Citrix NetScaler carried two unauthenticated remote code execution flaws for weeks before a patch existed. By the time four security outlets had finished covering it this weekend, the story each of them told was not quite the same story.

What Actually Happened

On September 27, CISA added two Citrix NetScaler vulnerabilities, CVE-2026-88771 and CVE-2026-88772, to its Known Exploited Vulnerabilities catalog. Both carry a CVSS score of 9.5. CVE-2026-88771 lets an unauthenticated attacker execute arbitrary commands through improper input validation. CVE-2026-88772 is a memory buffer overflow that enables remote code execution or denial of service on any NetScaler Gateway with DTLS enabled, which is the default configuration on VPN virtual servers. Citrix shipped patches for both, plus six lower-severity bugs in the same range (CVE-2026-88773 through CVE-2026-88778), across NetScaler ADC and Gateway versions 14.1 and 13.1. Fixed builds start at 14.1-73.37 and 13.1-64.23. CISA’s KEV entry sets a September 30 deadline and requires forensic triage under Binding Operational Directive 26-04, the directive CISA reserves for vulnerabilities it believes may already have produced compromises, not just exposure.

The Full Set of Eight

The two KEV-listed flaws were not the only ones Citrix patched this weekend. CVE-2026-88773, rated 9.3, is an HTTP request smuggling bug that can bypass security controls sitting in front of a NetScaler deployment, meaning a web application firewall or reverse proxy placed to protect the device can itself be routed around. Three more flaws, CVE-2026-88775 through 88777, are memory overflow issues rated 8.8 that Citrix describes as causing instability rather than confirmed code execution. CVE-2026-88778, also 8.8, is a TCP Initial Sequence Number prediction flaw, a session-hijacking primitive. CVE-2026-88774, the lowest-severity of the eight at 7.0, is a feature policy bypass tied to how NetScaler parses HTTP URL expressions. None of the six lower-severity bugs has been confirmed under active exploitation the way CVE-2026-88771 and CVE-2026-88772 have, but all eight ship in the same patch, which means an organization that applies the fix for the two KEV entries closes the other six at the same time.

Media Partner

Web3 x AI Fusion — Media Partner

Four Outlets, Four Different Emphases

The Hacker News led with the regulatory mechanics: the KEV addition, the three-day federal patch window, and the exact fixed-version numbers agencies need to check against. Its framing treats this as a compliance story as much as a security one.

Help Net Security told a different story entirely: exploitation had been running through most of September, and the Dutch National Cyber Security Center had intelligence on it before Citrix or CISA said anything in public. NCSC-NL passed word to IT suppliers, who quietly warned their own customers days ahead of Friday’s public disclosure. Researcher Kevin Beaumont, who has tracked NetScaler exploitation for years, told the outlet the activity looked “probably nation state aligned as well resourced, espionage rather than teens.” The piece also carried a data point from Tenable that roughly two-thirds of threat activity against NetScaler over the past seven years has involved advanced persistent threat groups, not opportunistic criminals.

The Register skipped the urgency angle almost entirely and instead built its story around Citrix’s history: critical, actively exploited NetScaler flaws in 2020, 2023, twice in 2025, and again this past March. Its argument is that this is not an incident, it is a pattern, and that some NetScaler operators have learned to run compensating controls specifically because they no longer expect timely patches.

Infosecurity Magazine took the broadest view, cataloguing all eight CVEs by severity and tracking the international response: CISA’s federal deadline, an Australian Cyber Security Centre alert issued the same day, and NCSC-NL’s own advisory to Dutch organizations.

Where the Accounts Disagree

The four outlets do not disagree on the facts. They disagree on what the facts mean. Help Net Security’s framing treats the story as a failure of coordinated disclosure, since defenders with Dutch government contacts had a head start measured in days over everyone else, while ordinary NetScaler operators found out from a Reddit post the Register says a Citrix channel partner posted on Saturday, ahead of Citrix’s own Sunday disclosure. The Hacker News and Infosecurity Magazine both treat the story as working as intended: a real vulnerability got a KEV listing and a hard deadline within 72 hours of confirmed exploitation, which is the system functioning. The Register is the outlier, arguing the deadline and the disclosure are beside the point when the same vendor has produced this exact scenario in 2020, 2023, twice in 2025, and again this past March. None of the four outlets connects those two arguments to each other, and that gap is the actual finding here: a fast, well-coordinated KEV response does nothing to fix a vendor pattern that keeps producing the vulnerabilities the response is reacting to, and it does not undo the fact that the best-connected defenders got a multi-day head start over everyone reading a public advisory.

The Disclosure Ladder

Lay the four accounts side by side and a rough timeline emerges that none of them state outright but that the reporting collectively supports. Dutch government intelligence sharing with IT suppliers appears to have started sometime in the week before September 25. Individual security researchers, Kevin Beaumont among them, were tracking and discussing the activity by Friday, September 25. A Citrix channel partner is reported to have warned its own customers via a public Reddit post on Saturday, September 26, before Citrix’s own disclosure. Citrix shipped patches and its own advisory on Sunday, September 27. CISA added the two flaws to the KEV catalog that same day and gave federal agencies until September 30. Each rung of that ladder is a different population of defenders finding out at a different time, and the gap between the top rung and the bottom one is measured in days, not hours, for a vulnerability pair rated 9.5 that requires no authentication to exploit.

Newsletter

Get the week's best tech coverage.

Free. Read by thousands of HR, tech, and business leaders.

What It Means for the Security Leader

A three-day patch clock assumes an organization already knows it has exposed NetScaler devices, already has a maintenance window, and already has a rollback plan if the update breaks something. For a security team running NetScaler as a VPN gateway, none of those are safe assumptions on a Friday before a holiday weekend. The BOD 26-04 forensic triage requirement matters more than the patch deadline itself: it is CISA’s way of saying it suspects some of these devices were already compromised before anyone knew to look. Treating this as a patch-and-move-on ticket, rather than an assume-breach investigation, is the mistake the Help Net Security reporting implies several organizations are already making, given how long exploitation appears to have run before anyone outside a small circle of Dutch officials and IT suppliers knew about it.

What to Do

Patch to 14.1-73.37 or 13.1-64.23 or later immediately, not on the next scheduled maintenance window. Before patching, run the indicators of compromise Citrix published against NetScaler Console logs, since CISA’s forensic triage requirement exists precisely because patching alone does not tell you whether a device was already exploited. Rotate any credentials or session tokens that traversed an affected Gateway during September. If DTLS is enabled on a VPN virtual server and cannot be patched within the CISA window, disable DTLS as an interim mitigation rather than leaving the service exposed. Organizations without a federal compliance deadline should still treat September 30 as their own target, since the exploitation predates the disclosure by weeks according to Dutch intelligence sharing, not days.

This piece did not carry a directly quoted, named-speaker statement from CISA or Citrix. CISA’s own advisory and KEV catalog pages returned access errors to automated retrieval at the time of writing; the vulnerability details above were independently confirmed against CISA’s published KEV data feed rather than the blocked HTML pages, but no on-the-record quote in that feed could be verified.

Prior CyberTech coverage: CISA Flags NetScaler and Fortinet, Sets 3-Day Clock and Same Severity Score, Different Deadline Now.

Source: CISA Known Exploited Vulnerabilities Catalog