Citrix Confirms Two NetScaler Zero-Days Exploited Since Early September
Security / news
Citrix Confirms Two NetScaler Zero-Days Exploited Since Early September
Palo Alto Networks' Unit 42 traces exploitation of CVE-2026-88771 and CVE-2026-88772 to Sept. 4, 23 days before Citrix published its bulletin, and says patching will not evict an attacker who is already inside.

Attackers exploited two unauthenticated remote-code-execution flaws in Citrix NetScaler ADC and NetScaler Gateway, CVE-2026-88771 and CVE-2026-88772, from at least Sept. 4, three weeks before Citrix published its security bulletin on Sept. 27.
CISA added both to its Known Exploited Vulnerabilities catalog the same day and wrote that "threat actors are actively exploiting these vulnerabilities globally." The agency told organizations to check for signs of compromise before patching, because the update can destroy forensic evidence.
What an attacker needs
CVE-2026-88771 is an improper-input-validation flaw that lets an unauthenticated remote attacker run arbitrary commands. Citrix's bulletin CTX697096 rates it 9.5 on the CVSS v4.0 scale, a 0-to-10 severity score. Per the Help Net Security write-up, it works against default configurations.
CVE-2026-88772 is a memory overflow that leads to code execution or a denial of service. It requires DTLS (a UDP variant of TLS) to be enabled on the appliance, and Help Net Security reports that DTLS is on by default for VPN virtual servers. In practice that means most Gateway deployments are in scope.
Citrix said that "exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed." It did not say who was behind them.
The Unit 42 timeline
Unit 42, the research arm of Palo Alto Networks, published a threat brief that it updated on Sept. 30. Its dates are the only public account of how long this ran.
- Aug. 21: fingerprinting traffic from 104.248.244[.]66 and 77.83.199[.]39.
- Sept. 4 to Sept. 24: DTLS exploitation that dropped a web shell packaged as a .deb file named nsg64.deb.
- Sept. 21: a three-stage command-injection chain.
- Sept. 27: Citrix publishes the bulletin; CISA lists both flaws.
Host indicators include /vpn/scripts/linux/nsgclient18.deb and /var/netscaler/logon/LogonPoint/custom/.ctxs.receiver. Unit 42 lists nine malicious IP addresses in all.
Its warning is the sentence an administrator should read first: "Updating and patching will not remove access for attackers that have already established persistence within a compromise the network." A patched NetScaler can still be a backdoored one.
Affected builds and the other six CVEs
The bulletin covers eight CVEs, CVE-2026-88771 through CVE-2026-88778. Only the first two are listed as exploited.
| CVE | Flaw | CVSS v4.0 |
|---|---|---|
| CVE-2026-88771 | Remote code execution | 9.5 |
| CVE-2026-88772 | Memory overflow, RCE or DoS | 9.5 |
| CVE-2026-88773 | HTTP request smuggling | 9.3 |
| CVE-2026-88775, 88776, 88777, 88778 | DoS overflows, TCP ISN prediction | 8.8 each |
| CVE-2026-88774 | Policy bypass | 7.0 |
- CVE-2026-887719.5 score
- CVE-2026-887729.5 score
- CVE-2026-887739.3 score
- CVE-2026-887758.8 score
- CVE-2026-887747 score
Source: Citrix security bulletin CTX697096, accessed 2026-10-02
Fixed builds are NetScaler ADC and Gateway 14.1-73.37, 13.1-64.23, ADC FIPS 14.1-73.37 FIPS, and ADC FIPS and NDcPP 13.1-37.279. For CVE-2026-88778, Citrix says to change TCP settings to enable Enhanced ISN Generation.
Where the sources disagree
The patch date is not settled. Citrix's bulletin carries a Sept. 27 initial-publication date. Help Net Security, published Sept. 28, gives Sunday, Sept. 29 for the patches and Sept. 30 as the CISA deadline for federal agencies. SecurityWeek reported on Sept. 28 that administrators were shutting appliances down after the Dutch NCSC-NL privately warned of exploitation "at multiple Citrix customers worldwide," so the disclosure was partly forced by leaks.
Researcher Kevin Beaumont, quoted by Help Net Security, called the activity "probably nation state aligned as well resourced, espionage rather than teens." That is one researcher's read, not an attribution from Citrix, CISA or Unit 42.
The count of exposed devices is Palo Alto Networks' own telemetry: 50,277 instances as of Sept. 27, described as potentially vulnerable rather than confirmed compromised. Update to the fixed builds, then hunt for the files and addresses above on every appliance that was reachable in September.
For other CISA-listed edge-device flaws see our coverage of the Johnson Controls EasyIO Neo firmware fix and the Monta EV charging authentication gap.
Sources
More in Security
- 01Fortinet FortiMail Path-Traversal Flaw Exploited Before Fixes ShipCVE-2026-104286 lets an unauthenticated attacker write files to a FortiMail appliance, and one analyst reading of Fortinet's advisory says the patched builds may not be downloadable yet.
- 02Cisco SD-WAN Manager Auth Bypass Exploited, With No WorkaroundCVE-2026-76504 gives an unauthenticated attacker admin access to the Catalyst SD-WAN Manager API, and Cisco's only advice besides patching is to keep the interface off untrusted networks.
- 03Three Exploited Edge Flaws Test CISA's Three-Day Patch DeadlineCitrix, Cisco and Fortinet appliances landed in the Known Exploited Vulnerabilities catalog within five days, and BOD 26-04 asks agencies to collect evidence before they patch any of them.
- 04Monta's EV Charging Platform Has No Patch for a 9.4 Authentication GapCISA lists four flaws in monta.app, all versions. The vendor points operators to an optional OCPP security profile and has shipped no fix.