NetScaler Exploitation Warnings Preceded Citrix's CVE-2026-88771 Disclosure by a Day
Security / news
NetScaler Exploitation Warnings Preceded Citrix's CVE-2026-88771 Disclosure by a Day
Citrix disclosed eight NetScaler flaws on Sept. 27, two of them rated 9.5 and already exploited, and a LevelBlue analysis shows what attackers leave behind.

Attackers were exploiting a pair of critical Citrix NetScaler flaws before the vendor's bulletin appeared, and neither needs a login. CVE-2026-88771 and CVE-2026-88772 are each rated 9.5, and the fix is to move to NetScaler 14.1-73.37 or 13.1-64.23, but the Cybersecurity and Infrastructure Security Agency (CISA) tells owners to look for compromise first.
Citrix disclosed eight vulnerabilities, CVE-2026-88771 through CVE-2026-88778, on Sept. 27, 2026 in bulletin CTX697096. Field Effect reports that exploitation warnings emerged on Sept. 26, a day before public disclosure.
The two flaws rated 9.5
CVE-2026-88771 is an improper-input-validation bug that lets a remote, unauthenticated attacker run arbitrary commands. Field Effect says it affects every NetScaler ADC and Gateway deployment, default configurations included.
CVE-2026-88772 is a memory overflow in DTLS processing that can give remote code execution or a denial of service. It needs DTLS enabled, which Field Effect says is the default on VPN virtual servers. The other six flaws are not the ones under attack.
Fixed builds
The Hacker News lists the fixed versions, and Citrix's bulletin names 14.1-73.37 and 13.1-64.23.
| Product line | Fixed at or after |
|---|---|
| NetScaler ADC and Gateway 14.1 | 14.1-73.37 |
| NetScaler ADC and Gateway 13.1 | 13.1-64.23 |
| NetScaler ADC 14.1-FIPS | 14.1-73.37 FIPS |
| NetScaler ADC 13.1-FIPS and 13.1-NDcPP | 13.1.37.279 |
For CVE-2026-88778, Citrix says to apply a TCP configuration change through the enhanced initial-sequence-number generation settings.
Check before you patch
CISA's alert of Sept. 27 says "threat actors are actively exploiting these vulnerabilities globally." It also warns that updating NetScaler "can be complex and may require downtime" and that patching may erase forensic evidence, so owners should check for indicators of compromise and preserve evidence first, using Citrix's compromise guidance document CTX694799.
The alert as published contains no remediation deadline. The Hacker News reports that federal agencies must patch by Sept. 30, a date the CISA text does not carry. The same outlet cites Palo Alto Networks Unit 42 as counting more than 50,277 internet-exposed NetScaler instances as potentially vulnerable on Sept. 27.

What LevelBlue found on compromised appliances
LevelBlue's Threat Hunt Operations and Research team, per The Hacker News, saw attacker-controlled authentication data containing variants of the strings "pitboss" and "NSPPE" in exploitation attempts. The same report says the Netherlands' National Cyber Security Centre sent a pre-notification urging organisations to shut down appliances.
A Perl script named update_c08937.pl then does the following:
- creates a local account named
sec_monitorwith superuser privileges; - archives
/flash/nsconfigand exfiltrates it; - writes a PHP web shell to
/var/netscaler/logon/LogonPoint/.local_journal; - edits
/etc/httpd.confto run PHP and maps the shell to URLs that resemble legitimate NetScaler style-sheet paths; - sets
/bin/shto mode 6555, which turns on the setuid and setgid bits.
A Python script opens reverse shells and kills processes tied to /var/python/bin/customsnmpd. Mandiant, the same report says, found dozens of organisations affected through CVE-2026-88772, with a PHP shell called WHIPSHOT and a Python tunneler called SLAPSHOT.
NetScaler has appeared on CISA's exploited list before, in the Cisco, Citrix and Fortinet additions, and the JFrog Artifactory chain also ended in admin access. Hunt for the sec_monitor account, the .local_journal file and a setuid /bin/sh on any appliance that ran an affected build after Sept. 26.
Sources
More in Security
- 01Fortinet FortiMail Path-Traversal Flaw Exploited Before Fixes ShipCVE-2026-104286 lets an unauthenticated attacker write files to a FortiMail appliance, and one analyst reading of Fortinet's advisory says the patched builds may not be downloadable yet.
- 02Citrix Confirms Two NetScaler Zero-Days Exploited Since Early SeptemberPalo Alto Networks' Unit 42 traces exploitation of CVE-2026-88771 and CVE-2026-88772 to Sept. 4, 23 days before Citrix published its bulletin, and says patching will not evict an attacker who is already inside.
- 03Cisco SD-WAN Manager Auth Bypass Exploited, With No WorkaroundCVE-2026-76504 gives an unauthenticated attacker admin access to the Catalyst SD-WAN Manager API, and Cisco's only advice besides patching is to keep the interface off untrusted networks.
- 04Three Exploited Edge Flaws Test CISA's Three-Day Patch DeadlineCitrix, Cisco and Fortinet appliances landed in the Known Exploited Vulnerabilities catalog within five days, and BOD 26-04 asks agencies to collect evidence before they patch any of them.