Citrix has confirmed active exploitation of two critical zero-day vulnerabilities in NetScaler ADC and Gateway appliances, both scoring 9.5 CVSS and affecting default configurations. Enterprises face immediate risk, with Citrix and CISA urging rapid patching and forensic checks.
Two zero-day flaws in Citrix NetScaler ADC and Gateway are under attack. Hackers are hitting unpatched systems and skipping authentication. Both bugs carry a 9.5 CVSS score. They strike at the edge of enterprise networks. Default settings make many devices easy targets. CERT-EU warns that CVE-2026-88771 and CVE-2026-88772 are being used in real attacks. CVE-2026-88772 is especially dangerous for devices with Datagram Transport Layer Security (DTLS) turned on. That's the default for VPN vServers.
Citrix published security bulletin CTX697096 on 27 September 2026. It lists eight vulnerabilities. But CVE-2026-88771 and CVE-2026-88772 are the ones causing panic. The US Cybersecurity and Infrastructure Security Agency (CISA) has put both on its Known Exploited Vulnerabilities list. Attacks are happening now. The National Cyber Security Centre of New Zealand has also issued an alert. Affected versions include NetScaler ADC and Gateway 14.1 before 14.1-73.37 and 13.1 before 13.1-64.23. The threat is global.
Perimeter breach risk for Indian enterprises
Indian IT exporters, banks, and global capability centers face real danger. NetScaler appliances sit on the network edge. They handle VPN, load balancing, and user logins. CVE-2026-88771 needs no authentication and no special setup. Any unpatched, internet-facing device is at risk. CERT-EU and NCSC NZ both stress that CVE-2026-88771 can hit standard NetScaler platforms. CVE-2026-88772 is even riskier for VPN perimeters because of DTLS.
Remote access gear is a prime target. If attackers get in before a patch, they can move deeper into the network. Security teams must patch fast. But they also need to check if attackers already broke in. HKCERT's analysis shows CVE-2026-88771 lets hackers run any command without logging in. CVE-2026-88772 is a memory overflow. It can lead to remote code execution or denial of service. The risk is real.
CERT-EU has confirmed that both CVE-2026-88771 and CVE-2026-88772 are being exploited in the wild, with a CVSS score of 9.5 each. CVE-2026-88772 specifically affects devices with DTLS enabled, which is the default on VPN vServer.
Inside the vulnerabilities: what makes these zero-days so dangerous
CVE-2026-88771 comes from bad input checks. Hackers can run commands on NetScaler ADC or Gateway without logging in. No extra features or tweaks are needed. The attack surface is wide. Only fast action can stop it. National cybersecurity agencies, including the Australian Cyber Security Centre, confirm these findings. They have issued their own alerts. The problem is global.
CVE-2026-88772 is a DTLS memory overflow. DTLS is on by default for VPN virtual servers. Most VPN gateways are exposed unless DTLS was turned off by hand. This bug can let attackers run code or crash the device. Companies that never changed their VPN vServer settings are wide open. The default state is dangerous.
Patch now-but don't skip forensic checks
Citrix has released fixed versions: 14.1-73.37 and up for NetScaler ADC and Gateway 14.1, and 13.1-64.23 and up for 13.1. FIPS and NDcPP editions have their own patches. There is no workaround. Only a full upgrade will block attackers. European and Asia-Pacific regulators agree. CERT-EU and the Australian Cyber Security Centre both say every affected system needs to be patched now.
Patching is not enough. Teams must check for signs of compromise before updating. Attacks started before fixes were out. Forensic evidence-like logs and memory dumps-should be saved before any reboot or upgrade. The Dutch NCSC says to keep these records before patching. Don't skip this step.
Citrix offers IOC scanning in NetScaler Console version 14.1-73.36 or later, if telemetry is on. But a clean scan does not mean you are safe. Not all attack methods are covered by current indicators. Italian companies can get more advice from the Agenzia per la Cybersicurezza Nazionale. They post updates and best practices.
Which NetScaler versions are at risk?
The bugs hit NetScaler ADC and Gateway 14.1 before 14.1-73.37, 13.1 before 13.1-64.23, 14.1-FIPS before 14.1-73.37 FIPS, and 13.1-FIPS/NDcPP before 13.1-37.279. Only customer-managed appliances are affected. Citrix-managed cloud services are patched by Cloud Software Group. These version numbers match those listed by NCSC New Zealand and CERT-EU. Companies can check their deployments against these lists.
Action plan for Indian CIOs and security teams
Indian companies must find any exposed NetScaler appliances running affected builds. If compromise is possible, save forensic evidence and check for indicators before upgrading. Citrix is clear: patching is the only fix. Waiting raises the risk of hidden breaches.
Recent attacks, like those in previous investigations, show how fast attackers can steal credentials after getting in. The NetScaler zero-days are just as dangerous. Default settings make things worse.
Citrix's bulletin also lists six more bugs. These include HTTP request smuggling, memory overflows, policy bypass, and TCP sequence-number prediction. But the two zero-days are already being used in real attacks. Every company using NetScaler for secure access must act now.
Patching without forensic checks is risky. Teams may miss the real damage. The lesson is simple. In the age of zero-days, security means more than just patching. You have to check who got in before you closed the door. Only fast patching and careful compromise checks can bring back trust in the network edge.