Citrix has confirmed that two critical zero-day vulnerabilities in its NetScaler ADC and NetScaler Gateway appliances were exploited in the wild before patches were available, prompting the U.S. Cybersecurity and Infrastructure Security Agency to add both flaws to its Known Exploited Vulnerabilities catalog with a federal remediation deadline of September 30, 2026. The vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, both carry a CVSS v4.0 base score of 9.5 and allow unauthenticated remote code execution, according to Citrix and multiple threat intelligence firms.
Security Affairs reported on September 27 that Citrix published fixes for the two exploited vulnerabilities along with patches for six other security issues, designated CVE-2026-88771 through CVE-2026-88778. The company confirmed that both CVE-2026-88771 and CVE-2026-88772 had been exploited on systems that had not been mitigated. The first warnings did not come from Citrix: on September 26, administrators said IT providers and security teams were privately advising them to take NetScaler systems offline, sometimes without explaining why.
The scale of exposure is significant. As of September 27, Palo Alto Networks Cortex Xpanse identified 50,277 exposed NetScaler instances that could potentially be vulnerable based on telemetry, according to Unit 42. Unit 42 reported on September 30 that threat actors have been using the flaws to deliver web shells and establish initial access and persistence. The earliest activity identified occurred on August 21, 2026, when hosts fingerprinted NetScaler Gateways by requesting specific files such as /admin_ui/common/css/ns/ui.css and /vpn/js/rdx/core/lang/rdx_en.json.gz.
Victims span multiple sectors and geographies. Echo Inside reported on September 30 that government agencies, financial services firms, education organizations and legal and professional services sectors across North America and Europe have been breached through CVE-2026-88772, according to Google Threat Intelligence Group and Mandiant. The campaign has been running since at least early September, weeks before Citrix publicly disclosed the flaw. No group has been attributed.
Key Facts
CVE-2026-88771 involves improper input validation and allows an unauthenticated attacker to execute arbitrary commands. It affects all NetScaler ADC and NetScaler Gateway deployments in the affected versions without requiring an additional feature to be enabled. CVE-2026-88772 is a memory overflow that can lead to remote code execution or denial of service and affects appliances with DTLS enabled, which is on by default for NetScaler Gateway VPN virtual servers unless an administrator explicitly disabled it.
Fixes are available in NetScaler ADC and Gateway 14.1-73.37 and later, and in 13.1-64.23 and later, plus the 14.1-FIPS, 13.1-FIPS and 13.1-NDcPP branches. Builds 14.1-73.32 and 13.1-63.21, which fixed the earlier CVE-2026-19490, are still within the affected range. The 13.1 branch reached End of Maintenance on September 15.
Exploitation details reveal a sophisticated toolkit. Unit 42 reported on September 30 that CVE-2026-88772 exploitation ran between September 4 and 24, dropping a PHP web shell disguised as .deb files in the /vpn/scripts/linux/ folder (nsgclient18.deb, nsg64.deb), with all command-and-control communication RC4-encrypted using a hard-coded passphrase and privilege escalation via the NetScaler SUID binary. CVE-2026-88771 was exploited as a three-stage command-injection chain: a Base64 dropper in the User-Agent string was logged to /var/log/httpaccess-vpn.log, log poisoning wrote text into ns.log, and the vulnerable Perl script /netscaler/ns_monuploadd_err.pl then ran the injected text as shell commands.
GreyNoise reported a shift from reconnaissance to mass exploitation beginning September 28, according to Security News Headlines on September 30. The roundup also confirmed that CISA set a Wednesday, September 30 federal remediation deadline, requiring forensic triage on affected appliances. The same source noted that attackers used CVE-2026-88772 to deploy custom web shells and tunneling malware, gain root, steal credentials and move into internal networks.
F5 Labs reported on September 30 that the eight vulnerabilities affect Citrix NetScaler ADC and Citrix NetScaler Gateway, with active global exploitation confirmed by threat intelligence partners. Victim industries listed include automotive, cloud infrastructure, education, energy, financial services, government, healthcare, higher education and research, information technology, insurance, legal services, life sciences, manufacturing, pharmaceuticals, professional services, retail, technology hardware, telecommunications and transportation, with victim countries the Netherlands and the United States.
Analysis
The timeline of this campaign raises serious questions about disclosure and response. GreyNoise observed a Citrix NetScaler Gateway targeted in an exploitation attempt involving CVE-2026-88771 on September 24, yet Citrix waited until Sunday, September 27, to publish its advisories. watchTowr founder and CEO Benjamin Harris said the flaws were discovered during incident response and forensic investigations at organizations already compromised, meaning both the exploitation and Citrix's awareness predated public disclosure. This gap gave attackers a head start, and mass exploitation ramped up almost immediately after the patches were released.
What this really means is that edge appliances remain the softest target for sophisticated intrusion sets. NetScaler ADC and Gateway devices sit at the perimeter, often exposed directly to the internet, and they handle authentication and VPN traffic. A single unauthenticated RCE on such a device can yield root access, persistence, and a pivot point into internal networks. The fact that CVE-2026-88772 bypasses authentication and crashes the NetScaler Packet Processing Engine to gain root on the FreeBSD appliance makes it a particularly dangerous weapon. Attackers then deploy tools like WHIPSHOT, a PHP web shell that hides Base64-encoded command-and-control payloads within native HTTP headers, and SLAPSHOT, a Python TCP tunneling tool that supports open, push, pull, exch, close and ping commands and relays arbitrary TCP streams to internal hosts.
The victim profile is telling. Government, financial services, legal and professional services, education and technology organizations across North America and Europe were hit. Mandiant Consulting CTO Charles Carmakal warned that patching alone may not eradicate the threat actor and urged customers to examine systems for compromise and preserve evidence first. F5 Labs echoed this, advising that if an appliance is suspected compromised, it should be isolated and a forensic image created before applying patches or configuration changes, because the update process can permanently erase critical forensic data.
The bigger picture here is that the security industry's reliance on rapid patching as a sole remediation strategy is insufficient against determined adversaries who establish deep persistence. The custom toolkit, the use of RC4-encrypted command-and-control with a hard-coded passphrase, and the abuse of legitimate system binaries like the NetScaler SUID binary show a high level of operational maturity. No attribution has been made public, and watchTowr's Harris noted that historically NetScaler vulnerabilities have been exploited by both state-sponsored groups and ransomware operators. Google noted that edge devices account for roughly half of enterprise-related zero-days recorded in 2025, a trend that continues into 2026.
Why It Matters
The CISA Known Exploited Vulnerabilities catalog addition with a September 30, 2026 federal remediation deadline means that U.S. federal agencies must patch or mitigate these flaws by that date. But the impact extends far beyond government networks. NetScaler appliances are used by banks, law firms, healthcare providers, manufacturers, retailers and telecommunications companies. The wide victim industry set listed by F5 Labs demonstrates that any organization using NetScaler ADC or Gateway for remote access, load balancing or application delivery is at risk. The vulnerabilities are unauthenticated and remotely exploitable, so no user interaction is required.
Forensic preservation is a critical but often overlooked step. Because the update process can erase evidence, organizations that patch without first imaging a compromised appliance may lose the ability to determine what data was accessed, what credentials were stolen, and whether additional backdoors remain. Mandiant's warning that patching alone may not eradicate the threat actor underscores the need for thorough hunting. Security News Headlines advised operators to hunt WHIPSHOT and SLAPSHOT persistence on both high-availability nodes before assuming an upgrade cleaned the appliance.
The Dutch National Cyber Security Centre sent a pre-notification to organizations in the Netherlands, and the victim countries listed include the Netherlands and the United States. This indicates a transatlantic impact. For European organizations, the Dutch NCSC's early warning may have helped some, but the mass exploitation that began on September 28 likely caught many off guard. The 13.1 branch reached End of Maintenance on September 15, meaning organizations still running that branch may face additional challenges in obtaining patches or may need to upgrade to supported versions.
Next Up
Organizations should immediately identify all NetScaler ADC and Gateway appliances, scan them for indicators of compromise, and apply Citrix updates prioritizing the KEV entries. If CVE-2026-88772 cannot be patched immediately, disable the DTLS protocol on affected Gateway VPN virtual servers as a temporary mitigation. For CVE-2026-88778, enable Enhanced ISN Generation on TCP-based virtual servers as a temporary mitigation. F5 Labs also noted that the same bulletin covers the September 30 Cisco Catalyst SD-WAN Manager authentication bypass CVE-2026-76504 (CVSS 9.8), SharePoint CVE-2026-65660, and WSO2/Adobe Commerce flaws added to CISA's KEV catalog, indicating a broader wave of edge and enterprise vulnerabilities.
Expect continued exploitation and further victim disclosures in the coming weeks. The attackers behind this campaign have demonstrated the ability to adapt, using custom malware and tunneling tools to maintain access. CISA's September 30 deadline is a hard stop for federal agencies, but private sector organizations should treat it as an urgent call to action. With no attribution yet, the threat remains active and the full scope of the breach may not be known for some time. Patching is necessary but not sufficient; hunting for persistence and preserving forensic evidence are equally important.
Comments (0)
Log in or sign up to leave a comment.
No comments yet. Be the first to share your thoughts.