A September 27, 2026 alert cites eight vulnerabilities in NetScaler ADC and Gateway. Two critical zero-days, CVE-2026-88771 and CVE-2026-88772, allow remote code execution and are under active exploitation.
In an alert published on September 27, 2026, CISA shared Citrix information about eight vulnerabilities affecting NetScaler ADC and NetScaler Gateway: CVE-2026-88771 through CVE-2026-88778. The agency added the first two to its Known Exploited Vulnerabilities (KEV) catalog. Each can allow remote code execution, and partner reports indicate active exploitation in multiple parts of the world.
CISA recommends consulting Citrix advisories, assessing exposure, and looking for signs of compromise before applying updates, if possible. Updating appliances may require downtime; if an intrusion is suspected, preserving forensic evidence before patching is important because updates may reduce visibility into that evidence. The alert says Citrix made indicators available through NetScaler Console and published guidance for assessing possible compromise. Consult the CISA alert and Citrix security bulletin to verify affected versions, fixes, and current procedures; account for operational impact and evidence preservation before making changes.