Two Citrix NetScaler zero-days were exploited for weeks before a patch
Both score CVSS 9.5 and allow remote code execution. CISA gave federal agencies until September 30, and Citrix, CISA, and the Dutch NCSC all say to look for compromise before patching.
The patch is out. The official advice is to copy memory and a month of logs before you install it.
Citrix disclosed eight vulnerabilities in NetScaler ADC and NetScaler Gateway on September 27. Two of them, CVE-2026-88771 and CVE-2026-88772, were already being exploited as zero-days before the disclosure, according to Rapid7 and CISA.
One works on the default config
CVE-2026-88771 is an input-validation flaw that lets an unauthenticated attacker run commands. It affects the default configuration with low attack complexity, and Rapid7 expects reliable remote code execution against every unpatched appliance. CVE-2026-88772 is a memory overflow that leads to code execution or a crash, but only when DTLS is enabled. Both score 9.5 on CVSS v4. The other six, including a 9.3 request-smuggling flaw, had no confirmed exploitation.
Help Net Security reports that European government sources, including the Dutch National Cyber Security Centre, had been warning about attacks through the week before disclosure. CISA added both CVEs to its Known Exploited Vulnerabilities catalog and gave US federal civilian agencies until September 30. Fixed builds are 14.1-73.37 and 13.1-64.23 or later, with matching FIPS releases.
Collect the evidence, then patch
CISA tells organizations to check for indicators of compromise and preserve forensic data before updating, because the update can erase what an investigator needs. The NCSC-NL advice cited by Help Net Security is to back up device memory and at least a month of logs. Citrix warns that the published indicators might miss real compromises. On an appliance exposed for weeks, a successful patch says nothing about whether someone got in first.
Why a build studio cares
The software we audit often sits behind a remote-access gateway that nobody on the product team owns, and it rarely appears on the architecture diagram. The governance part of an audit asks who can patch that edge device and how fast. This week adds a sharper version of the question: could that person have pulled memory and 30 days of logs before patching, on the Sunday the advisory landed? If not, the incident-response plan needs the order of operations written into it before the next advisory.
Next step: read CISA's alert and follow its links to Citrix's advisories. If a remote-access gateway sits in front of your app and nobody owns its incident plan, write to us at hello@gattyworks.com.