Abstract navy and teal crystalline gateway portal with network arcs — Citrix NetScaler KEV cybersecurity theme
Citrix NetScaler CVE-2026-88771 and CVE-2026-88772 hit CISA’s KEV — patch ADC/Gateway to fixed builds before Sept 30.

Citrix NetScaler CVE-2026-88771 Hit CISA’s KEV — Patch ADC/Gateway Before Sept 30

If your Midtown law firm, Staten Island medical practice, Brooklyn manufacturer, or Queens nonprofit still terminates remote access or load balancing on a Citrix NetScaler ADC or NetScaler Gateway, treat CVE-2026-88771 and CVE-2026-88772 as a same-week emergency — not a “next maintenance window” item. On September 27, 2026, Citrix published security bulletin CTX697096 covering eight NetScaler vulnerabilities. The same day, CISA added the two critical remote-code-execution CVEs to its Known Exploited Vulnerabilities (KEV) catalog with a federal remediation due date of September 30, 2026. Private NYC shops are not under Binding Operational Directive the same way federal agencies are, but two CVSS 9.5 unauthenticated RCE paths with confirmed exploitation and a three-day federal clock should jump the queue ahead of lifecycle upgrades and cosmetic change tickets.

This post is a practical checklist for NYC SMBs and the MSPs who support them. Named sources only: Citrix security bulletin CTX697096 (September 27, 2026), CISA’s “Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway” alert (September 27, 2026), CISA’s KEV catalog entries for CVE-2026-88771 and CVE-2026-88772 (dateAdded 2026-09-27, dueDate 2026-09-30), and CISA’s KEV addition notice for the same pair. No invented percentages. No exploit recipes.

What CVE-2026-88771 and CVE-2026-88772 actually are

Per Citrix CTX697096 and aligned CISA wording, CVE-2026-88771 is an improper input validation vulnerability (CWE-20) that can allow an unauthenticated attacker to execute arbitrary commands. Citrix rates it CVSS v4.0 base score 9.5. The precondition is blunt: all NetScaler ADC and NetScaler Gateway deployments — default configuration, no extra feature required. That is the highest-relevance path for most NYC SMBs: the appliance that fronts VPN, ICA Proxy, and published apps is also the appliance adversaries probe first.

CVE-2026-88772 is a memory overflow issue (CWE-119) that can lead to remote code execution or denial of service. Citrix also rates it CVSS v4.0 9.5. The precondition is DTLS configuration enabled on NetScaler ADC or NetScaler Gateway — and Citrix notes DTLS is enabled by default on VPN vServer. In other words, a typical Gateway VPN deployment that never touched the DTLS toggle still meets the precondition unless DTLS was explicitly disabled.

CISA’s September 27 alert states both CVEs are critical zero-days that can independently enable remote code execution, and that CISA has received reports and partner threat intelligence confirming active exploitation globally. Citrix’s bulletin states exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed. That combination — vendor confirmation plus KEV listing — is why this is not a “monitor for a patch Tuesday bundle” story.

The rest of CTX697096 (six more CVEs — still patch them)

The same bulletin covers six additional NetScaler issues that did not land in KEV on September 27 but still matter for exposed appliances:

  • CVE-2026-88773 — HTTP request smuggling (CVSS 9.3) when HTTP configuration is enabled.
  • CVE-2026-88774 — feature policy bypass tied to HTTP URL-based policy expressions (CVSS 7.0).
  • CVE-2026-88775 through CVE-2026-88777 — memory overflow issues (CVSS 8.8 each) tied to Gateway/AAA, Oracle LB, or non-HTTP L7 features.
  • CVE-2026-88778 — TCP Initial Sequence Number prediction (CVSS 8.8); Citrix points to an Enhanced ISN Generation TCP configuration change in addition to the build upgrade path for other CVEs.

For most NYC SMBs the operational message is simple: get onto a fixed build from CTX697096. Do not assume “we only use Gateway VPN, so the LB-only CVEs do not matter” as an excuse to delay the upgrade that also closes the two KEV RCE paths.

Affected versions and fixed builds (from Citrix)

Per CTX697096, affected supported versions include:

  • Citrix NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
  • Citrix NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
  • Citrix NetScaler ADC FIPS before 14.1-73.37 FIPS
  • Citrix NetScaler ADC FIPS and NDcPP before 13.1-37.279

Fixed targets called out by Citrix include 14.1-73.37 and later, 13.1-64.23 and later of 13.1, the matching 14.1-FIPS 14.1-73.37 FIPS line, and 13.1-FIPS / 13.1-NDcPP 13.1.37.279 and later. Citrix also notes that Secure Private Access Hybrid deployments using customer-managed NetScaler instances are affected and need those instances upgraded. Citrix-managed cloud services and Citrix-managed Adaptive Authentication are outside the customer-managed scope of the bulletin — Cloud Software Group handles those updates.

Citrix has not published a workaround that replaces the upgrade for CVE-2026-88771 or CVE-2026-88772. Upgrade is the fix.

Why NYC SMBs should care even if “we are not federal”

NetScaler ADC and Gateway show up in New York professional services, healthcare affiliates, finance back offices, and hybrid Citrix Virtual Apps and Desktops estates that still rely on Gateway for remote staff. Internet-facing VPN and ADC front ends are exactly the asset class ransomware crews and initial-access brokers scan after a KEV listing. CISA’s BOD 26-04 framing in the September 27 KEV notice applies to Federal Civilian Executive Branch agencies, but CISA explicitly encourages all organizations to prioritize KEV remediation. The federal due date of September 30, 2026 is a useful outer bound for private-sector urgency: if agencies must be done by Wednesday, an exposed SMB gateway should not still be “scheduled for next month.”

Also remember history without romanticizing it: NetScaler / Citrix Gateway has been a recurring KEV target in prior years. A shop that patched an earlier 2026 NetScaler CVE is not automatically safe here — watchTowr’s public FAQ notes that appliances patched for earlier NetScaler KEV entries remain vulnerable to CVE-2026-88771 and CVE-2026-88772 unless they run one of the fixed builds above. Build number wins. “We patched Citrix last quarter” does not.

NYC MSP / SMB checklist (preserve evidence, then patch)

CISA’s zero-day alert is explicit: if possible, check for indication of compromise prior to patching, and preserve forensic evidence if you suspect compromise, because updates may reduce forensic visibility. Citrix has made indicators of compromise available through NetScaler Console and points to additional compromise-assessment guidance alongside CTX697096. Practical sequence for a managed NYC estate:

  1. Inventory every customer-managed NetScaler ADC and Gateway — HA pairs, DR appliances, lab boxes that somehow got a public VIP, and Secure Private Access Hybrid instances. Record current build strings, not just “we are on 14.1.”
  2. Confirm internet exposure — which VIPs terminate SSL VPN, ICA Proxy, AAA, or published apps from the public internet. Priority follows exposure.
  3. Run Citrix’s IoC / compromise checks via NetScaler Console (and any org-approved EDR / firewall telemetry you already trust) before you wipe useful logs with an upgrade. If compromise is suspected, preserve images, config exports, and relevant logs first.
  4. Upgrade to a fixed build from CTX697096 for each branch in your estate. Schedule short, communicated cutovers; Gateway downtime is painful, but less painful than incident response after RCE.
  5. For CVE-2026-88778, apply Citrix’s Enhanced ISN Generation TCP guidance in addition to the build path where that CVE’s preconditions apply.
  6. Re-verify build strings after failover — HA secondary nodes that never got the upgrade are a classic miss.
  7. Watch auth and VPN logs for a few days post-patch for odd sessions, new local accounts, or unexpected management access. Patching closes the hole; it does not undo prior access if the box was already owned.

Do not spend the weekend reverse-engineering PoCs from random repos. Citrix and CISA already told you what matters: evidence first if you suspect compromise, then fixed builds, with no workaround substitute for the two KEV RCEs.

What “good” looks like for an MSP-run New York estate

Good looks like a living appliance inventory with build numbers, owners, and public VIP flags — not a spreadsheet last updated when the Gateway was installed. Good looks like a change window you can call within 24–48 hours of a KEV listing on an internet-facing VPN or ADC. Good looks like clients hearing a clear message: “Your NetScaler is on build X; fixed build is Y; cutover is Z; we checked IoCs first.” Vague reassurance (“we monitor Citrix advisories”) is not the same as a completed upgrade ticket with before/after build evidence.

If you are an internal IT lead without an MSP, the same checklist applies — just assign a named owner for the upgrade and a named owner for the IoC review. NetScaler upgrades are operationally fiddly; that is why CISA called out complexity and downtime risk in the September 27 alert. Complexity is not a reason to leave a CVSS 9.5 KEV RCE on the internet past September 30.

Sources (named, primary)

  • Citrix / Cloud Software Group — Security Bulletin CTX697096 for CVE-2026-88771 through CVE-2026-88778 (published September 27, 2026): affected versions, fixed builds, preconditions, exploitation observed on unmitigated deployments.
  • CISA — “Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway” (September 27, 2026): eight CVEs disclosed; CVE-2026-88771 and CVE-2026-88772 confirmed exploited globally; preserve evidence before patching when compromise is suspected.
  • CISA — “CISA Adds Two Known Exploited Vulnerabilities to Catalog” (September 27, 2026) and the KEV catalog feed entries for CVE-2026-88771 and CVE-2026-88772 (dateAdded 2026-09-27, dueDate 2026-09-30).

If your organization needs hands-on help inventorying NetScaler builds, checking for compromise indicators, and scheduling a safe upgrade window across New York offices, MicroSky Managed Services can help. Call (718) 672-2177 or visit https://microskyms.com.

Share This Article