Citrix NetScaler Zero-Days (CVE-2026-88771) Actively Exploited

Citrix Patches Two Critical NetScaler Zero-Days Under Active Attack

CRITICAL
September 28, 2026
7m read
VulnerabilityCyberattackPatch Management

Related Entities

Organizations

Other

Known Exploited Vulnerabilities (KEV) Catalog

CVE Identifiers

CVE-2026-88771
CRITICAL
CVSS:9.5
CVE-2026-88772
CRITICAL
CVSS:9.5
CVE-2026-88773
CVSS:9.3
CVE-2026-88774
CVSS:7
CVE-2026-88775
CVSS:8.8
CVE-2026-88776
CVSS:8.8
CVE-2026-88777
CVSS:8.8

Full Report

Executive Summary

On September 27, 2026, Citrix released emergency security updates for its NetScaler Application Delivery Controller (ADC) and NetScaler Gateway products, addressing eight vulnerabilities. Two of these, CVE-2026-88771 and CVE-2026-88772, are rated critical (CVSS 9.5) and are being actively exploited in the wild as zero-days. These vulnerabilities allow unauthenticated attackers to achieve remote code execution (RCE) on affected appliances, providing a gateway into corporate networks. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added both to its Known Exploited Vulnerabilities (KEV) catalog, underscoring the urgency for immediate action. Due to the widespread deployment of NetScaler appliances as network edge devices for VPN and load balancing, the impact is global and affects all industries. Organizations must not only patch but also actively hunt for signs of compromise, as attackers have been observed deploying webshells for persistent access.


Vulnerability Details

The two zero-day vulnerabilities pose a severe threat to organizations relying on NetScaler appliances.

  • CVE-2026-88771 (CVSSv4 9.5 - Critical): An improper input validation vulnerability that enables an unauthenticated attacker to achieve remote code execution. This is the most severe flaw as it affects default configurations and requires no user interaction. A successful exploit grants the attacker full control over the appliance.
  • CVE-2026-88772 (CVSSv4 9.5 - Critical): A memory overflow vulnerability that also leads to unauthenticated remote code execution or a denial-of-service condition. This flaw is exploitable when the Datagram Transport Layer Security (DTLS) feature is enabled, which is the default setting for VPN virtual servers, making a large number of deployments vulnerable.

These vulnerabilities are particularly dangerous because they reside in appliances that sit at the perimeter of a network, often serving as the primary gateway for remote access. A compromise of a NetScaler device can provide an attacker with a direct foothold into the internal network.

Affected Systems

The vulnerabilities affect multiple versions of customer-managed NetScaler ADC and Gateway appliances. Citrix has released patches for the following product versions:

  • NetScaler ADC and Gateway 14.1 before version 14.1-73.37
  • NetScaler ADC and Gateway 13.1 before version 13.1-64.23
  • NetScaler ADC FIPS before version 14.1-73.37 FIPS
  • NetScaler ADC FIPS and NDcPP before version 13.1-37.279

Cloud-hosted Citrix services are not affected.

Exploitation Status

Both CVE-2026-88771 and CVE-2026-88772 are under active and widespread exploitation. CISA confirmed on September 27, 2026, that it has evidence of threat actors exploiting these flaws globally. Reports from security firms and national CERTs, including the Dutch NCSC, indicate that exploitation may have begun weeks before the patches were released. Attackers have been observed using these vulnerabilities to install webshells on compromised appliances, establishing persistent access and a platform for lateral movement within the victim's network. The ease of exploitation (unauthenticated, remote) combined with the critical function of NetScaler devices makes this a high-priority threat.

Impact Assessment

The business impact of exploiting these vulnerabilities is severe. As edge devices, NetScaler appliances control access to critical internal applications, services, and data. A successful RCE attack can lead to:

  • Complete Network Compromise: Attackers can use the compromised appliance as a beachhead to pivot into the internal corporate network, access sensitive data, and deploy further malware, such as ransomware.
  • Data Exfiltration: Sensitive corporate and customer data transiting through or accessible from the compromised network can be stolen.
  • Operational Disruption: Attackers can cause a denial-of-service, disrupting VPN access for remote employees and access to critical applications for customers, leading to significant business interruption and financial loss.
  • Reputational Damage: A public breach originating from a compromised security appliance can severely damage an organization's reputation and erode customer trust.

Given the KEV status and active exploitation, the risk is not theoretical. Any organization with a vulnerable, internet-facing NetScaler appliance should assume it is a target.

IOCs — Directly from Articles

No specific file hashes, IP addresses, or domains were listed as Indicators of Compromise in the source articles.

Cyber Observables — Hunting Hints

The following patterns may help identify vulnerable systems or active exploitation attempts. Security teams should hunt for these indicators in their logs and on their NetScaler appliances:

Type
url_pattern
Value
/..%2f/ or similar path traversal sequences
Description
Look for unusual URL patterns in web server logs targeting the NetScaler management interface or other exposed services.
Type
file_name
Value
*.php, *.jsp, *.aspx
Description
Search for newly created files with web-executable extensions in unexpected directories on the appliance, particularly in web-accessible paths. This could indicate a webshell.
Type
process_name
Value
sh, bash, powershell.exe, cmd.exe
Description
Monitor for suspicious child processes spawned by the main NetScaler processes (nsppe). These could indicate command execution.
Type
network_traffic_pattern
Value
Outbound connections from NetScaler to unknown IPs
Description
Analyze firewall and NetFlow logs for anomalous outbound connections originating from the NetScaler appliance's management or network interface IPs.
Type
log_source
Value
/var/log/httpaccess.log, /var/log/ns.log
Description
These are key log files on the NetScaler appliance to review for anomalous entries, errors, or signs of exploit attempts.

Detection & Response

Defenders should prioritize immediate investigation and response activities.

  1. Log Analysis: Scrutinize web server access logs, shell logs (/var/log/sh.log), and NetScaler system logs (/var/log/ns.log) for any signs of exploitation. Look for unusual requests, path traversal attempts, and unexpected command execution. D3FEND Network Traffic Analysis (D3-NTA) is critical here.
  2. File System Integrity: Check for the presence of unauthorized files, especially webshells in directories like /netscaler/portal/ or /var/vpn/. Use file integrity monitoring or manual checks against a known-good baseline. D3FEND File Analysis (D3-FA) should be employed.
  3. Process Monitoring: Look for unexpected processes or child processes spawned by the NetScaler nsppe process. Attackers may use these to run commands or establish reverse shells.
  4. Network Traffic Monitoring: Monitor all traffic originating from the NetScaler appliance. Any outbound connections to non-standard ports or unknown IP addresses should be considered highly suspicious and investigated immediately.
  5. Forensic Image: Before patching, CISA recommends preserving a forensic image of the appliance if compromise is suspected. This is crucial for incident response and investigation.
title: Citrix NetScaler RCE Exploitation Attempt
status: experimental
description: Detects potential exploitation attempts against Citrix NetScaler CVE-2026-88771/CVE-2026-88772.
logsource:
  product: webserver
  service: citrix
detection:
  selection:
    cs-method: 'POST'
    c-uri|contains|all:
      - '/..%2f'
      - '/vpns/'
  condition: selection
fields:
  - c-ip
  - c-uri
  - cs-user-agent
falsepositives:
  - Vulnerability scanners
level: critical

Remediation Steps

Immediate action is required to mitigate this threat.

  1. Patch Immediately: Apply the security updates provided by Citrix to all affected NetScaler appliances. This is the primary and most critical step. This aligns with D3FEND Software Update (D3-SU).
  2. Hunt for Compromise: Before and after patching, follow the detection steps above to search for indicators of compromise. Patching a compromised system does not remove the attacker.
  3. Isolate and Rebuild: If any evidence of compromise is found, the affected appliance should be isolated from the network and rebuilt from a trusted source. Restore configuration from a clean backup.
  4. Rotate Credentials: If compromise is confirmed, rotate all credentials, keys, and certificates stored on or accessible from the NetScaler appliance.
  5. Harden Configuration: As a general best practice, restrict access to the NetScaler management interface to a trusted internal network segment. This is a form of D3FEND Network Isolation (D3-NI).

Timeline of Events

1
September 27, 2026
Citrix discloses eight vulnerabilities and releases patches. CISA adds CVE-2026-88771 and CVE-2026-88772 to its KEV catalog.
2
September 28, 2026
This article was published
3
September 30, 2026
CISA deadline for U.S. federal civilian executive branch agencies to secure their systems against the vulnerabilities.

MITRE ATT&CK Mitigations

Applying the patches provided by Citrix is the most critical and direct mitigation for these vulnerabilities.

Mapped D3FEND Techniques:

Restrict access to the NetScaler management interface to a limited set of trusted administrative hosts to reduce the attack surface.

Mapped D3FEND Techniques:

Audit

M1047enterprise

Implement comprehensive logging and auditing of NetScaler appliances to detect anomalous activity, such as unexpected file creation or process execution.

Use network security monitoring and IPS/IDS to detect and potentially block exploit attempts and anomalous outbound connections from the appliance.

Mapped D3FEND Techniques:

D3FEND Defensive Countermeasures

Immediately apply the patches released by Citrix for CVE-2026-88771 and CVE-2026-88772. This is the primary and most effective countermeasure. Prioritize patching for all internet-facing NetScaler ADC and Gateway appliances. Due to the active exploitation, this should be treated as an emergency change. Before applying the patch, organizations should, if possible, capture a forensic snapshot of the system for later analysis, as recommended by CISA. After patching, it is crucial to verify that the update was successful and the appliance is running the fixed version (e.g., 14.1-73.37 or 13.1-64.23). This action directly remediates the root cause of the vulnerability, preventing initial access via this vector. It is not sufficient to rely on other controls; patching is mandatory.

Implement robust network traffic analysis focused on traffic to and from NetScaler appliances. For detection, monitor inbound web requests for suspicious patterns like path traversal sequences (/..%2f/). For post-compromise activity, focus on outbound traffic originating from the NetScaler appliance's own IP addresses. Establish a baseline of normal outbound communication for the appliance; any deviation, such as connections to unknown IP addresses, connections on non-standard ports, or large data transfers, should trigger an immediate alert. This is critical for detecting webshell C2 communication or data exfiltration. Utilize NetFlow, firewall logs, and full packet capture if available. This technique is vital for identifying compromised systems where patching was applied too late.

Perform file system analysis on all potentially affected NetScaler appliances to hunt for webshells, the primary payload observed in these attacks. Security teams should establish a script to check for files created or modified around the time of suspected compromise. Focus on web-accessible directories such as /netscaler/portal/, /var/vpn/, and other custom portal theme directories. Look for files with common webshell extensions (.php, .aspx, .jsp) and inspect any suspicious or recently modified files for malicious code. A file integrity monitoring (FIM) solution can automate this process. If a webshell is found, the system must be considered fully compromised, isolated, and rebuilt from a known-good state. This is a crucial step in the remediation process, as patching does not remove previously planted backdoors.

Timeline of Events

1
September 27, 2026

Citrix discloses eight vulnerabilities and releases patches. CISA adds CVE-2026-88771 and CVE-2026-88772 to its KEV catalog.

2
September 30, 2026

CISA deadline for U.S. federal civilian executive branch agencies to secure their systems against the vulnerabilities.

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

zero-dayremote code executionRCEwebshellnetwork securityVPNload balancer

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

⚡ Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.