Citrix NetScaler Zero-Days CVE-2026-88771 & CVE-2026-88772 Under Active Global Exploitation

·

On September 27, 2026, Citrix confirmed that two critical remote code execution flaws in NetScaler ADC and NetScaler Gateway — CVE-2026-88771 and CVE-2026-88772, both rated CVSS 9.5 — are being exploited as zero-days. The same day, CISA added both to the Known Exploited Vulnerabilities catalog and ordered Federal Civilian Executive Branch agencies to remediate by September 30, 2026.

Both bugs are unauthenticated and reachable across the network. CVE-2026-88771 is an input-validation flaw that lets an attacker run arbitrary commands; CVE-2026-88772 is a memory-buffer flaw that yields RCE or denial of service when DTLS is enabled — the default on VPN virtual servers. Shadowserver counts roughly 23,000 internet-exposed NetScaler instances.

If you run NetScaler at the edge, treat every appliance as potentially compromised. Citrix warns its indicators may be of limited forensic value, so patching alone is not incident response. This brief covers the flaws, the affected/fixed matrix, a DFIR runbook, hunt queries, ATT&CK mapping, and hardening.

◈ Table of Contents

01 Threat Snapshot 02 Disclosure & Exploitation Timeline 03 Affected Products & Versions 04 Initial Access Vector 05 Technical Deep Dive 06 Post-Exploitation Tradecraft 07 Exposure & Scope 08 DFIR Investigation Steps 09 Indicators & Artifact Locations 10 Detection & Hunt Queries 11 MITRE ATT&CK Mapping 12 Mitigation & Hardening 13 Sources & References
🎯

01 · THREAT SNAPSHOT

Profile

NetScaler ADC and Gateway sit at the network edge as reverse proxies, load balancers, and VPN/ICA access gateways. That position makes them a perennial nation-state and ransomware target: a single pre-auth RCE on the box hands an attacker a foothold in front of the entire estate, plus the credentials and sessions of everyone who authenticates through it. This is the same appliance family behind CitrixBleed (CVE-2023-4966) and CitrixBleed 2 (CVE-2025-5777).

AttributeDetail
VulnerabilitiesCVE-2026-88771 CVSS 9.5 · CVE-2026-88772 CVSS 9.5
ClassCWE-20 improper input validation · CWE-119 improper memory-buffer restriction
ImpactUnauthenticated remote code execution (88771); RCE or denial of service (88772)
Auth requiredNone — pre-authentication, network-reachable
Exploitation statusActive in the wild as zero-days; CISA KEV-listed 2026-09-27
Vendor advisoryCitrix bulletin CTX697096
AttributionUnattributed — global, opportunistic exploitation reported by multiple parties
Exposed devices~23,000 internet-facing instances (Shadowserver): ~22,000 ADC, 1,500+ Gateway

CVE-2026-88771 affects default configurations with no special prerequisite. CVE-2026-88772 requires DTLS, which is enabled by default on VPN virtual servers — so the majority of remote-access deployments are exposed to both.

🕔

02 · DISCLOSURE & EXPLOITATION TIMELINE

Chronology
T
How the week unfolded
Sep 2026
  • 1Late Sep 2026 (pre-disclosure): Exploitation activity against internet-facing NetScaler appliances is observed before any public advisory — the hallmark of a zero-day. Researchers, including watchTowr, begin verifying rumours with authoritative sources.
  • 2Sep 27, 2026: Citrix publishes bulletin CTX697096, confirming both flaws are being exploited and releasing fixed builds. Administrators receive private warnings to take exposed appliances offline immediately.
  • 3Sep 27, 2026: CISA adds CVE-2026-88771 and CVE-2026-88772 to the KEV catalog and issues an emergency directive to FCEB agencies.
  • 4Sep 28, 2026: BleepingComputer and The Hacker News report global exploitation; Shadowserver telemetry pegs internet exposure near 23,000 appliances.
  • 5Sep 30, 2026: Federal remediation deadline. This is a floor, not a target — every hour of exposure since disclosure is dwell time for an attacker.

Since November 2021, CISA has catalogued 26 actively exploited Citrix vulnerabilities, six of them abused by ransomware crews. Treat any NetScaler KEV entry as a "patch today" event, not a maintenance-window item.

📦

03 · AFFECTED PRODUCTS & VERSIONS

Version matrix

Both CVEs share the same affected/fixed matrix. There is no configuration workaround that fully mitigates CVE-2026-88771; upgrading to a fixed build is the only supported remediation.

Product / TrainAffectedFixed build
NetScaler ADC & Gateway 14.1before 14.1-73.3714.1-73.37 and later FIX
NetScaler ADC & Gateway 13.1before 13.1-64.2313.1-64.23 and later FIX
NetScaler ADC 14.1 FIPSbefore 14.1-73.37 FIPS14.1-73.37 FIPS and later FIX
NetScaler ADC 13.1 FIPS / NDcPPbefore 13.1-37.27913.1-37.279 and later FIX
NetScaler ADC & Gateway 13.0End-of-life EOLNo fix — migrate to a supported train
NetScaler ADC & Gateway 12.1End-of-life EOLNo fix — migrate to a supported train
Secure Private Access (hybrid, on-prem)Affected where it relies on an on-prem NetScaler instanceUpdate the underlying NetScaler build

Citrix-managed cloud NetScaler and Adaptive Authentication are updated by the vendor. Everything you self-host at the edge is your responsibility — and EOL 12.1 / 13.0 boxes will never receive a fix. If you are still running them, they are the first thing an attacker finds.

🚪

04 · INITIAL ACCESS VECTOR

Entry point
A
Directly reachable, pre-auth, at the edge
T1190

Neither flaw requires credentials, a valid session, or user interaction. An attacker sends a crafted request to the management, AAA, or VPN virtual server exposed to the internet and reaches vulnerable code before authentication. This maps cleanly to MITRE T1190 — Exploit Public-Facing Application.

Because the appliance terminates VPN and ICA proxy sessions, a successful exploit does more than land code on one host. The attacker inherits a position that can read session material, harvest credentials submitted through the AAA logon page, and pivot into the internal network the appliance was built to protect. That is why NetScaler compromise so often precedes ransomware and large-scale data theft.

Do not assume "internal only" appliances are safe. Management interfaces exposed to a flat internal network, or reachable through a compromised jump host, are exploitable by an attacker who is already inside.

🔬

05 · TECHNICAL DEEP DIVE

How it works

Both flaws score CVSS v4.0 9.5, but they differ in class and trigger condition. The side-by-side below shows why they are best treated as a paired threat rather than two independent bugs.

MetricCVE-2026-88771CVE-2026-88772
CWE classCWE-20 input validationCWE-119 memory buffer
CVSS v4.0 base9.5 CRITICAL9.5 CRITICAL
Attack complexityAC:L (low)AC:H (high — memory grooming)
Attack requirementAT:P (present)AT:N (none)
Privileges / UIPR:N · UI:NPR:N · UI:N
PrerequisiteNone — default configDTLS enabled (default on VPN vserver)
Primary impactArbitrary command executionRCE or denial of service
1
CVE-2026-88771 — improper input validation (CWE-20)
CVSS 9.5

NVD classes this as improper input validation leading to arbitrary command execution by an unauthenticated attacker. The CVSS v4.0 vector is AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H — network-attackable, low complexity, no privileges, no user interaction, with high impact to confidentiality, integrity and availability of both the appliance and downstream systems.

In practice, CWE-20 on an appliance like this means attacker-controlled input reaches a code path that treats it as trusted — most commonly a request field that is passed into a system call, a template resolver, or a management action without proper sanitisation. Because the flaw sits in a default-reachable code path, no non-standard feature has to be enabled for it to fire.

The AT:P ("Attack Requirements: Present") bit in the v4.0 vector signals the attacker needs some condition to line up — a race, a specific request sequence, or state — but this only marginally raises the bar. Reliable weaponisation of NetScaler bugs has historically followed disclosure within days.

2
CVE-2026-88772 — memory-buffer overflow via DTLS (CWE-119)
CVSS 9.5

This is a classic memory-safety defect: improper restriction of operations within the bounds of a memory buffer. Its CVSS v4.0 vector is AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H — note AC:H (high complexity), reflecting the memory-grooming a reliable overflow requires, offset by AT:N (no special attack requirement).

The trigger is DTLS — Datagram TLS running over UDP for VPN virtual servers, and enabled by default. An attacker who can reach the DTLS listener sends malformed handshake or record data that overflows a buffer inside the packet-processing engine. Depending on how the corruption lands, the result is either code execution in the context of the appliance's network stack or a crash that takes the box (and everyone's VPN) offline — the DoS half of the CVE.

DEFENSIVE — reduce the CVE-2026-88772 attack surface if you cannot patch instantly
# NetScaler CLI — disable DTLS on an affected VPN vserver as an interim risk reduction # (breaks EDT/UDP transport for Citrix sessions; TCP fallback still works) > set vpn vserver VPN_VSRV -dtls OFF > save ns config # Verify no vserver still advertises DTLS > show vpn vserver | grep -i dtls

Disabling DTLS lowers exposure to CVE-2026-88772 only. It does nothing for CVE-2026-88771, which needs no such prerequisite. Treat this as a stopgap while you schedule the upgrade — not a substitute for it.

Figure 1 — Generalised attack flow for edge-appliance pre-auth RCE. Weaponisation detail is withheld; no exploit code is published here.
🧬

06 · POST-EXPLOITATION TRADECRAFT

After the foothold

No campaign-specific IOCs have been published for these two CVEs yet, and this brief invents none. The tradecraft below is the known behaviour pattern from prior NetScaler compromises (CitrixBleed and follow-ons) — use it to direct hunting, not as confirmed indicators of this campaign.

🔑

Session & token theft

Attackers scrape live authentication sessions and tokens from appliance memory to replay valid sessions, bypassing MFA entirely. A patched box with stolen sessions is still owned.

🐚

Web shells & scripts

Dropped PHP/scripts under the web GUI or VPN portal directories provide re-entry after reboot. Files with recent modification times in appliance web roots are a top hunt target.

🧾

Config & secret exfil

The running config holds LDAP bind creds, RADIUS secrets, and certificate keys. Expect these to be exfiltrated and reused against your directory and VPN.

👤

Rogue accounts

Creation of new local system users or additional admin bindings for persistence that survives a firmware update if the config is restored from a tainted backup.

🧹

Log tampering

Selective clearing or truncation of ns.log and shell history to frustrate forensics. Gaps in log continuity are themselves an indicator.

🎯

Internal pivot

Using harvested credentials and the appliance's trusted network position to reach domain controllers, file shares, and backup infrastructure — the pre-ransomware staging pattern.

Citrix has stated its indicators of compromise "might be of limited forensic value" — a strong hint that skilled operators are cleaning up after themselves. Assume you must prove innocence, not prove compromise.

🌐

07 · EXPOSURE & SCOPE

Attack surface

Shadowserver telemetry places internet-exposed NetScaler around 23,000 instances — the pool an opportunistic operator can mass-scan and hit before defenders finish patching. Distribution skews heavily to ADC appliances.

Bar chart of internet-exposed NetScaler ADC vs Gateway instances
Figure 2 — Approximate internet exposure by product (source: Shadowserver). Rounded figures.
Exposure factorDetail
Total exposed~23,000 internet-facing NetScaler instances
By product~22,000 ADC · 1,500+ Gateway
Default-vulnerable88771 hits default configs; 88772 hits any VPN vserver with DTLS (default on)
Historical precedent26 Citrix CVEs on KEV since Nov 2021; six tied to ransomware campaigns
🔎

08 · DFIR INVESTIGATION STEPS

Responder runbook
1
Preserve before you patch
Order matters

Citrix explicitly recommends engaging experienced forensic investigators before applying the update, because patching and rebooting destroys volatile evidence. Snapshot VPX/virtual instances, capture the running config, and export logs off-box first.

# Capture running + saved config and technical support bundle BEFORE upgrade > show ns runningConfig # copy full output off-box > show techsupport # generates collector archive under /var/tmp/support # From the shell, hash and export the archive to your evidence store $ sha256 /var/tmp/support/collector_*.tar.gz
2
Enumerate and terminate all active sessions
Kill replay

Stolen sessions survive a patch. After capturing evidence, terminate every ICA and PCoIP/VPN session and force re-authentication so replayed tokens are useless.

# List then kill active sessions (do this AFTER evidence capture) > show icaConnection > show aaa session > kill icaconnection -all > kill aaa session -all > kill pcoipConnection -all
3
Hunt for on-box persistence
Shell review

From the appliance BSD shell, look for files that should not exist in web-served directories and for shell processes spawned by the packet engine. Focus on recent modification times relative to the disclosure window.

# Recently modified files in VPN portal / GUI web roots (common web-shell drop sites) $ find /var/netscaler/logon /netscaler/ns_gui -type f -mtime -14 -name '*.php' -o -name '*.pl' # Unexpected shells or interpreters as children of the packet engine (nsppe) $ ps -auxww | egrep '(sh|bash|perl|python|nc)' | grep -v grep # Review crontab and rc scripts for attacker-added persistence $ crontab -l; cat /nsconfig/rc.netscaler /etc/rc.d/* 2>/dev/null

Compare the current running config against your last known-good backup line by line. New system users, extra admin bindings, unfamiliar responder/rewrite policies, or added authentication actions are prime persistence indicators.

4
Rotate every secret the appliance held
Assume theft

If compromise is suspected, treat all secrets stored on or transiting the appliance as burned. The recommended response sequence is: isolate, revoke credentials and access, investigate connected systems, rebuild firmware, then rotate.

  • 1Rotate all local appliance passwords and any service accounts (LDAP/RADIUS/TACACS bind accounts).
  • 2Reissue SSL certificates and private keys hosted on the appliance — assume the keys are exfiltrated.
  • 3Rotate encryption keys and any pre-shared/RADIUS secrets referenced in the config.
  • 4Force credential reset for users who authenticated through the AAA logon page during the exposure window.
📌

09 · INDICATORS & ARTIFACT LOCATIONS

Where to look

No file hashes, IPs, or domains have been publicly attributed to this specific campaign — so none are listed here. What follows are the appliance artifact locations and log fields where evidence of exploitation of this device class typically lives.

Artifact / LocationWhat to check
/var/log/ns.logGaps, truncation, or bursts of errors around the exposure window; unexpected CLI command events
/var/netscaler/logon/*New or recently modified files in the VPN portal web root (web-shell drop location)
/netscaler/ns_gui/*Unexpected scripts or modified GUI assets served by the management interface
/var/nstmp, /var/tmpStaged archives, unfamiliar tarballs, or attacker tooling awaiting exfiltration
Running config diffNew local users, extra admin bindings, unfamiliar authentication actions, responder/rewrite policies
Process treeShell/interpreter processes (sh, perl, python, nc) parented by appliance daemons
AAA / VPN auth logsSuccessful sessions with no matching MFA event — signature of session/token replay
Crash / core filesRepeated packet-engine crashes may indicate CVE-2026-88772 exploitation attempts (DoS half)
🔗
Citrix Bulletin CTX697096
Official advisory · fixed builds · vendor IOC guidance via NetScaler Console
OPEN ▸
🛰️

10 · DETECTION & HUNT QUERIES

KQL · SPL

These assume NetScaler ns.log is forwarded via syslog into your SIEM. Each query is paired KQL (Microsoft Sentinel) and SPL (Splunk) with a one-line purpose. Tune thresholds to your baseline.

DETECTS: anomalous request volume to the NetScaler management/AAA/VPN endpoints from a single source — mass-scan or exploitation attempts.
KQL — Microsoft Sentinel
Syslog | where TimeGenerated > ago(14d) | where Computer has_any ("ns", "netscaler") | where SyslogMessage has_any ("/vpn/", "/aaa/", "/nCPClientRequest", "dtls") | extend src = extract(@"(\d{1,3}(?:\.\d{1,3}){3})", 1, SyslogMessage) | summarize hits = count() by src, bin(TimeGenerated, 5m) | where hits > 200 | sort by hits desc
SPL — Splunk
index=netscaler ("/vpn/" OR "/aaa/" OR "/nCPClientRequest" OR dtls) earliest=-14d | rex field=_raw "(?<src>\d{1,3}(?:\.\d{1,3}){3})" | bucket _time span=5m | stats count as hits by src, _time | where hits > 200 | sort - hits
DETECTS: successful AAA/VPN authentication events that lack a corresponding MFA challenge — a signature of stolen-session/token replay.
KQL — Microsoft Sentinel
Syslog | where Computer has_any ("ns", "netscaler") | where SyslogMessage has "LOGIN" and SyslogMessage has_any ("AAA", "VPN") | extend user = extract(@"User ([^\s]+)", 1, SyslogMessage) | where isnotempty(user) | join kind=leftanti ( Syslog | where SyslogMessage has "nFactor" or SyslogMessage has "OTP" | extend user = extract(@"User ([^\s]+)", 1, SyslogMessage) ) on user | project TimeGenerated, user, SyslogMessage
SPL — Splunk
index=netscaler LOGIN (AAA OR VPN) | rex field=_raw "User (?<user>[^\s]+)" | search NOT [ search index=netscaler (nFactor OR OTP) | rex field=_raw "User (?<user>[^\s]+)" | return 10000 user ] | table _time user _raw
DETECTS: repeated packet-engine crashes / core dumps consistent with CVE-2026-88772 DTLS overflow attempts.
KQL — Microsoft Sentinel
Syslog | where Computer has_any ("ns", "netscaler") | where SyslogMessage has_any ("core dump", "nsppe", "segfault", "restart") | summarize events = count() by bin(TimeGenerated, 1h), Computer | where events > 3
SPL — Splunk
index=netscaler ("core dump" OR nsppe OR segfault OR restart) | bucket _time span=1h | stats count as events by _time, host | where events > 3

Pair these SIEM rules with an external attack-surface check: alert whenever a NetScaler management, AAA, or DTLS listener becomes reachable from the internet. Most successful edge-appliance breaches start with an interface that was never meant to be public.

🗺️

11 · MITRE ATT&CK MAPPING

TTPs
TacticTechniqueID
ReconnaissanceActive Scanning: Wordlist / Vulnerability ScanningT1595
Initial AccessExploit Public-Facing ApplicationT1190
ExecutionCommand and Scripting Interpreter: Unix ShellT1059.004
PersistenceServer Software Component: Web ShellT1505.003
PersistenceCreate Account: Local AccountT1136.001
Credential AccessUnsecured Credentials: Credentials In Files (config secrets)T1552.001
Credential AccessSteal Web Session Cookie / session token replayT1539
Defense EvasionIndicator Removal: Clear Logs / File DeletionT1070
ImpactEndpoint Denial of Service (CVE-2026-88772 DoS path)T1499
Lateral MovementRemote Services (via harvested credentials)T1021
🛡️

12 · MITIGATION & HARDENING

Fix & harden
1
Patch to a fixed build now
Priority 1

Upgrade to 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, or 13.1-37.279 FIPS/NDcPP or later per your train. There is no full config workaround for CVE-2026-88771 — the patch is the fix. If you run EOL 12.1 or 13.0, migrate to a supported train; no fix is coming for those.

2
Assume breach — do not stop at patching
Priority 1

Any appliance internet-exposed since disclosure should be triaged as potentially compromised. Run the DFIR runbook (Phase 08): preserve evidence, kill sessions, hunt persistence, rotate every secret. A patched appliance with a live web shell or replayed session is still owned.

3
Shrink the edge footprint
Priority 2
  • 1Never expose the NetScaler management interface (NSIP) to the internet — restrict it to an out-of-band admin network.
  • 2Disable DTLS on VPN vservers if EDT/UDP transport is not required, reducing the CVE-2026-88772 surface.
  • 3Enforce nFactor MFA on AAA logon and monitor for logins lacking an MFA event (Phase 10).
  • 4Forward ns.log to your SIEM and alert on config changes, new users, and packet-engine crashes.
Remediation complete when
  • All internet-facing appliances run a fixed build (or EOL boxes are decommissioned)
  • Active sessions terminated and all appliance-held secrets rotated
  • Config diff against known-good shows zero unexplained changes
  • Web roots and process tree reviewed; no web shells or rogue processes found
  • SIEM detections for the three hunt queries are live and baselined
📚

13 · SOURCES & REFERENCES

Primary
The Hacker News — CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally BleepingComputer — CISA orders feds to patch exploited Citrix flaws by Wednesday BleepingComputer — Citrix confirms two NetScaler RCE zero-days exploited in attacks Citrix — Security Bulletin CTX697096 (NetScaler ADC & Gateway) NVD — CVE-2026-88771 NVD — CVE-2026-88772 CISA — Known Exploited Vulnerabilities Catalog Shadowserver Foundation — internet exposure telemetry

Run an exposed NetScaler? Confirm you are on a fixed build, then hunt — a patch does not evict an attacker who already has a session or web shell. Use the CyberHawk IOC Scanner to check artifacts against known-bad, and track live edge-appliance exploitation on the CyberHawk Threat Intel feed. For the full responder playbook, browse our SOP library.

◈ Stay Connected

Follow CyberHawk Threat Intel for threat intelligence, deployment guides and hands-on SOC tooling content.

🌐 Website ▶️ YouTube ▶️ YouTube (2) 𝕏 Twitter / X ♪ TikTok ✈️ Telegram
🔍 IOC Scanner 🛠️ Live Tools 📚 Courses 🚨 Threat Intel 📝 Blog 📋 SOPs

"They can't exploit you if you are the Exploit."