Skip to main content

IoC Assessment and Forensic Analysis for Critical NetScaler CVEs

Citrix has published a critical security bulletin on September 27th 2026, covering eight vulnerabilities in customer-managed NetScaler ADC and NetScaler Gateway deployments. Two of the vulnerabilities, CVE-2026-88771 and CVE-2026-88772, have a CVSS v4.0 score of 9.5, and Citrix has confirmed that exploitation has already been observed against unmitigated NetScaler deployments.

This is not a routine update to place into the next maintenance cycle. Affected organisations should prioritise upgrading immediately while also establishing whether their NetScaler environment may already have been compromised.

Why this bulletin matters

The most significant vulnerability is CVE-2026-88771. It is a remote code execution vulnerability caused by improper input validation, potentially allowing an unauthenticated attacker to execute arbitrary commands.

CVE-2026-88771 affects all NetScaler ADC and NetScaler Gateway deployments, including default configurations. No additional feature or service needs to be enabled for an appliance to be exposed.

CVE-2026-88772 is another critical vulnerability that could result in remote code execution or denial of service. It affects deployments where DTLS is enabled, which is particularly relevant to organisations using NetScaler Gateway because DTLS is enabled by default on VPN virtual servers.

The wider bulletin also addresses HTTP request smuggling, security policy bypass, multiple memory overflow vulnerabilities, denial-of-service conditions and TCP Initial Sequence Number prediction. Exposure to some of these vulnerabilities depends on the services, virtual servers and features configured, but Citrix states that all customer-managed NetScaler ADC and NetScaler Gateway deployments are affected by one or more of the vulnerabilities. (support.citrix.com)

Which NetScaler versions contain the fixes?

Citrix is advising customers to install one of the following builds, or a later release in the same branch:

  • NetScaler ADC and NetScaler Gateway 14.1-73.37 or later
  • NetScaler ADC and NetScaler Gateway 13.1-64.23 or later
  • NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS or later
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 or later

Customer-managed NetScaler instances used within SecurAccess hybrid deployments are also affected and must be updated. Citrix-managed cloud services are being updated directly by Citrix. (support.citrix.com)

Customers remaining on the 13.1 branch should also consider a known operational issue affecting certain upgrades to 13.1-64.23. Citrix advises customers with configured NetScaler variables to plan an upgrade to 13.1-64.24 to avoid the risk of a cyclic reboot during the upgrade process.

Patching closes the vulnerability. It does not confirm the appliance is clean.

Installing a fixed build prevents these vulnerabilities from being exploited through the affected code, but it does not establish whether an attacker accessed the appliance before it was upgraded. It also cannot confirm whether files were modified, persistence was established or the appliance was used as a route into connected systems.

Because exploitation has already been observed, organisations should consider both remediation and investigation. The response should address the immediate technical exposure while assessing whether any suspicious activity occurred before the update was applied.

This is particularly important for internet-facing NetScaler Gateways and ADCs protecting critical applications. Where an appliance provides access to identity services, management systems or sensitive applications, the potential impact can extend beyond the NetScaler itself.

Indicators of Compromise and forensic analysis

Citrix has made generic Indicators of Compromise available through the NetScaler Console Security Advisory workflow. This provides a useful initial assessment, but Citrix makes clear that the indicators cannot cover every technique, tactic or procedure that a threat actor may use.

A clean IoC result should not therefore be treated as definitive evidence that an appliance has not been compromised. Threat actors can change their methods and infrastructure quickly, while some malicious activity may only be visible by correlating NetScaler evidence with identity, firewall, SIEM and application logs. (community.citrix.com)

NetScaler Console File Integrity Monitoring can also help identify unexpected changes to monitored files. Combined with centralised logging and wider security telemetry, this can provide valuable evidence when determining whether an appliance has been targeted or compromised.

Our forensic analysis service includes

cloudDNA can provide a focused NetScaler forensic analysis and Indicators of Compromise assessment for organisations affected by this bulletin. The service is designed to provide a clear view of exposure, identify suspicious activity and support an informed incident-response decision.

The service includes:

  • Validation of the NetScaler versions, deployment models and affected configurations
  • NetScaler Console Indicators of Compromise checks
  • Review of available system, audit, authentication, Gateway, web and security logs
  • Analysis of unexpected files and file-integrity changes
  • Review of administrative access and recent configuration changes
  • Investigation of unusual processes, connections or outbound activity
  • Correlation with available firewall, identity, SIEM and security telemetry
  • Identification of suspicious authentication or downstream activity
  • Documented findings, risks and recommended next actions

Where evidence suggests that an appliance may have been compromised, cloudDNA can help define the required containment and remediation actions. This may include extending the investigation into connected identity services, management systems and applications where the available evidence supports it.

NetScaler upgrade assistance

cloudDNA can also provide urgent upgrade assistance for affected NetScaler environments. Our NetScaler specialists can assess the estate, confirm the appropriate target build, review deployment-specific risks and plan upgrades across standalone and high-availability appliances.

The engagement can include pre-upgrade validation, configuration review, change planning, upgrade execution and post-upgrade service validation. This helps organisations move quickly while protecting availability and avoiding known operational issues.

Expert assistance when the response cannot wait

The combination of critical remote code execution vulnerabilities and confirmed exploitation makes rapid action essential. Organisations need to close the vulnerability, but they also need confidence that the environment was not compromised before the fix was applied.

As a Citrix Preferred Services Partner with deep NetScaler expertise, cloudDNA can provide both upgrade assistance and focused forensic analysis. Our NetScaler SME on Demand service gives customers direct access to experienced specialists when urgent technical support is required.

Concerned that your NetScaler may have been compromised?

Get in touch to learn more about our NetScaler Indicators of Compromise assessment, forensic analysis and urgent upgrade assistance. Call 0330 010 3443 or email hello@clouddnagroup.com.

Read the full Citrix security bulletin:

https://support.citrix.com/external/article/CTX697096/citrix-netscaler-adc-and-citrix-netscale.html