On September 27, 2026, Citrix confirmed that two critical remote code execution flaws in NetScaler ADC and NetScaler Gateway — CVE-2026-88771 and CVE-2026-88772, both rated CVSS 9.5 — are being exploited as zero-days. The same day, CISA added both to the Known Exploited Vulnerabilities catalog and ordered Federal Civilian Executive Branch agencies to remediate by September 30, 2026.
Both bugs are unauthenticated and reachable across the network. CVE-2026-88771 is an input-validation flaw that lets an attacker run arbitrary commands; CVE-2026-88772 is a memory-buffer flaw that yields RCE or denial of service when DTLS is enabled — the default on VPN virtual servers. Shadowserver counts roughly 23,000 internet-exposed NetScaler instances.
If you run NetScaler at the edge, treat every appliance as potentially compromised. Citrix warns its indicators may be of limited forensic value, so patching alone is not incident response. This brief covers the flaws, the affected/fixed matrix, a DFIR runbook, hunt queries, ATT&CK mapping, and hardening.
◈ Table of Contents
01 · THREAT SNAPSHOT
ProfileNetScaler ADC and Gateway sit at the network edge as reverse proxies, load balancers, and VPN/ICA access gateways. That position makes them a perennial nation-state and ransomware target: a single pre-auth RCE on the box hands an attacker a foothold in front of the entire estate, plus the credentials and sessions of everyone who authenticates through it. This is the same appliance family behind CitrixBleed (CVE-2023-4966) and CitrixBleed 2 (CVE-2025-5777).
| Attribute | Detail |
|---|---|
| Vulnerabilities | CVE-2026-88771 CVSS 9.5 · CVE-2026-88772 CVSS 9.5 |
| Class | CWE-20 improper input validation · CWE-119 improper memory-buffer restriction |
| Impact | Unauthenticated remote code execution (88771); RCE or denial of service (88772) |
| Auth required | None — pre-authentication, network-reachable |
| Exploitation status | Active in the wild as zero-days; CISA KEV-listed 2026-09-27 |
| Vendor advisory | Citrix bulletin CTX697096 |
| Attribution | Unattributed — global, opportunistic exploitation reported by multiple parties |
| Exposed devices | ~23,000 internet-facing instances (Shadowserver): ~22,000 ADC, 1,500+ Gateway |
CVE-2026-88771 affects default configurations with no special prerequisite. CVE-2026-88772 requires DTLS, which is enabled by default on VPN virtual servers — so the majority of remote-access deployments are exposed to both.
02 · DISCLOSURE & EXPLOITATION TIMELINE
Chronology- 1Late Sep 2026 (pre-disclosure): Exploitation activity against internet-facing NetScaler appliances is observed before any public advisory — the hallmark of a zero-day. Researchers, including watchTowr, begin verifying rumours with authoritative sources.
- 2Sep 27, 2026: Citrix publishes bulletin
CTX697096, confirming both flaws are being exploited and releasing fixed builds. Administrators receive private warnings to take exposed appliances offline immediately. - 3Sep 27, 2026: CISA adds CVE-2026-88771 and CVE-2026-88772 to the KEV catalog and issues an emergency directive to FCEB agencies.
- 4Sep 28, 2026: BleepingComputer and The Hacker News report global exploitation; Shadowserver telemetry pegs internet exposure near 23,000 appliances.
- 5Sep 30, 2026: Federal remediation deadline. This is a floor, not a target — every hour of exposure since disclosure is dwell time for an attacker.
Since November 2021, CISA has catalogued 26 actively exploited Citrix vulnerabilities, six of them abused by ransomware crews. Treat any NetScaler KEV entry as a "patch today" event, not a maintenance-window item.
03 · AFFECTED PRODUCTS & VERSIONS
Version matrixBoth CVEs share the same affected/fixed matrix. There is no configuration workaround that fully mitigates CVE-2026-88771; upgrading to a fixed build is the only supported remediation.
| Product / Train | Affected | Fixed build |
|---|---|---|
| NetScaler ADC & Gateway 14.1 | before 14.1-73.37 | 14.1-73.37 and later FIX |
| NetScaler ADC & Gateway 13.1 | before 13.1-64.23 | 13.1-64.23 and later FIX |
| NetScaler ADC 14.1 FIPS | before 14.1-73.37 FIPS | 14.1-73.37 FIPS and later FIX |
| NetScaler ADC 13.1 FIPS / NDcPP | before 13.1-37.279 | 13.1-37.279 and later FIX |
| NetScaler ADC & Gateway 13.0 | End-of-life EOL | No fix — migrate to a supported train |
| NetScaler ADC & Gateway 12.1 | End-of-life EOL | No fix — migrate to a supported train |
| Secure Private Access (hybrid, on-prem) | Affected where it relies on an on-prem NetScaler instance | Update the underlying NetScaler build |
Citrix-managed cloud NetScaler and Adaptive Authentication are updated by the vendor. Everything you self-host at the edge is your responsibility — and EOL 12.1 / 13.0 boxes will never receive a fix. If you are still running them, they are the first thing an attacker finds.
04 · INITIAL ACCESS VECTOR
Entry pointNeither flaw requires credentials, a valid session, or user interaction. An attacker sends a crafted request to the management, AAA, or VPN virtual server exposed to the internet and reaches vulnerable code before authentication. This maps cleanly to MITRE T1190 — Exploit Public-Facing Application.
Because the appliance terminates VPN and ICA proxy sessions, a successful exploit does more than land code on one host. The attacker inherits a position that can read session material, harvest credentials submitted through the AAA logon page, and pivot into the internal network the appliance was built to protect. That is why NetScaler compromise so often precedes ransomware and large-scale data theft.
Do not assume "internal only" appliances are safe. Management interfaces exposed to a flat internal network, or reachable through a compromised jump host, are exploitable by an attacker who is already inside.
05 · TECHNICAL DEEP DIVE
How it worksBoth flaws score CVSS v4.0 9.5, but they differ in class and trigger condition. The side-by-side below shows why they are best treated as a paired threat rather than two independent bugs.
| Metric | CVE-2026-88771 | CVE-2026-88772 |
|---|---|---|
| CWE class | CWE-20 input validation | CWE-119 memory buffer |
| CVSS v4.0 base | 9.5 CRITICAL | 9.5 CRITICAL |
| Attack complexity | AC:L (low) | AC:H (high — memory grooming) |
| Attack requirement | AT:P (present) | AT:N (none) |
| Privileges / UI | PR:N · UI:N | PR:N · UI:N |
| Prerequisite | None — default config | DTLS enabled (default on VPN vserver) |
| Primary impact | Arbitrary command execution | RCE or denial of service |
NVD classes this as improper input validation leading to arbitrary command execution by an unauthenticated attacker. The CVSS v4.0 vector is AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H — network-attackable, low complexity, no privileges, no user interaction, with high impact to confidentiality, integrity and availability of both the appliance and downstream systems.
In practice, CWE-20 on an appliance like this means attacker-controlled input reaches a code path that treats it as trusted — most commonly a request field that is passed into a system call, a template resolver, or a management action without proper sanitisation. Because the flaw sits in a default-reachable code path, no non-standard feature has to be enabled for it to fire.
The AT:P ("Attack Requirements: Present") bit in the v4.0 vector signals the attacker needs some condition to line up — a race, a specific request sequence, or state — but this only marginally raises the bar. Reliable weaponisation of NetScaler bugs has historically followed disclosure within days.
This is a classic memory-safety defect: improper restriction of operations within the bounds of a memory buffer. Its CVSS v4.0 vector is AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H — note AC:H (high complexity), reflecting the memory-grooming a reliable overflow requires, offset by AT:N (no special attack requirement).
The trigger is DTLS — Datagram TLS running over UDP for VPN virtual servers, and enabled by default. An attacker who can reach the DTLS listener sends malformed handshake or record data that overflows a buffer inside the packet-processing engine. Depending on how the corruption lands, the result is either code execution in the context of the appliance's network stack or a crash that takes the box (and everyone's VPN) offline — the DoS half of the CVE.
Disabling DTLS lowers exposure to CVE-2026-88772 only. It does nothing for CVE-2026-88771, which needs no such prerequisite. Treat this as a stopgap while you schedule the upgrade — not a substitute for it.
06 · POST-EXPLOITATION TRADECRAFT
After the footholdNo campaign-specific IOCs have been published for these two CVEs yet, and this brief invents none. The tradecraft below is the known behaviour pattern from prior NetScaler compromises (CitrixBleed and follow-ons) — use it to direct hunting, not as confirmed indicators of this campaign.
Session & token theft
Attackers scrape live authentication sessions and tokens from appliance memory to replay valid sessions, bypassing MFA entirely. A patched box with stolen sessions is still owned.
Web shells & scripts
Dropped PHP/scripts under the web GUI or VPN portal directories provide re-entry after reboot. Files with recent modification times in appliance web roots are a top hunt target.
Config & secret exfil
The running config holds LDAP bind creds, RADIUS secrets, and certificate keys. Expect these to be exfiltrated and reused against your directory and VPN.
Rogue accounts
Creation of new local system users or additional admin bindings for persistence that survives a firmware update if the config is restored from a tainted backup.
Log tampering
Selective clearing or truncation of ns.log and shell history to frustrate forensics. Gaps in log continuity are themselves an indicator.
Internal pivot
Using harvested credentials and the appliance's trusted network position to reach domain controllers, file shares, and backup infrastructure — the pre-ransomware staging pattern.
Citrix has stated its indicators of compromise "might be of limited forensic value" — a strong hint that skilled operators are cleaning up after themselves. Assume you must prove innocence, not prove compromise.
07 · EXPOSURE & SCOPE
Attack surfaceShadowserver telemetry places internet-exposed NetScaler around 23,000 instances — the pool an opportunistic operator can mass-scan and hit before defenders finish patching. Distribution skews heavily to ADC appliances.
| Exposure factor | Detail |
|---|---|
| Total exposed | ~23,000 internet-facing NetScaler instances |
| By product | ~22,000 ADC · 1,500+ Gateway |
| Default-vulnerable | 88771 hits default configs; 88772 hits any VPN vserver with DTLS (default on) |
| Historical precedent | 26 Citrix CVEs on KEV since Nov 2021; six tied to ransomware campaigns |
08 · DFIR INVESTIGATION STEPS
Responder runbookCitrix explicitly recommends engaging experienced forensic investigators before applying the update, because patching and rebooting destroys volatile evidence. Snapshot VPX/virtual instances, capture the running config, and export logs off-box first.
Stolen sessions survive a patch. After capturing evidence, terminate every ICA and PCoIP/VPN session and force re-authentication so replayed tokens are useless.
From the appliance BSD shell, look for files that should not exist in web-served directories and for shell processes spawned by the packet engine. Focus on recent modification times relative to the disclosure window.
Compare the current running config against your last known-good backup line by line. New system users, extra admin bindings, unfamiliar responder/rewrite policies, or added authentication actions are prime persistence indicators.
If compromise is suspected, treat all secrets stored on or transiting the appliance as burned. The recommended response sequence is: isolate, revoke credentials and access, investigate connected systems, rebuild firmware, then rotate.
- 1Rotate all local appliance passwords and any service accounts (LDAP/RADIUS/TACACS bind accounts).
- 2Reissue SSL certificates and private keys hosted on the appliance — assume the keys are exfiltrated.
- 3Rotate encryption keys and any pre-shared/RADIUS secrets referenced in the config.
- 4Force credential reset for users who authenticated through the AAA logon page during the exposure window.
09 · INDICATORS & ARTIFACT LOCATIONS
Where to lookNo file hashes, IPs, or domains have been publicly attributed to this specific campaign — so none are listed here. What follows are the appliance artifact locations and log fields where evidence of exploitation of this device class typically lives.
| Artifact / Location | What to check |
|---|---|
| /var/log/ns.log | Gaps, truncation, or bursts of errors around the exposure window; unexpected CLI command events |
| /var/netscaler/logon/* | New or recently modified files in the VPN portal web root (web-shell drop location) |
| /netscaler/ns_gui/* | Unexpected scripts or modified GUI assets served by the management interface |
| /var/nstmp, /var/tmp | Staged archives, unfamiliar tarballs, or attacker tooling awaiting exfiltration |
| Running config diff | New local users, extra admin bindings, unfamiliar authentication actions, responder/rewrite policies |
| Process tree | Shell/interpreter processes (sh, perl, python, nc) parented by appliance daemons |
| AAA / VPN auth logs | Successful sessions with no matching MFA event — signature of session/token replay |
| Crash / core files | Repeated packet-engine crashes may indicate CVE-2026-88772 exploitation attempts (DoS half) |
10 · DETECTION & HUNT QUERIES
KQL · SPLThese assume NetScaler ns.log is forwarded via syslog into your SIEM. Each query is paired KQL (Microsoft Sentinel) and SPL (Splunk) with a one-line purpose. Tune thresholds to your baseline.
Pair these SIEM rules with an external attack-surface check: alert whenever a NetScaler management, AAA, or DTLS listener becomes reachable from the internet. Most successful edge-appliance breaches start with an interface that was never meant to be public.
11 · MITRE ATT&CK MAPPING
TTPs| Tactic | Technique | ID |
|---|---|---|
| Reconnaissance | Active Scanning: Wordlist / Vulnerability Scanning | T1595 |
| Initial Access | Exploit Public-Facing Application | T1190 |
| Execution | Command and Scripting Interpreter: Unix Shell | T1059.004 |
| Persistence | Server Software Component: Web Shell | T1505.003 |
| Persistence | Create Account: Local Account | T1136.001 |
| Credential Access | Unsecured Credentials: Credentials In Files (config secrets) | T1552.001 |
| Credential Access | Steal Web Session Cookie / session token replay | T1539 |
| Defense Evasion | Indicator Removal: Clear Logs / File Deletion | T1070 |
| Impact | Endpoint Denial of Service (CVE-2026-88772 DoS path) | T1499 |
| Lateral Movement | Remote Services (via harvested credentials) | T1021 |
12 · MITIGATION & HARDENING
Fix & hardenUpgrade to 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, or 13.1-37.279 FIPS/NDcPP or later per your train. There is no full config workaround for CVE-2026-88771 — the patch is the fix. If you run EOL 12.1 or 13.0, migrate to a supported train; no fix is coming for those.
Any appliance internet-exposed since disclosure should be triaged as potentially compromised. Run the DFIR runbook (Phase 08): preserve evidence, kill sessions, hunt persistence, rotate every secret. A patched appliance with a live web shell or replayed session is still owned.
- 1Never expose the NetScaler management interface (NSIP) to the internet — restrict it to an out-of-band admin network.
- 2Disable DTLS on VPN vservers if EDT/UDP transport is not required, reducing the CVE-2026-88772 surface.
- 3Enforce nFactor MFA on AAA logon and monitor for logins lacking an MFA event (Phase 10).
- 4Forward
ns.logto your SIEM and alert on config changes, new users, and packet-engine crashes.
- All internet-facing appliances run a fixed build (or EOL boxes are decommissioned)
- Active sessions terminated and all appliance-held secrets rotated
- Config diff against known-good shows zero unexplained changes
- Web roots and process tree reviewed; no web shells or rogue processes found
- SIEM detections for the three hunt queries are live and baselined
13 · SOURCES & REFERENCES
PrimaryRun an exposed NetScaler? Confirm you are on a fixed build, then hunt — a patch does not evict an attacker who already has a session or web shell. Use the CyberHawk IOC Scanner to check artifacts against known-bad, and track live edge-appliance exploitation on the CyberHawk Threat Intel feed. For the full responder playbook, browse our SOP library.
◈ Stay Connected
Follow CyberHawk Threat Intel for threat intelligence, deployment guides and hands-on SOC tooling content.
"They can't exploit you if you are the Exploit."