life, will not get a fix.
CISA's alert, the same day. CISA added both CVEs to the KEV catalog and said they "can independently enable remote code execution". It wrote: "Threat actors are actively exploiting these vulnerabilities globally". It asks organizations to check for indicators of compromise before patching and to preserve forensic evidence, because updating can remove forensic visibility. The alert, updated on October 2, points to SIGMA detection rules.
The October 3 bulletin (CTX697174). CVE-2026-88779 is a memory overflow that leads to denial of service when the appliance is configured as a SAML service provider or identity provider. It is rated 8.7 under CVSS 4.0. The fixed builds are 14.1-73.41 and 13.1-64.28, with their FIPS variants. CISA added it to the KEV catalog on October 4, with a deadline of October 7 for US federal civilian agencies. The Canadian Centre for Cyber Security published advisory AV26-996 on October 5.
Why it matters
The first lesson fits in two build numbers. A team that installed 14.1-73.37 over the weekend of September 27 did the right thing. Eight days later, that was no longer enough for its SAML appliances, which needed 14.1-73.41. An emergency patch is not the end of a vendor incident; it is often the start of a series. Researchers look hard at a product that has just shipped two critical flaws.
The second lesson is about order. CISA asks organizations to hunt for a compromise before patching. An edge appliance exploited before the fix can carry persistent access that the update does not remove. Patching without looking closes the door with the intruder inside.
The third lesson is about inventory. CVE-2026-88779 only affects appliances configured for SAML, and CVE-2026-88772 only those with DTLS enabled. Knowing you have "some NetScalers" is not enough: you need to know which ones, on which build, with which configuration, exposed to what. For a managed service provider, the question multiplies by the number of clients.
What we think at Sentrix
Edge appliances keep coming back to the KEV catalog, as we noted in 28 exploited vulnerabilities in thirteen days. In order:
- Keep the edge inventory down to the configuration. Build, branch, SAML, DTLS, internet exposure, owner. This is what the CTEM continuous exposure module keeps current, the scoping and discovery stages described in the five stages of CTEM.
- Decide when an entry lands in the KEV catalog, not at the monthly cycle. The method is in prioritizing patches with the KEV catalog.
- Capture, hunt, then patch. A procedure written in advance: capture the state, hunt for indicators, update, hunt again after the update.
- Come back to the appliance after every bulletin from the same vendor. A product that just received a critical fix deserves closer watch for the following weeks.
- Take end-of-life versions off direct exposure. With no fix and no workaround, only migration or removal remains.
- For an MSP or MSSP: one inventory across all clients. A question like "who has a NetScaler 14.1 in SAML below 73.41?" should get an answer in minutes, not days.
Our vulnerability and patch management service applies this method, from inventory to proof of remediation.
The next step
List your NetScaler appliances with, for each one, the installed build, the SAML and DTLS configuration, and the date of the last hunt for indicators of compromise. Any line below 14.1-73.41 or 13.1-64.28 in SAML, or on a 12.1 or 13.0 branch, needs action today. If you want to run the exercise with us, contact us.
Sources
- CISA, Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway (September 27, 2026)
- Citrix, Security Bulletin for CVE-2026-88771 through CVE-2026-88778 (CTX697096)
- Citrix, Security Bulletin for CVE-2026-88779 (CTX697174)
- CISA, CISA Adds One Known Exploited Vulnerability to Catalog (October 4, 2026)
- Canadian Centre for Cyber Security, Alerts and advisories (AV26-996, October 5, 2026)
Frequently asked questions
- I installed 14.1-73.37 after September 27. Am I up to date?
- Not necessarily. Build 14.1-73.37 fixes CVE-2026-88771 and CVE-2026-88772, but not CVE-2026-88779, published on October 3. If the appliance is configured as a SAML service provider or identity provider, it needs 14.1-73.41 (or 13.1-64.28 on the 13.1 branch). Check the SAML configuration of each appliance before concluding.
- Should I patch right away or hunt for a compromise first?
- Both, in that order. CISA asks organizations to preserve forensic evidence before applying updates, because updating can remove forensic visibility. Capture the appliance state, hunt for indicators of compromise with the SIGMA rules CISA published, then update without delay. A flaw exploited globally does not leave weeks to investigate.
- What about a NetScaler on 13.0 or 12.1?
- Those versions are end of life and Citrix will not ship a fix for them, and bulletin CTX697096 offers no workaround. An internet-facing appliance on either version must move to a supported branch or come off direct exposure. Record the decision and its date in the risk register.
Let's talk about your compliance program.
Last updated: 2026-10-05
