Zero Day Room
Live
Vulnerabilities

NetScaler CVE-2026-88771 and CVE-2026-88772 Exploited

Two critical Citrix NetScaler vulnerabilities, CVE-2026-88771 and CVE-2026-88772, are being actively exploited in zero-day attacks to deploy webshells

Two critical Citrix NetScaler vulnerabilities, CVE-2026-88771 and CVE-2026-88772, are being actively exploited in...

Two critical NetScaler vulnerabilities are being exploited in zero-day attacks to deploy webshells. The US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities catalog and ordered US federal civilian agencies to patch by September 30, 2026.

Citrix confirmed exploitation of both flaws, which affect customer-managed deployments of NetScaler ADC and NetScaler Gateway. CVE-2026-88771 stems from improper input validation and allows remote, unauthenticated attackers to execute arbitrary commands on vulnerable devices running a default configuration. It requires no user interaction. CVE-2026-88772 is a memory overflow vulnerability that can lead to remote code execution or denial of service. Both were exploited as zero-days before a fix existed and can be exploited independently.

Exploitation mechanics and prerequisites

Exploitation requires specific conditions and enables full network access. CVE-2026-88772 requires DTLS to be enabled, which is default on VPN virtual servers, to exploit. It is remotely exploitable without user interaction under that configuration. The Netherlands' National Cyber Security Centre (NCSC-NL) stated that this vulnerability gives attackers full control of the gateway, providing direct access to the internal corporate network behind it.

The vulnerabilities affect the following versions:

ProductAffected VersionsFixed Version
NetScaler ADC & Gateway v14.1Before v14.1-73.37v14.1-73.37
NetScaler ADC & Gateway v13.1Before v13.1-64.23v13.1-64.23
NetScaler ADC FIPSBefore v14.1-73.37 FIPSv14.1-73.37 FIPS
NetScaler ADC FIPS and NDcPPBefore v13.1-37.279v13.1-37.279

Secure Private Access Hybrid deployments using NetScaler instances are also affected. Researcher Kevin Beaumont noted that given the activity started weeks ago, logs have probably been rotated. He advised checking SIEM logs for base64 strings after the User-Agent field and loglines for 'pitboss' followed by the string IFS.

Threat actor involvement and attribution

Evidence points to sophisticated nation-state actors conducting espionage operations. Kevin Beaumont commented, "Probably nation state aligned as well resourced, espionage rather than teens." The webshells are unique for each compromised device, and the attackers ran anti-forensics commands to delete artefacts.

Satnam Narang, a senior staff research engineer at Tenable, stated, "Based on public reporting, it has not been determined whether exploitation has reached widespread scale." He added that roughly two-thirds of threat actor activity targeting Citrix NetScaler over the last seven years involved advanced persistent threat groups, while one-third involved ransomware groups. Citrix acknowledged that threat actors change techniques frequently, so published indicators of compromise might fail to identify all compromises.

Vendor response and mitigation

Citrix has released patches and CISA mandates federal agency remediation by September 30. Citrix patched eight critical and high-severity vulnerabilities, CVE-2026-88771 through CVE-2026-88778, and published its security bulletin CTX697096 on September 27, 2026. The company confirmed both vulnerabilities and released fixed builds on that date. The bulletin applies to customer-managed appliances; Citrix updates its own managed cloud services.

Citrix has not published a workaround for CVE-2026-88771 or CVE-2026-88772. Upgrading is the only fix. The company advises customers to upgrade to a version containing the fixes, then check for evidence of compromise and follow incident response processes if signs are identified. CISA advises checking for compromise and preserving forensic evidence before updating, as updates can remove evidence. Recommended preservation steps include capturing logs, snapshots, support bundles, and core dumps from each exposed appliance.

Compromise can be checked using the IOC scan on the NetScaler Console Security Advisory page for version 14.1-73.36 or later with telemetry enabled. Alternatively, IOCs can be requested from Citrix Support. Citrix warns that IOCs do not cover every technique, so a clean result is not proof of no compromise. On NetScaler 13.1, administrators should run show ns variable first; if variables are returned, use build 13.1-64.24 to avoid a known reboot loop during upgrade.

Enhanced ISN Generation should be enabled to close CVE-2026-88778, which requires a configuration change beyond the upgrade. Passwords, secrets, and certificates stored on or used through the appliance should be rotated. NetScaler logs should be forwarded to a SIEM. Organizations must upgrade to patched versions and conduct forensic triage to detect webshells.

Related coverage

More from Vulnerabilities