Citrix has confirmed exploitation of CVE-2026-88771 and CVE-2026-88772 against unmitigated NetScaler deployments. Both vulnerabilities can lead to remote code execution, and the first affects every customer-managed NetScaler ADC and NetScaler Gateway deployment, including default configurations. This is therefore a fleet-wide emergency change, not a feature-specific exception exercise.
The immediate objective is simple: identify every appliance and virtual instance, move every supported node to a fixed build, verify the running version after failover, and preserve enough evidence to assess whether exploitation occurred before the update.
Know the two exploited paths
Citrix bulletin CTX697096 rates both CVE-2026-88771 and CVE-2026-88772 at CVSS 9.5. CVE-2026-88771 is an unauthenticated command-execution issue caused by improper input validation, with no additional feature required. CVE-2026-88772 is a memory-overflow issue that can cause code execution or denial of service when DTLS is enabled. DTLS is enabled by default on VPN virtual servers unless explicitly disabled.
The same bulletin also fixes six additional vulnerabilities involving request smuggling, policy bypass, memory corruption, and TCP initial sequence number prediction. Even when a configuration does not meet the precondition for CVE-2026-88772, it may still be exposed to CVE-2026-88771 or another issue in the release.
Set the correct target build
Citrix identifies these fixed baselines:
- NetScaler ADC and Gateway 14.1-73.37 or later;
- NetScaler ADC and Gateway 13.1-64.23 or later;
- NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS or later;
- NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 or later.
There is an operational caveat for 13.1-64.23: Citrix reports that appliances with configured NetScaler variables may enter a reboot cycle during the upgrade. Run show ns variable; if it returns configured variables, plan for 13.1-64.24 or later. Do not confuse the minimum security build with the safest operational target.
Inventory every node and image
Build the list from more than the CMDB. Include active and standby HA members, autoscale images, disaster-recovery instances, test gateways reachable from production networks, Secure Private Access Hybrid NetScaler instances, and dormant virtual machines that can be started later. Record management IP, public VIPs, software branch, running build, HA role, hypervisor or cloud account, owner, and exposure.
Customer-managed appliances require customer action. Citrix-managed cloud services are updated by the provider, but customers should still verify which side of that boundary each gateway belongs to. The 15.1 Technology Preview is not approved for production and is also vulnerable.
Patch an HA pair without leaving a gap
- Export configuration and diagnostic data before changing either member.
- Confirm session-capacity and failover readiness on the node that will remain active.
- Upgrade the secondary member and verify the running build locally.
- Fail over in a controlled window and test VPN, ICA Proxy, authentication, SAML, and application delivery.
- Upgrade the former primary, re-establish synchronization, and verify both members again.
- Update golden images and automation templates so replacement nodes do not reintroduce a vulnerable build.
Do not close the change merely because the GUI reports a successful installation. Capture the live build from each member, confirm the intended boot partition, and test failover. A patched active node paired with an old standby remains an incomplete remediation.
Reduce exposure while the rollout proceeds
If any node cannot be updated immediately, restrict management access, remove unnecessary public listeners, and place upstream controls around reachable services. Disabling DTLS can reduce exposure to CVE-2026-88772, but it does not address CVE-2026-88771 and must not be treated as a substitute for the update.
Because exploitation has already been observed, collect logs and system evidence before reboots where feasible. The companion compromise-assessment process should run in parallel with patching, especially for internet-facing gateways. A software update blocks the published path going forward; it does not prove the appliance was clean beforehand.
Test authentication changes after the upgrade
Citrix notes that signed SAML assertions are now required and that a configuration allowing unsigned assertions is converted to the secure behavior during upgrade. Confirm that the identity provider signs assertions and test both successful and rejected logins. Also validate certificate chains, LDAP or RADIUS dependencies, session persistence, and application health through every gateway VIP.
Monitor CPU, memory, crashes, authentication errors, and HA synchronization through at least one representative traffic cycle. Keep the rollback plan available, but do not roll back to a vulnerable build; if an application fails, restore service through a patched alternate node or correct the compatibility issue.
Define evidence for closure
The final record should show the complete asset list, target build, upgrade result for each node, HA and application tests, updated deployment images, and the outcome of compromise assessment. Track systems that are offline or ownerless separately rather than removing them from the denominator. For this incident, “all known production gateways” is not enough—the standard is every customer-managed NetScaler instance that can return to service.

