Citrix NetScaler Gets Two Exploited Flaws, Then a Third in a Week
Security / news
Citrix NetScaler Gets Two Exploited Flaws, Then a Third in a Week
CVE-2026-88771 and CVE-2026-88772 were under attack by Sept. 27, and Citrix disclosed another exploited NetScaler bug, CVE-2026-88779, on Oct. 4.

Attackers were exploiting two critical flaws in Citrix NetScaler ADC and Gateway before most administrators had read the bulletin, and a third exploited bug followed a week later. CISA added CVE-2026-88771 and CVE-2026-88772, both rated 9.5 on the CVSS 4.0 severity scale, to its Known Exploited Vulnerabilities catalog on Sept. 27, 2026, and gave federal civilian agencies until Sept. 30 to patch, according to The Hacker News.
On Oct. 4, Citrix disclosed CVE-2026-88779, a memory overflow rated 8.7, in bulletin CTX697174. Sophos says Citrix has seen targeted attacks against unpatched deployments.
The two critical bugs
CVE-2026-88771 is an input validation flaw that lets an unauthenticated attacker run arbitrary commands, and it affects all NetScaler ADC and Gateway deployments. According to watchTowr, as relayed by The Hacker News, it comes from a Perl script, ns_monuploadd_err.pl, that processes crash and error data: log content an attacker controls reaches a shell command, giving root code execution through the /nf/auth/doAuthentication.do endpoint before login.
CVE-2026-88772 is a memory bounds flaw that can give remote code execution or a crash. It applies only when DTLS, an encrypted datagram transport, is enabled, and that option is on by default for VPN virtual servers, per The Hacker News. That default is why the second bug matters more than its precondition suggests.
The UK's National Cyber Security Centre published an alert on Sept. 28 covering all eight vulnerabilities in Citrix bulletin CTX697096. It confirmed these two as actively exploited and said it was still assessing the impact on UK organisations.
| CVE | Flaw | Exploited |
|---|---|---|
| CVE-2026-88771 | Input validation, unauthenticated command execution | Yes |
| CVE-2026-88772 | Memory bounds, RCE or denial of service (DTLS) | Yes |
| CVE-2026-88773 | HTTP request smuggling | Not stated |
| CVE-2026-88774 | Feature policy bypass | Not stated |
| CVE-2026-88775 to 88777 | Memory overflows | Not stated |
| CVE-2026-88778 | Predictable value | Not stated |
Fixed builds
The NCSC lists on-premises, customer-managed builds before these as affected. Fixed builds are 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS and 13.1-37.279 for the FIPS and NDcPP variants.
Palo Alto Networks Unit 42 counted more than 50,277 publicly exposed NetScaler instances potentially vulnerable to both flaws as of Sept. 27, The Hacker News reported. That is a count of reachable hosts, not of compromised ones.
What the first attempt looked like
GreyNoise saw the earliest attempt on its sensors on Sept. 24, from 149.104.78[.]141, three days before CISA's listing. It failed. The attacker tried to set setuid and setgid bits on /bin/sh, install a password-protected webshell, route requests for a non-existent stylesheet to it, and restart the web server. A failed attempt shows what the attacker wanted on a successful one: a persistent shell that survives a restart.
Citrix's guidance for suspected compromise is to preserve evidence, isolate the device, revoke credentials, rebuild from the latest firmware and rotate local account passwords and key encryption keys. If you restored from a backup, replace the SSL certificates too. The NCSC adds file integrity monitoring through NetScaler Console.
The October bug is a different kind of problem
CVE-2026-88779 affects customer-managed NetScaler ADC and Gateway appliances set up as a SAML service provider or identity provider. The impact Sophos lists is denial of service that could disrupt authentication and remote access. Citrix-managed cloud services and Citrix-managed Adaptive Authentication are not affected, because Citrix applies updates there.
The Sophos page gives no CVSS vector and no fixed build numbers, so check CTX697174 for both. Sophos says it is monitoring for related activity and will add detections.
A denial of service on the SAML path is lower in severity than command execution, but on a gateway it can lock users out of remote access. Operators already patching for the September pair should confirm they are also covered for CTX697174. For other recent exploitation of edge and device flaws, see The Terminal's reports on the Cling botnet and the Apple CoreGraphics zero-day.
Sources
More in Security
- 01CISA Gave Agencies Three Days for Five 2015-2023 Bugs, and Four Come With a Forensic Triage OrderThe October 8 additions to the exploited-vulnerabilities catalogue show how BOD 26-04 has changed what a deadline means: the patch is the smaller job.
- 02Apple's CoreGraphics Zero-Day CVE-2026-86950 Has a CISA Deadline of October 13, Not the October 2 Being ReportedTrade coverage gives a three-day federal deadline. The catalogue entry itself carries 14 days and no forensic-triage flag.
- 03Rejetto HFS CVE-2026-61500, Found With Anthropic's Mythos, Was Probed One Day After DisclosureA predictable session-signing key lets an unauthenticated attacker forge an HFS admin cookie and run server-side JavaScript; HFS 3.2.1 has carried the fix since July.
- 04Exchange CVE-2026-96940 Lets Any Mailbox User Read Others' Mail, and Patched Servers Need V2Microsoft's out-of-band September V2 update closes an 8.8-rated authorization flaw in on-premises Exchange, with four KBs and a support cliff for 2016 and 2019.