Cybersecurity

Citrix NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772): Exploited for Weeks — Patch and Hunt Now

Two critical Citrix NetScaler zero-days, CVE-2026-88771 and CVE-2026-88772, were exploited for weeks before the September 2026 patch. Here is what they do, who is behind them, and why patching alone is not enough.

Waqas Ahmed Waseer
Waqas Ahmed Waseer Oct 1, 2026 6 min read
Citrix NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772): Exploited for Weeks — Patch and Hunt Now

Two Citrix NetScaler zero-days, CVE-2026-88771 and CVE-2026-88772, were exploited in the wild for weeks before Citrix shipped a fix the weekend of September 27–28, 2026. Both carry a CVSS score of 9.5, both allow remote code execution on internet-facing appliances, and CISA gave U.S. federal agencies until September 30 to patch. If you run NetScaler ADC or Gateway, the urgent part is this: upgrading closes the door, but it does not tell you whether someone already walked through it. You need to patch and hunt for compromise, in that order of urgency but not that order of completeness.

This is a news breakdown of what the two flaws are, the exploitation timeline, who researchers think is behind it, and the remediation steps that actually matter.

What CVE-2026-88771 and CVE-2026-88772 actually are

The two bugs are different classes of flaw in the same appliance, and an attacker can reach them without authenticating. CVE-2026-88771 is an improper input validation issue that lets a remote, unauthenticated attacker execute arbitrary commands. CVE-2026-88772 is a memory overflow that can be driven to remote code execution or a denial-of-service condition. Because NetScaler Gateway sits at the network edge as a remote-access and load-balancing device, a working exploit lands straight on a box that already has lines into the internal network.

CVETypeCVSSWhat it gives an attacker
CVE-2026-88771Improper input validation9.5 (critical)Unauthenticated remote command execution
CVE-2026-88772Memory overflow9.5 (critical)Remote code execution or denial of service

Neither flaw requires a valid session, a stolen credential, or user interaction. That combination — pre-auth, network-edge, code execution — is why both bugs sit at the top of the severity scale and why they were weaponized before most defenders knew they existed.

Which NetScaler versions are affected

Citrix published the fixes in bulletin CTX697096. The affected and fixed builds are:

BranchFixed in
NetScaler ADC & Gateway 14.114.1-73.37 and later
NetScaler ADC & Gateway 13.113.1-64.23 and later
NetScaler ADC FIPS 14.114.1-73.37 FIPS and later
NetScaler ADC FIPS / NDcPP 13.113.1-37.279 and later

Only customer-managed NetScaler appliances need action; Citrix-managed cloud services are handled by Citrix. Older, end-of-life branches do not receive a patch, so anything running an unsupported build should be treated as exposed and upgraded onto a supported branch immediately. Citrix advised that organizations which cannot patch right away should reduce internet exposure of the appliances where operationally possible until they can.

The timeline: exploited before anyone was told

This was a zero-day in the strict sense — attacks came first, disclosure came later. Google Threat Intelligence Group and Mandiant traced exploitation of CVE-2026-88772 back to early September 2026, weeks before any public notice. GreyNoise observed exploitation activity climbing around September 26, Citrix began telling customers to disconnect affected servers on September 28, and the official bulletin followed that weekend. CISA added both CVEs to its Known Exploited Vulnerabilities catalog on September 27 with a federal remediation deadline of September 30.

The gap between first exploitation and public disclosure is the whole story. By the time admins had a patch in hand, well-resourced attackers had already had a multi-week head start on a device that brokers access to everything behind it.

Who is behind the attacks

The fingerprints point at espionage, not opportunists. Mandiant reported that the threat actor deployed web shells on compromised NetScaler systems and moved laterally into internal networks at some victims. Mandiant's Charles Carmakal said dozens of organizations across North America and Europe were hit, spanning government, financial services, education, telecommunications, legal, and professional services. Independent researcher Kevin Beaumont characterized the operators as "probably nation state aligned," well-resourced, and focused on espionage rather than smash-and-grab. The Shadowserver Foundation counted more than 20,000 potentially vulnerable NetScaler instances exposed online, which is the pool the attackers were picking from.

What to do now (patch is step one, not the finish line)

The most important operational point from this incident is one that most headlines bury: upgrading does not evict an attacker who is already inside. Carmakal explicitly warned that customers should check whether they have been compromised before upgrading, because a clean-looking patched appliance can still be hosting a web shell or have seeded persistence deeper in the network. A practical order of operations:

  • Patch to the fixed build for your branch (14.1-73.37, 13.1-64.23, or the matching FIPS/NDcPP build) — or pull the appliance offline if you cannot patch yet.
  • Hunt before you trust the box. Researchers recommend searching logs for anomalous base64 strings following the User-Agent field and for strings containing "pitboss" followed by "IFS"; the deployed web shells are unique per device, so signature-only checks are not enough.
  • Assume credential and session theft. Edge appliances like this have been abused before to lift session tokens, so rotate secrets and invalidate active sessions after you have confirmed the box is clean.
  • Look for lateral movement, not just the NetScaler itself. The reported attacker behavior was to pivot inward, so the real blast radius is the internal hosts the appliance could reach.

For the bigger picture on why putting a single VPN-style appliance at the edge concentrates this kind of risk, see our explainer on Zero Trust vs VPN in 2026. This is also part of a broader 2026 pattern of pre-auth RCEs in edge and collaboration software — the same playbook ran against SharePoint and against SimpleHelp remote-access software used by MSPs.

Why NetScaler keeps being a target

This is not NetScaler's first bad week, and that is the part worth sitting with. Internet-facing access gateways are high-value because one unauthenticated bug turns the device that is supposed to guard the perimeter into the beachhead inside it. The appliances are always on, always reachable, and trusted by the internal network by design, which is exactly what an espionage actor wants. Treat any edge appliance — Citrix, or a competing gateway — as a system that will eventually have a pre-auth RCE, and build your response plan (fast patching, exposure reduction, and routine compromise hunting) around that assumption rather than hoping the next zero-day skips you.

FAQ

Are CVE-2026-88771 and CVE-2026-88772 being actively exploited? Yes. Both were exploited in the wild before Citrix released patches, and CISA added both to its Known Exploited Vulnerabilities catalog on September 27, 2026. Google Threat Intelligence Group and Mandiant traced exploitation of CVE-2026-88772 back to early September 2026.

Which NetScaler versions are safe? Upgrade to NetScaler ADC and Gateway 14.1-73.37 or 13.1-64.23 (or the matching FIPS build 14.1-73.37 FIPS / NDcPP 13.1-37.279) and later, per Citrix bulletin CTX697096. End-of-life branches do not get a fix and should be migrated to a supported version.

Is patching enough to be safe? No. Mandiant advises checking whether an appliance was already compromised before upgrading, because attackers deployed web shells and moved laterally into internal networks. Patch, then hunt for signs of compromise and rotate credentials and sessions.

Who is exploiting these Citrix flaws? Researchers attribute the activity to suspected nation-state-aligned, well-resourced actors focused on espionage. Dozens of organizations across North America and Europe in government, finance, education, telecom, and professional services have been affected.

Sources

Some links may earn us a commission at no extra cost to you.

Waqas Ahmed Waseer

Waqas Ahmed Waseer

Waqas Ahmed Waseer is a developer and automation builder with 8+ years shipping production systems used by 100k+ people. He builds custom multi-tenant SaaS, AI automation (n8n, LLM workflows, WhatsApp bots) and hosting infrastructure (WHM/cPanel, CloudLinux) — and is the maker of WaSphere, FlowMaticX, and the WaseerHost hosting brand. 100+ projects delivered for SMBs, agencies and funded startups.

Related

More in Cybersecurity

View all →

Discussion · 0

Be kind. Comments are public.

    Newsletter · Monday edition

    The Monday brief.

    One email every Monday morning. The week ahead in AI, startups, hosting and dev tools — no fluff, no sponsored bait.

    Free. Unsubscribe in one click.