In short: On September 27, 2026, Citrix released emergency bulletin CTX697096 patching two critical zero-day vulnerabilities in NetScaler ADC and NetScaler Gateway — CVE-2026-88771 and CVE-2026-88772 (CVSS 9.5). Both allow unauthenticated remote code execution and are already under active exploitation: eSentire traced attacks on CVE-2026-88771 back to September 5, more than three weeks before public disclosure. NetScaler Gateway is widely deployed as a corporate VPN gateway, so this isn't an abstract perimeter flaw — it's a risk to the remote-access channel employees rely on. CISA added both CVEs to its KEV catalog the same day the bulletin was published.
What happened
On September 27, 2026, Citrix disclosed eight new vulnerabilities across the NetScaler ADC and NetScaler Gateway product lines, including two critical, CVSS-9.5-rated flaws: CVE-2026-88771 (improper input validation) and CVE-2026-88772 (memory overflow in DTLS processing). Both are remotely exploitable, require no authentication, and need no user interaction. According to Tenable, the first reports of active exploitation surfaced on security forums on September 25, and researchers confirmed in-the-wild attacks on September 26 — before the official patch was even released.
Notably, the Dutch National Cyber Security Centre received a private pre-notification from Citrix ahead of public disclosure and was able to warn NetScaler administrators to consider disconnecting exposed appliances before a patch existed. Israel's national cybersecurity authority issued a separate advisory naming affected organizations across finance, pharma, and retail — including Mizrahi Tefahot Bank, Mastercard's local unit, pharmaceutical company Teva, shipping firm ZIM, and retail chain Super-Pharm — all of which use NetScaler as a remote-access entry point.
Why this specifically hits VPN infrastructure
NetScaler Gateway isn't a generic web server — it's the gateway thousands of companies use to provide employees with secure remote access to internal systems, effectively a corporate VPN concentrator. CVE-2026-88772 is particularly concerning because it affects DTLS processing, a protocol enabled by default specifically on NetScaler's VPN servers — meaning the flaw sits inside the mechanism that's supposed to guarantee an encrypted connection. CVE-2026-88771, meanwhile, is exploitable even in default configurations, with no special settings required.
Affected are the supported 13.1 and 14.1 branches; versions 12.1 and 13.0 are end-of-life and will receive no patch at all — organizations still running them have no option but network segmentation or full disconnection. CISA's same-day addition of both CVEs to its Known Exploited Vulnerabilities catalog triggers mandatory remediation deadlines for US federal agencies and functions as an industry-wide severity signal.
What this means for everyday users
Concrete scenario: an employee connects to work systems through a corporate VPN built on a vulnerable NetScaler Gateway. If the gateway is compromised, an attacker can potentially gain a foothold inside the company's internal network — from there, an attack can reach email, file storage, and personal data an employee assumed was protected by default. This illustrates a broader principle: VPN reliability isn't just about the encryption protocol — it's about how quickly and responsibly the gateway provider patches its own infrastructure. For more on choosing a genuinely secure VPN, see our guide on picking the most secure VPN.
For personal use, the practical takeaway is this: if your VPN provider relies on separate corporate gateway appliances with a history of zero-days, it's worth looking at alternatives running their own, purpose-built infrastructure. LiMP VPN runs on dedicated servers under its own stack rather than general-purpose corporate ADC platforms — narrowing the attack surface that comes with multi-function gateways like NetScaler.
What administrators and users should do
- Organizations running NetScaler ADC/Gateway should patch immediately per bulletin CTX697096; if patching isn't immediately possible, temporarily disconnect external access to the appliance.
- Versions 12.1/13.0 (end-of-life) will get no patch — migrate to a supported branch or fully isolate the gateway from the internet.
- Citrix provides indicators of compromise via NetScaler Console; without access, contact Citrix Support directly.
- Employees whose company uses a NetScaler-based VPN should change their corporate VPN password once IT confirms the patch is installed, and enable 2FA if not already active.
