As of September 28, the initial report of two unpatched NetScaler zero-days is out of date. Citrix has confirmed exploitation of CVE-2026-88771 and CVE-2026-88772 and released security updates. Administrators should use the fixed build for their appliance edition, preserve available evidence, and investigate the period before patching for signs of compromise.
3
33
50
Fixed NetScaler builds
For standard NetScaler ADC and NetScaler Gateway deployments, Citrix lists 14.1-73.37 or later and 13.1-64.23 or later as fixed. FIPS and NDcPP editions have separate build requirements: the bulletin lists 14.1-73.37 FIPS or later and 13.1.37.279 or later for 13.1-FIPS and 13.1-NDcPP. Check Citrix’s bulletin for the requirement that matches your appliance rather than assuming the standard build applies to every edition.
3
The key implication for 13.1 is that the new fixed target is 13.1-64.23 or later. A build that addressed an earlier NetScaler vulnerability may still fall short of this target.
3
4
These are not CVE-2026-19490
CVE-2026-19490 is a separate issue: Citrix describes it as an authentication bypass using an alternate path, with specific Gateway or AAA virtual-server configuration requirements. Its fixed builds include 14.1-73.32 and 13.1-63.21; those version numbers are below the fixed-build targets for the two new RCE flaws. An appliance updated for CVE-2026-19490 should not be assumed protected against CVE-2026-88771 and CVE-2026-88772.
4
20
The available reporting identifies CVE-2026-88771 as an improper-input-validation flaw that can let an unauthenticated attacker run commands. It names both CVEs as remote-code-execution vulnerabilities, but the reporting available here does not provide enough detail to reliably compare the flaws’ exploit mechanics.
33
50
54
Decide quickly between service disruption and exposure
Taking a NetScaler appliance offline may disrupt remote access or applications it delivers. Keeping an affected appliance exposed while delaying an available security update carries a different risk: Citrix has confirmed that both flaws were exploited on unmitigated deployments. Prioritize applying the correct fixed build; if that cannot happen promptly, consider restricting external access or taking the appliance out of service while weighing the operational impact.
3
50
This is especially important for 13.1: do not treat the earlier CVE-2026-19490 fix level as sufficient for these RCE vulnerabilities. Confirm the appliance’s exact version and edition against Citrix’s current bulletin.
3
20
Preserve evidence and investigate before patching where possible
An update closes the vulnerabilities; it does not establish whether attackers accessed the appliance beforehand. Where operationally possible, preserve relevant logs, configuration and other available forensic evidence before actions such as rebooting or upgrading could change it. Then investigate the pre-patch period for suspicious access or changes, and involve incident responders if compromise is suspected. watchTowr’s update also recommends preserving evidence, checking for compromise and then updating to fixed builds.
33
Citrix has confirmed exploitation, but reporting available here does not establish how many organizations were affected, who was responsible, or when exploitation began. Treat those questions as unresolved rather than assuming a clean system—or a known scope—based on the patch status alone.
49