Unit 42 is reporting on the active exploitation of two critical zero-day vulnerabilities in Citrix NetScaler (formerly Citrix ADC) devices. The vulnerabilities are tracked as CVE-2026-88771 and CVE-2026-88772. Both have been assigned a critical CVSS v4.0 base score of 9.5, indicating a high potential for severe impact. Citrix has confirmed that these vulnerabilities have been exploited in the wild.
As of September 27, 2026, Palo Alto Networks Cortex Xpanse has identified over 50,000 internet-exposed NetScaler instances that are potentially vulnerable. Due to the active exploitation and the critical nature of these flaws, organizations are strongly urged to apply the patches provided by Citrix immediately. It is crucial to note that patching will not evict an attacker who has already established persistence; therefore, threat hunting for signs of compromise is a necessary follow-up action.
This threat brief addresses two distinct vulnerabilities affecting Citrix NetScaler appliances:
The source article does not provide specific technical details about the vulnerability types (e.g., remote code execution, authentication bypass) or the attack vectors. However, a CVSS score of 9.5 on a network appliance typically suggests a flaw that is remotely exploitable with low complexity and high impact on confidentiality, integrity, and availability.
The vulnerabilities affect Citrix NetScaler ADC and Gateway appliances. The specific vulnerable versions have not been detailed in the source article; customers must refer to the official security advisory from Citrix for a complete list of affected products and versions.
Based on telemetry from Cortex Xpanse, there are 50,277 exposed instances globally that could be vulnerable if not patched.
Citrix has confirmed that both CVE-2026-88771 and CVE-2026-88772 have been exploited as zero-days in the wild. This means that attackers were leveraging these flaws before patches were available. The identities of the threat actors and the scale of the attacks are not yet known.
The exploitation of critical vulnerabilities on an internet-facing device like Citrix NetScaler can have severe consequences. A successful attack could allow a threat actor to:
Given the widespread use of NetScaler for load balancing, VPN access, and application delivery, a compromise could lead to significant business disruption, data breaches, and financial loss.
Important: The Unit 42 report stresses that applying patches is not sufficient for systems that may have already been compromised. Updating the software will not remove any backdoors, webshells, or other persistence mechanisms an attacker may have already established.
No specific Indicators of Compromise (IOCs) or Tactics, Techniques, and Procedures (TTPs) related to these CVEs have been released in the source article.
Security teams may want to hunt for the following general patterns which could indicate NetScaler compromise:
/var/log/ns.log/var/log/httpaccess.log & /var/log/httperror.log/var/tmp/, /tmp/, /netscaler/, /var/vpn/.sh, .py) and binaries.nsppesh, bash, or curl.shellUntil specific IOCs are available, detection should focus on anomaly detection and hunting for post-exploitation behavior.
syslog, auditlog, web logs) into a SIEM. Look for spikes in errors, unusual authentication patterns, or connections from unexpected IP addresses. This aligns with D3FEND's Network Traffic Analysis..php, .aspx files in web-accessible directories). This uses D3FEND's File Analysis.Immediate action is required to mitigate the risk from these vulnerabilities.
Software Update.New details on NetScaler zero-days reveal specific attack patterns, web shell capabilities, and IOCs, with exploitation dating back to August 21.
The primary mitigation is to apply the security patches provided by Citrix as soon as possible.
Mapped D3FEND Techniques:
Use an IPS/IDS to monitor for and potentially block traffic patterns associated with exploitation attempts against NetScaler devices.
Restrict access to the NetScaler management interface to a minimal set of trusted IP addresses to reduce the attack surface.
Mapped D3FEND Techniques:
The most critical and immediate action is to apply the security patches released by Citrix for CVE-2026-88771 and CVE-2026-88772. Given that these are actively exploited zero-days on a perimeter device, patching should be treated as an emergency change. Prioritize all internet-facing NetScaler ADC and Gateway appliances. Before deployment, ensure a valid backup of the appliance configuration is available. After applying the update, verify the new version is correctly reported in the system dashboard and that services have returned to a normal operational state. Because patching does not remove an existing compromise, this action must be paired with a comprehensive threat hunt. Document the patching process and timeline for compliance and incident response purposes. This countermeasure directly removes the vulnerability, preventing future exploitation by threat actors.
To detect potential compromise from the NetScaler zero-days, security teams must implement rigorous Network Traffic Analysis focused on the appliances. Ingest NetFlow, firewall, and proxy logs into a SIEM or network detection and response (NDR) platform. Establish a baseline of normal traffic patterns for each NetScaler appliance. Create alerts for anomalies, such as: connections from the NetScaler management IP to internal servers it does not normally communicate with (potential lateral movement); large or unusual data transfers from the NetScaler to external IP addresses (potential data exfiltration); or connections to known malicious C2 infrastructure or unusual ports. This analysis is crucial for identifying post-exploitation activity, as a compromised appliance can serve as a powerful pivot point into the network. This technique helps detect a breach even after the initial exploit has occurred.
Following the patching of CVE-2026-88771 and CVE-2026-88772, a thorough File Analysis must be conducted on all affected NetScaler appliances to hunt for persistence mechanisms like webshells. Security teams should connect to the appliance's command line and search for suspicious files in web-accessible directories such as /netscaler/ns_gui/ and script directories like /var/python/. Look for files with recent modification times that do not correspond to the patch installation time. Pay close attention to files with common webshell extensions (.php, .jsp, .aspx) or suspicious script files (.sh, .py). Use strings or other binary analysis tools on any suspicious executables found in temporary directories like /tmp or /var/tmp. Hashing all suspicious files and comparing them against threat intelligence feeds like VirusTotal can help confirm if they are malicious. This is a critical step to ensure the attacker has been fully evicted from the device.
Palo Alto Networks Cortex Xpanse identifies over 50,277 exposed NetScaler instances potentially vulnerable to the zero-days.
Unit 42 publishes a threat brief confirming active exploitation of CVE-2026-88771 and CVE-2026-88772.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.