NetScaler patches land: eight CVEs, two already exploited
Citrix bulletin CTX697096 assigns CVEs to the exploited NetScaler zero-days and ships fixed builds. Patch to 14.1-73.37 or 13.1-64.23 now.
The NetScaler patch exists now. On September 27, Citrix published security bulletin CTX697096 covering eight NetScaler ADC and Gateway vulnerabilities, including the two that were being exploited over the weekend with no CVE and no advisory. If your MSP told you to power the appliance down, this is the bulletin that tells you what to install before you turn it back on. Patch to 14.1-73.37 or 13.1-64.23.
What actually happened
Straight from the Citrix bulletin, published September 27:
- CVE-2026-88771 — CVSS 9.5, exploited. Remote code execution from improper input validation. Citrix says all NetScaler ADC and Gateway deployments are affected, including the default configuration. No feature has to be enabled. There is no "we don't use that module" out.
- CVE-2026-88772 — CVSS 9.5, exploited. A memory overflow that can produce RCE or denial of service when DTLS is enabled — and DTLS is on by default on VPN virtual servers.
- CVE-2026-88773 — CVSS 9.3. HTTP request smuggling. Not reported as exploited.
- Five more at 7.0–8.8: a feature policy bypass via HTTP URL expressions (CVE-2026-88774), memory overflows in gateway/AAA configs (CVE-2026-88775), Oracle load-balancing virtual servers (CVE-2026-88776), and non-HTTP L7 protocol features (CVE-2026-88777), plus TCP initial sequence number prediction (CVE-2026-88778).
Fixed builds: 14.1-73.37 and later, 13.1-64.23 and later, 14.1-73.37 FIPS and later, and 13.1-37.279 and later for FIPS/NDcPP. Anything on 14.1 before 14.1-73.37 or 13.1 before 13.1-64.23 is vulnerable. Citrix's own language is to install the updated versions as soon as possible.
This is the resolution of the advisory-free weekend we wrote about in NetScaler zero-days: no CVE, no patch, turn it off. The instruction went from shut it off to shut it off, patch it, then assume it was reached — because an unauthenticated RCE on a default config that was live in the wild for days is not a patch-and-move-on event.
Why NetScaler patching matters for your business
Patching is step one of three. Two of these were exploited before a fix existed. If your appliance faced the internet during that window, the patch closes the door and tells you nothing about who already walked through it. Rotate the credentials the appliance holds — LDAP/AD bind accounts, RADIUS secrets, API keys, certificates — and terminate active VPN and ICA sessions. Then read the logs for the window, not just for today.
"Default configuration is affected" changes your inventory question. Most vuln triage starts with do we use that feature? CVE-2026-88771 removes that filter, and CVE-2026-88772 rides a default-on setting. Your list is not "appliances with DTLS enabled." It is every NetScaler you own, including the one a vendor stood up three years ago for a single remote app and nobody has logged into since. Find it by IP range, not by memory.
A five-day gap between "turn it off" and "here is the CVE" is now a normal shape. Coordinated disclosure assumes the vendor moves first. Increasingly a researcher or an MSP moves first, and you act on an unnumbered warning. Decide now who is authorized to take a production appliance offline on that kind of signal, because the answer cannot be "whoever is awake."
Edge appliances deserve a patch tier of their own. A NetScaler is not a server in your patch rotation — it is the authentication boundary for everything behind it, and it is directly reachable. Put edge devices on a separate, faster SLA than internal workloads, with a named owner and a tested rollback. If a critical edge patch has to wait for next month's maintenance window, the window is the vulnerability.
Key takeaways
- Citrix CTX697096 (September 27) covers eight CVEs; CVE-2026-88771 and CVE-2026-88772 are both CVSS 9.5 and both exploited
- CVE-2026-88771 affects every deployment including the default configuration — no feature gating
- CVE-2026-88772 needs DTLS, which is enabled by default on VPN virtual servers
- Fixed builds: 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, 13.1-37.279 FIPS/NDcPP
- Patching is not remediation: rotate bind accounts, secrets and certificates, and kill live sessions
- Give internet-facing appliances a faster patch SLA than the servers behind them
If you cannot name every internet-facing appliance you own, the patch list is not your problem — the inventory is. We build and document systems where the edge is enumerated, owned and monitored, not inherited. See how we build, or have us map your external surface.
Sources: Citrix security bulletin CTX697096, BleepingComputer.
- #security
- #netscaler
- #citrix
- #cve-2026-88771
- #patch-management
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Plugin4Shell: your SHA pin was never verified
Plugin4Shell let attackers swap AI coding agent plugins past SHA pinning. Claude Code and Codex are patched; Copilot and Gemini CLI are not.
Read itMeta's 43M violations: your public claims are evidence
A Santa Fe jury found Facebook committed ~43 million consumer-protection violations by counting public statements times people reached. Version-control your claims.
Read it