← All resources

NetScaler: two flaws exploited before the patch (27/09/2026)

Published October 2, 2026 · 7 min read · CyberNovaLabs.io

Eight vulnerabilities, two exploited before the patch existed, and four national authorities raising the alarm within three days. Here is the part that matters to an SME that does not run its own remote-access appliances.

In short

On 27 September 2026 Citrix published security bulletin CTX697096: eight vulnerabilities in NetScaler ADC and NetScaler Gateway, the appliances that carry remote access and VPN traffic in a great many corporate networks[1]. Two of them, CVE-2026-88771 and CVE-2026-88772, were already being exploited before the fix shipped, and each carries a CVSS v4.0 score of 9.5[1][2]. Within three days, the authorities in all four countries we work in had passed the alert on: the Dutch NCSC on 27 September, CERT-FR and Belgium's CCB on the 28th, CIRCL and the CSSF in Luxembourg[2][4][5][6][7].

Why patching is not the whole job

CVE-2026-88771 stems from improper input validation: an unauthenticated attacker can run arbitrary commands. Citrix is explicit that it affects every NetScaler ADC and Gateway deployment in its default configuration, with no extra feature needing to be switched on[1]. CVE-2026-88772 is a memory overflow leading to remote code execution or denial of service; it requires DTLS to be enabled, which is the default on a VPN virtual server[1].

For a managing director the decisive detail is not the score but the order of events: exploitation came first, the patch second. An appliance updated this week may already have been compromised last week. That is why the Dutch NCSC asks organisations to preserve evidence before patching — a dump of the full RAM, a disk image, logs copied off the appliance — then to install the update immediately and check the environment with the scanning script and indicators of compromise supplied by Citrix[2][3]. Luxembourg's CIRCL adds that at least a month of logs should be kept somewhere other than the appliance, and that NetScaler logs should be forwarded continuously to a SIEM, precisely so they survive the appliance being compromised[6].

Fixed versions

ProductFixed version
NetScaler ADC and Gateway 14.114.1-73.37 or later
NetScaler ADC and Gateway 13.113.1-64.23 or later
NetScaler ADC 14.1 FIPS14.1-73.37 FIPS or later
NetScaler ADC 13.1 FIPS and NDcPP13.1-37.279 or later

Versions taken from the Citrix bulletin and CIRCL report TR-100[1][6].

The other six flaws, and why they matter

The remaining six vulnerabilities are not reported as exploited, but they weigh on the decision to patch outside the usual maintenance window. The Dutch NCSC scores them from 7.0 to 9.3: CVE-2026-88773 (9.3) allows HTTP request smuggling with no authentication, CVE-2026-88774 (7.0) bypasses a feature policy, and CVE-2026-88775 to CVE-2026-88778 (8.8) cover memory overflows and predictable TCP initial sequence numbers[2]. Eight reasons to upgrade, two of them already used against real companies.

Is your SME affected? Three situations

You run a Citrix appliance. You are affected even if you never configured it yourself: the default configuration is enough to be vulnerable[1]. The CCB recommends installing the update with the highest priority, after testing[5].

Your IT provider runs one on your behalf. This is the common case in a company of 20 to 200 people: the portal your staff log into from home technically belongs to the provider, but the risk sits with you. One written question settles it: "Does our remote access run through a NetScaler ADC or NetScaler Gateway? If so, which version is live today, and have you looked for the indicators of compromise Citrix published?" Ask for a dated answer and keep it.

You have no Citrix equipment at all. The episode is still useful: it measures how fast your supplier reacts on an internet-facing appliance. That is exactly what our supplier security questionnaire is for, and the same reflex we describe for supply chains in NIS2 in the Netherlands: transport and logistics.

Who to notify, and how fast

Compromised remote access almost always leads to personal data: staff, customers, applicants. Two regimes then apply at once, with different recipients and different clocks.

CountryCybersecurity (NIS2)Personal data (GDPR)
NetherlandsCyberbeveiligingswet in force since 15 August 2026: report to the CSIRT and the supervisor as soon as possible and in any event within 24 hours[8]Autoriteit Persoonsgegevens, 72 hours
BelgiumLaw of 26 April 2024, CCB as authority: early warning within 24 hours, incident notification within 72 hours, final report within one month[9]APD / GBA, 72 hours
FranceNo transposition law yet: the Résilience bill, tabled on 13 March 2025 after Senate adoption, is scheduled for debate in the Assemblée nationale on 7 October 2026[10]CNIL, 72 hours
LuxembourgLaw of 5 May 2026, ILR as authority: 24 hours, 72 hours, one month. Financial sector: the CSSF treats unauthenticated remote code execution as a major ICT-related incident, to be notified under circular 25/893 or 24/847[7]CNPD, 72 hours

The GDPR's 72 hours start when you become aware of the breach, not when the intrusion happened — a count we unpack in the Jims breach and what SMEs owe their regulator. The French position is worth reading the other way round: the absence of a NIS2 law removes neither the GDPR duty nor the contractual demands your enterprise customers already place on you.

This week

  1. Ask your provider in writing whether a NetScaler ADC or NetScaler Gateway serves your remote access, and which version is running today.
  2. If yes: preserve evidence (RAM, disk image, logs) before any update, then move to 14.1-73.37, 13.1-64.23 or the matching FIPS build[1][2].
  3. Run Citrix's scanning script and IoC checks, and ask for the result in writing[2][6].
  4. If any sign of compromise appears: trigger your incident procedure, invalidate live VPN sessions and rotate the authentication secrets that were exposed.
  5. Confirm who in your organisation is authorised to notify the authority, and within what deadline. Settle that before an incident, not during one.
  6. Set up log forwarding from the appliance to external storage, so there is something to analyse next time[6].

At CyberNovaLabs.io

We help SMEs in the Netherlands, Belgium, France and Luxembourg with the unglamorous part: knowing which equipment is exposed, who patches it, and how quickly the authority has to be told. Our country-by-country reference points sit on our cybersecurity for SMEs page, with the Dutch detail on NIS2 in the Netherlands. To review your remote access and your supplier chain, take half an hour with us.

Sources

  1. Citrix — Security Bulletin CTX697096, NetScaler ADC et NetScaler Gateway (27/09/2026)
  2. NCSC-NL — Beveiligingsadvies NCSC-2026-0394, versie 1.0.1 (27/09/2026, mis à jour le 30/09/2026)
  3. NCSC-NL — Alerte « Kwetsbaarheden in Citrix NetScaler ADC en NetScaler Gateway: update nu » (27/09/2026)
  4. CERT-FR — Alerte CERTFR-2026-ALE-011, multiples vulnérabilités dans Citrix NetScaler ADC et Gateway (28/09/2026)
  5. CCB (Belgique) — Warning: Citrix NetScaler ADC & NetScaler Gateway RCE Vulnerabilities Actively Exploited as Zero-Days, Patch Immediately! (septembre 2026)
  6. CIRCL (Luxembourg) — Rapport TR-100, Multiple Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway, version 1.0 (27/09/2026)
  7. CSSF (Luxembourg) — Multiple Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway (28/09/2026)
  8. NCSC-NL — Cyberbeveiligingswet, en vigueur depuis le 15 août 2026
  9. CCB (Belgique) — Guide sur les notifications NIS2, version 08.2025
  10. Assemblée nationale — Dossier législatif, projet de loi relatif à la résilience des infrastructures critiques et au renforcement de la cybersécurité
CyberNovaLabs.io

Qualified meetings, no lock-in.

Criteria in writing before launch, pay per meeting or monthly, stop with a simple email.

→ Get meetings booked

Read next

Newsletter · CyberNovaLabs.io

Security Briefing

One email a month: a figure from our barometer, the NIS2 and CRA dates that matter in the Netherlands, Belgium and Luxembourg, and one practical guide. In English. Unsubscribe in one click.

→ Get meetings booked