Threat Actors Exploiting Critical Citrix NetScaler Zero-Day Vulnerabilities
Impact: All Firms Using Customer-Managed Citrix NetScaler ADC or NetScaler Gateway Deployments
FINRA member firms should be aware of several vulnerabilities Citrix disclosed related to customer-managed Citrix NetScaler ADC and NetScaler Gateway,1 two programs designed to manage the delivery of applications across a network and provide secure remote access to a corporate network, respectively. Two are critical “zero-day” vulnerabilities that threat actors are actively exploiting.2 Successful attacks could allow a threat actor to execute code, disrupt services and gain unauthorized access to connected networks.
This Alert summarizes the two critical vulnerabilities, identifies affected versions, and lists recommendations to help firms assess their potential exposure, apply available updates, and respond to suspected compromise.
FINRA recommends all firms share this Alert with appropriate information technology and information security personnel, as well as any third-party vendors that manage or support Citrix NetScaler ADC or NetScaler Gateway appliances, to identify whether your firm is impacted and take immediate steps to protect your environment.
Background
Citrix NetScaler ADC and NetScaler Gateway are network devices used for application delivery and secure remote access.1 Citrix recently disclosed eight vulnerabilities related to these products, including two—CVE-2026-887713 and CVE-2026-887724—with 9.5 CVSS scores, indicating that they are critical. Threat actors have been observed exploiting these vulnerabilities; as a result, the U.S. Department of Homeland Security’s Cybersecurity & Infrastructure Security Agency (CISA) added them to its Known Exploited Vulnerabilities Catalog.4
If your firm uses the affected versions of Citrix NetScaler ADC or NetScaler Gateway listed in the table below, it is recommended your firm take corrective action. Exploitation of these vulnerabilities could allow attackers to take control of a device at the firm that is connected via either application, interrupt remote-access or application-delivery services, access sensitive configuration or session information, and attempt to gain access to connected internal systems.4 Because patching may affect forensic visibility, firms that suspect that they have been compromised should preserve all relevant logs and assess the impacted device before applying updates.5
Recommended Actions
Member firms that use either Citrix NetScaler ADC or NetScaler Gateway should review the Citrix security bulletin1 and CISA alert4 referenced in the Technical Details below and consider the following actions. Firms should note that updating or patching will not remove attackers who have previously accessed a compromised network.
- Identify Exposure: Inventory customer-managed NetScaler ADC and NetScaler Gateway appliances, confirm the installed build, and determine whether Datagram Transport Layer Security (DTLS) is enabled.1
- Check for Compromise: Before updating, where feasible, use the indicators-of-compromise assessment available through NetScaler Console and review Citrix’s published guidance. Citrix cautions that the assessment may not identify every compromise.5
- Apply the Citrix Update: Upgrade affected appliances in accordance with Citrix Security Bulletin CTX697096.1
- Respond if Compromise Is Suspected: Preserve available forensic evidence and follow Citrix’s published response guidance,5 which addresses investigation, containment, credential protection and recovery.
Technical Details
Table 1 – Vulnerability Summary
| Vulnerability | Product / Release | Affected Build Versions | Additional Condition |
|---|---|---|---|
| CVE-2026-88771 | NetScaler ADC and NetScaler Gateway 14.1 | Before 14.1-73.37 | None—all deployments using an affected version, including default configurations. |
| NetScaler ADC and NetScaler Gateway 13.1 | Before 13.1-64.23 | ||
| NetScaler ADC 14.1 FIPS | Before 14.1-73.37 FIPS | ||
| NetScaler ADC 13.1 FIPS and NDcPP | Before 13.1-37.279 | ||
| CVE-2026-88772 | NetScaler ADC and NetScaler Gateway 14.1 | Before 14.1-73.37 | DTLS enabled; DTLS is enabled by default on VPN virtual servers. |
| NetScaler ADC and NetScaler Gateway 13.1 | Before 13.1-64.23 | ||
| NetScaler ADC 14.1 FIPS | Before 14.1-73.37 FIPS | ||
| NetScaler ADC 13.1 FIPS and NDcPP | Before 13.1-37.279 |
Firms can report suspicious activity or cyber incidents to FINRA by contacting their Risk Monitoring Analyst, via the Financial Intelligence Fusion Center (FIFC), or by filing a regulatory tip.
Firms should also review their patch management and incident response programs to ensure they have processes in place to respond to this type of security incident, including appropriate policies, procedures and controls. Related effective practices can be found in FINRA’s recently published Cybersecurity Effective Practices.
For questions related to this Alert or other cybersecurity-related topics, contact the FINRA Cyber and Operational REsilience (CORE) team. Both the FBI and CISA urge you to promptly report cyber incidents to a local FBI Field Office, the FBI Internet Crime Complaint Center (IC3) at IC3.gov, or CISA via CISA’s 24/7 Operations Center ([email protected] or 888-282-0870).
Do Your Firm’s IT and Information Security Staff Have Access to the Latest Cybersecurity Intelligence?
FINRA's Financial Intelligence Fusion Center (FIFC) is a secure portal where member firms can access and share timely, actionable cybersecurity and fraud threat intelligence. FIFC portal access can be entitled to staff at your member firm and its affiliates, so intelligence is shared with the appropriate people. Visit fifc.finra.org to learn more and to sign up.
Note: This Alert does not create new legal or regulatory requirements or new interpretations of existing requirements, nor does it relieve firms of any existing obligations under federal securities laws, regulations, and FINRA rules. Member firms may consider the information in this Alert in developing new, or modifying existing, policies and procedures that are reasonably designed to achieve compliance with relevant regulatory obligations based on the firm’s size and business model.