Citrix NetScaler Zero-Days CVE-2026-88771 & CVE-2026-88772 Exploited

Citrix NetScaler Zero-Days Actively Exploited in the Wild

CRITICAL
September 29, 2026
October 1, 2026
2m read
VulnerabilityThreat IntelligencePatch Management

Related Entities(initial)

Products & Tech

NetScalerCortex Xpanse

CVE Identifiers

CVE-2026-88771
CRITICAL
CVSS:9.5
CVE-2026-88772
CRITICAL
CVSS:9.5

Full Report(when first published)

Executive Summary

Unit 42 is reporting on the active exploitation of two critical zero-day vulnerabilities in Citrix NetScaler (formerly Citrix ADC) devices. The vulnerabilities are tracked as CVE-2026-88771 and CVE-2026-88772. Both have been assigned a critical CVSS v4.0 base score of 9.5, indicating a high potential for severe impact. Citrix has confirmed that these vulnerabilities have been exploited in the wild.

As of September 27, 2026, Palo Alto Networks Cortex Xpanse has identified over 50,000 internet-exposed NetScaler instances that are potentially vulnerable. Due to the active exploitation and the critical nature of these flaws, organizations are strongly urged to apply the patches provided by Citrix immediately. It is crucial to note that patching will not evict an attacker who has already established persistence; therefore, threat hunting for signs of compromise is a necessary follow-up action.


Vulnerability Details

This threat brief addresses two distinct vulnerabilities affecting Citrix NetScaler appliances:

  • CVE-2026-88771: CVSSv4.0 Score: 9.5 (Critical)
  • CVE-2026-88772: CVSSv4.0 Score: 9.5 (Critical)

The source article does not provide specific technical details about the vulnerability types (e.g., remote code execution, authentication bypass) or the attack vectors. However, a CVSS score of 9.5 on a network appliance typically suggests a flaw that is remotely exploitable with low complexity and high impact on confidentiality, integrity, and availability.

Affected Systems

The vulnerabilities affect Citrix NetScaler ADC and Gateway appliances. The specific vulnerable versions have not been detailed in the source article; customers must refer to the official security advisory from Citrix for a complete list of affected products and versions.

Based on telemetry from Cortex Xpanse, there are 50,277 exposed instances globally that could be vulnerable if not patched.

Exploitation Status

Citrix has confirmed that both CVE-2026-88771 and CVE-2026-88772 have been exploited as zero-days in the wild. This means that attackers were leveraging these flaws before patches were available. The identities of the threat actors and the scale of the attacks are not yet known.

Impact Assessment

The exploitation of critical vulnerabilities on an internet-facing device like Citrix NetScaler can have severe consequences. A successful attack could allow a threat actor to:

  • Gain initial access to the corporate network.
  • Execute arbitrary code on the appliance, effectively taking control of it.
  • Intercept, view, and modify sensitive traffic passing through the appliance.
  • Use the compromised device as a pivot point for lateral movement within the network.
  • Deploy malware, including ransomware, on downstream systems.

Given the widespread use of NetScaler for load balancing, VPN access, and application delivery, a compromise could lead to significant business disruption, data breaches, and financial loss.

Important: The Unit 42 report stresses that applying patches is not sufficient for systems that may have already been compromised. Updating the software will not remove any backdoors, webshells, or other persistence mechanisms an attacker may have already established.

IOCs — Directly from Articles

No specific Indicators of Compromise (IOCs) or Tactics, Techniques, and Procedures (TTPs) related to these CVEs have been released in the source article.

Cyber Observables — Hunting Hints

Security teams may want to hunt for the following general patterns which could indicate NetScaler compromise:

Type
Log Source
Value
/var/log/ns.log
Description
Default NetScaler log file. Look for unusual error messages or system events.
Type
Log Source
Value
/var/log/httpaccess.log & /var/log/httperror.log
Description
Web server logs. Hunt for anomalous URI patterns or requests from unusual user agents.
Type
File Path
Value
/var/tmp/, /tmp/, /netscaler/, /var/vpn/
Description
Check for recently created or modified files, especially scripts (e.g., .sh, .py) and binaries.
Type
Process Name
Value
nsppe
Description
The NetScaler Packet Processing Engine. Look for unexpected child processes spawning from it, such as sh, bash, or curl.
Type
Command Line Pattern
Value
shell
Description
Any commands indicating a shell was invoked on the appliance should be investigated immediately.

Detection Methods

Until specific IOCs are available, detection should focus on anomaly detection and hunting for post-exploitation behavior.

  1. Log Analysis: Ingest NetScaler logs (syslog, auditlog, web logs) into a SIEM. Look for spikes in errors, unusual authentication patterns, or connections from unexpected IP addresses. This aligns with D3FEND's Network Traffic Analysis.
  2. File Integrity Monitoring: Scan critical system directories on the NetScaler appliance for new or modified files, particularly webshells (e.g., .php, .aspx files in web-accessible directories). This uses D3FEND's File Analysis.
  3. Network Traffic Monitoring: Analyze network flows to and from the NetScaler appliance. Look for connections to known malicious IPs/domains or data exfiltration patterns (e.g., large outbound transfers to unusual destinations).
  4. Vulnerability Scanning: Use vulnerability management tools to scan your environment and identify all unpatched NetScaler instances.

Remediation Steps

Immediate action is required to mitigate the risk from these vulnerabilities.

  1. Patch Immediately: The highest priority is to apply the security updates provided by Citrix to all affected NetScaler appliances. This is a direct application of D3FEND's Software Update.
  2. Hunt for Compromise: After patching, assume compromise and initiate a threat hunt. Use the observables listed above to search for signs of post-exploitation activity. Review logs from the period before patching for any suspicious entries.
  3. Engage Incident Response: If a compromise is suspected or confirmed, engage an incident response team to determine the scope of the breach, eradicate the threat actor, and recover the environment.
  4. Review Access Controls: Restrict access to the NetScaler management interface to a limited set of trusted administrative hosts.

Timeline of Events

1
September 27, 2026
Palo Alto Networks Cortex Xpanse identifies over 50,277 exposed NetScaler instances potentially vulnerable to the zero-days.
2
September 28, 2026
Unit 42 publishes a threat brief confirming active exploitation of CVE-2026-88771 and CVE-2026-88772.
3
September 29, 2026
This article was published

Article Updates

October 1, 2026

New details on NetScaler zero-days reveal specific attack patterns, web shell capabilities, and IOCs, with exploitation dating back to August 21.

MITRE ATT&CK Mitigations

The primary mitigation is to apply the security patches provided by Citrix as soon as possible.

Mapped D3FEND Techniques:

Use an IPS/IDS to monitor for and potentially block traffic patterns associated with exploitation attempts against NetScaler devices.

Mapped D3FEND Techniques:

Restrict access to the NetScaler management interface to a minimal set of trusted IP addresses to reduce the attack surface.

Mapped D3FEND Techniques:

Audit

M1047enterprise

Regularly collect and review NetScaler logs for signs of anomalous activity or compromise.

Mapped D3FEND Techniques:

D3FEND Defensive Countermeasures

The most critical and immediate action is to apply the security patches released by Citrix for CVE-2026-88771 and CVE-2026-88772. Given that these are actively exploited zero-days on a perimeter device, patching should be treated as an emergency change. Prioritize all internet-facing NetScaler ADC and Gateway appliances. Before deployment, ensure a valid backup of the appliance configuration is available. After applying the update, verify the new version is correctly reported in the system dashboard and that services have returned to a normal operational state. Because patching does not remove an existing compromise, this action must be paired with a comprehensive threat hunt. Document the patching process and timeline for compliance and incident response purposes. This countermeasure directly removes the vulnerability, preventing future exploitation by threat actors.

To detect potential compromise from the NetScaler zero-days, security teams must implement rigorous Network Traffic Analysis focused on the appliances. Ingest NetFlow, firewall, and proxy logs into a SIEM or network detection and response (NDR) platform. Establish a baseline of normal traffic patterns for each NetScaler appliance. Create alerts for anomalies, such as: connections from the NetScaler management IP to internal servers it does not normally communicate with (potential lateral movement); large or unusual data transfers from the NetScaler to external IP addresses (potential data exfiltration); or connections to known malicious C2 infrastructure or unusual ports. This analysis is crucial for identifying post-exploitation activity, as a compromised appliance can serve as a powerful pivot point into the network. This technique helps detect a breach even after the initial exploit has occurred.

Following the patching of CVE-2026-88771 and CVE-2026-88772, a thorough File Analysis must be conducted on all affected NetScaler appliances to hunt for persistence mechanisms like webshells. Security teams should connect to the appliance's command line and search for suspicious files in web-accessible directories such as /netscaler/ns_gui/ and script directories like /var/python/. Look for files with recent modification times that do not correspond to the patch installation time. Pay close attention to files with common webshell extensions (.php, .jsp, .aspx) or suspicious script files (.sh, .py). Use strings or other binary analysis tools on any suspicious executables found in temporary directories like /tmp or /var/tmp. Hashing all suspicious files and comparing them against threat intelligence feeds like VirusTotal can help confirm if they are malicious. This is a critical step to ensure the attacker has been fully evicted from the device.

Timeline of Events

1
September 27, 2026

Palo Alto Networks Cortex Xpanse identifies over 50,277 exposed NetScaler instances potentially vulnerable to the zero-days.

2
September 28, 2026

Unit 42 publishes a threat brief confirming active exploitation of CVE-2026-88771 and CVE-2026-88772.

Sources & References(when first published)

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

CitrixNetScalerZero-DayCVERCEVulnerabilityPatchingThreat Intelligence

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

⚡ Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.