A Private Warning From The Netherlands, Then A Public Scramble
The Dutch national cyber agency NCSC-NL told a small group of NetScaler operators to shut their appliances down before Citrix said anything in public. That is how the third Citrix NetScaler zero-day emergency of the quarter started, on Saturday 26 September 2026, a full day before Citrix's own security bulletin CTX697096 went live.
By Sunday, Citrix had confirmed active exploitation of two new vulnerabilities, CVE-2026-88771 and CVE-2026-88772, and shipped fixed builds. The US Cybersecurity and Infrastructure Security Agency (CISA) added both to its Known Exploited Vulnerabilities catalog the same day and gave its own federal agencies until Tuesday 30 September to patch every exposed appliance.
This is not NetScaler's first emergency of 2026. It is the third in ninety days.
What CVE-2026-88771 And CVE-2026-88772 Actually Do
CVE-2026-88771 is an improper input validation flaw that lets an attacker with no credentials at all run arbitrary commands on the appliance, and Citrix's own advisory rates it 9.5 out of 10 on the CVSS scale. It works against a default NetScaler configuration, no optional feature has to be switched on first.
CVE-2026-88772 is a memory overflow bug that can crash the appliance or hand an attacker remote code execution, but only on systems where DTLS is enabled, which is the default setting for every NetScaler used as a VPN gateway. Between the two flaws, almost every common NetScaler deployment pattern is covered.
Security researchers at watchTowr, who published the technical breakdown, confirmed both flaws were exploited as true zero-days: attackers had working exploits in hand before any fixed build existed for administrators to install.
Ninety Days, Three Emergencies
| CVE | Disclosed | Flaw type | Exploited before patch |
|---|---|---|---|
| CVE-2026-8451 (CitrixBleed 3) | 7 July 2026 | Session-token leak via the SAML login parser | Yes, within about a day of the patch shipping |
| CVE-2026-8452 | Patched 30 June, public proof-of-concept in August | Unauthenticated remote code execution | Yes, once the proof-of-concept became public |
| CVE-2026-88771 / CVE-2026-88772 | 27 September 2026 | Unauthenticated RCE / memory overflow | Yes, as a genuine zero-day, before any fix existed |
Citrix NetScaler has now needed three unrelated emergency-patch cycles inside a single quarter, and no two of them share a root cause.
Every row in that table ends the same way: attackers moving faster than the fix. A vendor whose flagship appliance produces that pattern three times running is not having bad luck, it is running a product line under sustained active attack.
Twenty-Three Thousand Appliances, Two Warnings Already Ignored
Shadowserver's internet-wide scan still counts roughly 23,000 NetScaler ADC and Gateway instances reachable from the public internet, split between about 22,000 ADC appliances and more than 1,500 Gateway instances.
That is largely the same population CISA and Citrix asked administrators to patch in July and again in August. A meaningful share of it did not move fast enough either time, which is the actual reason a third zero-day lands as hard as it does: the exposed surface never really shrank between emergencies.
What To Do If You Run NetScaler
Patch to the fixed builds first: 14.1-73.37 or later, 13.1-64.23 or later, or the matching FIPS and NDcPP builds if you run those. Citrix's own bulletin CTX697096 lists the exact version numbers for every branch.
If your appliance was internet-facing before you patched, treat it as compromised until you prove otherwise. CISA's own guidance for this incident is unusual for a routine advisory: capture logs, a system snapshot, a support bundle and a core dump before you apply the update, because the update itself can erase the forensic evidence you would need to know whether you were already breached.
Then ask the harder question the last two emergencies should already have raised: does a single perimeter appliance still deserve to sit unmonitored between your network and the internet, or does it need a second control behind it that does not depend on Citrix shipping a fix in time.
Read next: Most Artifactory Servers Still Run a Patched Flaw | GitLab's Worst-Rated Flaw Needs Just One Public Project



