Critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway
Multiple critical vulnerabilities have been disclosed affecting Citrix NetScaler ADC and Citrix NetScaler Gateway, potentially leading to Remote Code Execution (RCE). We strongly recommend applying the patches as soon as possible.

T-Update
This live blog provides information regarding vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway. Citrix has released security updates to address these vulnerabilities.
Blog last updated on September 29
Update September 29, 2026
Based on new insights, the guidance for NetScaler ADC and NetScaler Gateway has been updated. For NetScaler nodes that have been vulnerable and accessible from the internet, prior compromise cannot be ruled out. Installing the available security updates prevents new exploitation of the patched vulnerabilities, but does not automatically remove any previously installed webshells or backdoors.
The IoC scan in NetScaler Console also does not provide complete certainty in this regard. The scan checks for known indicators but does not cover all possible attacker methods. Therefore, a "No Compromise Detected" result does not mean that a prior compromise can be ruled out.
For this reason, we recommend that NetScaler nodes that have been vulnerable and accessible from the internet be rebuilt from a new, clean build. This applies even if the security updates have already been installed and regardless of the outcome of the IoC scan. More information and the full advisory can be found below.
Update September 27, 2026
On September 27, multiple vulnerabilities were disclosed in Citrix NetScaler ADC and Citrix NetScaler Gateway. In total, Citrix has patched eight security flaws, three of which are classified as critical. The vulnerabilities can lead to, among other things, Remote Code Execution (RCE), HTTP Request Smuggling, security policy bypass, and Denial-of-Service. The NCSC has issued a security advisory for this with a priority of High .
According to Citrix, active exploitation has been observed for vulnerabilities CVE-2026-88771 and CVE-2026-88772. Additionally, Citrix states that no additional configuration or functionality is required to exploit CVE-2026-88771.
Background
On September 27, several critical vulnerabilities were disclosed in the Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin, which could potentially lead to Remote Code Execution (RCE).
Risk
The vulnerabilities affect supported versions of Citrix NetScaler ADC and NetScaler Gateway, including certain FIPS and NDcPP variants. Secure Private Access hybrid deployments that utilize NetScaler instances may also be vulnerable.
Furthermore, a residual risk remains for NetScaler nodes that have been vulnerable and accessible from the internet. Installing security updates prevents new exploitation of the patched vulnerabilities, but does not rule out prior compromise. In previous attack campaigns targeting NetScaler, webshells and backdoors remained active even after updates were installed.
The IoC scan in NetScaler Console can assist in investigating potential compromise, but it has limitations. The scan does not cover all possible attacker methods. Therefore, a "No Compromise Detected" result only means that no known indicators were found and does not rule out an actual compromise.
Advice
We strongly advise installing the available security updates as soon as possible.
The NCSC advises organizations to account for the possibility that systems accessible prior to the installation of these updates may have already been compromised. Furthermore, it is recommended to secure relevant logs and a memory dump before performing updates to ensure that any potential forensic investigation remains possible.
Citrix has provided a scan tool to check if your host may have been compromised; see Indicators of Compromise detection in NetScaler Console. However, this scan has limitations and cannot detect all forms of compromise. Therefore, a "No Compromise Detected" result does not rule out a prior compromise.
We therefore recommend that every NetScaler node that was vulnerable and accessible from the internet be rebuilt from a clean, new build. This advice applies regardless of the IoC scan results and even if the node has already been patched. Use a clean image of a patched version for this purpose. The available versions are listed in Citrix bulletin CTX697096.
Do you have questions about a potential compromise or the impact on your environment? Please contact our T-CERT emergency line for advice and to coordinate next steps.
Sign up for T-Updates
Receive the latest news about malware or vulnerabilities in your inbox every Wednesday
More than 1,000 organizations have already joined us.
