CERT.LV: Critical Citrix Vulnerabilities Are Already Being Exploited — Companies Must Update Immediately

CERT.LV: Critical Citrix Vulnerabilities Are Already Being Exploited — Companies Must Update Immediately

Short answer: companies that manage their own Citrix NetScaler ADC or NetScaler Gateway appliances should install the security updates immediately. On 28 September 2026, CERT.LV warned that exploitation of two critical vulnerabilities — CVE-2026-88771 and CVE-2026-88772 — had already been observed in real-world attacks.

Both vulnerabilities have a CVSS v4.0 score of 9.5. They can lead to remote code execution without user authentication. Under the relevant conditions, an attacker may therefore execute commands on a vulnerable appliance before the organisation detects the intrusion.

Which Citrix NetScaler vulnerabilities are being exploited?

CVE-2026-88771 is an improper input validation vulnerability that allows an unauthenticated attacker to execute arbitrary commands. It affects all relevant NetScaler ADC and NetScaler Gateway deployments, including default configurations; no additional feature has to be enabled.

CVE-2026-88772 is a memory overflow vulnerability that can cause remote code execution or denial of service. It affects systems with DTLS enabled. DTLS is enabled by default on a NetScaler Gateway VPN virtual server unless an administrator has explicitly disabled it.

The Citrix bulletin describes eight vulnerabilities in total, from CVE-2026-88771 through CVE-2026-88778. However, exploitation of the first two vulnerabilities on unmitigated systems has been confirmed.

Which versions must be updated?

CERT.LV and Citrix identify the following fixed versions:

  • NetScaler ADC and NetScaler Gateway 14.1 — 14.1-73.37 or later;
  • NetScaler ADC and NetScaler Gateway 13.1 — 13.1-64.23 or later;
  • NetScaler ADC 14.1-FIPS — 14.1-73.37 FIPS or later;
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP — 13.1-37.279 or later.

The bulletin applies to customer-managed appliances. NetScaler instances used in Secure Private Access Hybrid deployments are also affected. Citrix-managed cloud services and Citrix-managed Adaptive Authentication are updated by the vendor.

Why is installing the update alone not enough?

A security update closes the vulnerability, but it does not automatically undo actions that an attacker may have taken before patching. Because exploitation has already been observed, CERT-EU recommends conducting a compromise assessment on internet-facing appliances after they are updated.

In practice, organisations should examine administrative sessions, unusual outbound connections, unexplained gaps in logs and other anomalies. If an incident is suspected, available logs and other evidence needed for investigation should be preserved before cleaning or rebuilding the system.

What should a company do now?

  1. Inventory appliances. Determine whether the organisation uses a customer-managed NetScaler ADC, NetScaler Gateway or Secure Private Access Hybrid instance.
  2. Check the exact version. Compare the installed build with the fixed versions listed in the Citrix security bulletin.
  3. Update immediately. Prioritise internet-facing appliances and gateways that provide remote access.
  4. Reduce exposure. If an immediate update is impossible, do not leave the vulnerable appliance freely accessible from the internet; follow the organisation's incident and change-management process.
  5. Assess for compromise. Successful patching does not prove that the appliance was not exploited beforehand.
  6. Escalate suspected incidents. Where Latvian IP addresses or .LV infrastructure are involved, contact CERT.LV and engage the organisation's cybersecurity specialist.

What does this mean for company management?

NetScaler Gateway is often located at the organisation's external boundary and provides remote access to internal resources. This is therefore not merely a routine IT update. An unpatched gateway can become the initial access point for a broader incident affecting system availability, confidential data and business continuity.

Management should obtain clear confirmation of three points: whether the company has affected appliances, whether they have been updated and whether an assessment has been performed for possible compromise before patching.

Official information sources

Comments

No comments yet. Yours could be the first!

Add a comment