Citrix NetScaler Zero-Days Are Exploited Without Credentials, and Web Shells Survive the Patch
Security / news
Citrix NetScaler Zero-Days Are Exploited Without Credentials, and Web Shells Survive the Patch
CVE-2026-88771 and CVE-2026-88772 both score 9.5. Citrix shipped fixed builds on September 27, but researchers say implants planted earlier persist through the update.

An unauthenticated attacker with network access to a Citrix NetScaler ADC or Gateway appliance can run commands on it through CVE-2026-88771, and the flaw is present in the default configuration. A second bug, CVE-2026-88772, needs the DTLS feature enabled, which is the default for VPN virtual servers. Both score 9.5 under CVSS 4.0, according to watchTowr's FAQ on the pair.
Citrix published bulletin CTX697096 with fixed builds on September 27, 2026. The same day, the US Cybersecurity and Infrastructure Security Agency added both CVEs to its Known Exploited Vulnerabilities catalog and said it had "received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally" in its alert.

Which builds are fixed
The fix is a build number on each release branch, and there is no workaround. watchTowr's FAQ says patching is mandatory.
| Branch | Vulnerable before | Fixed in |
|---|---|---|
| NetScaler ADC and Gateway 14.1 | 14.1-73.37 | 14.1-73.37 |
| NetScaler ADC and Gateway 13.1 | 13.1-64.23 | 13.1-64.23 |
| NetScaler ADC 14.1-FIPS | 14.1-73.37 FIPS | 14.1-73.37 FIPS |
| NetScaler ADC 13.1-FIPS and 13.1-NDcPP | 13.1-37.279 | 13.1-37.279 |
CISA's alert lists eight CVEs in total, CVE-2026-88771 through CVE-2026-88778. Only the first two are in the exploited catalog.
Exploitation began before the patch
The timeline is where the sources diverge, and the divergence matters. watchTowr wrote that on September 26 it "publicly warned that multiple unpatched NetScaler remote code execution vulnerabilities were being exploited in the wild." That is one day before the bulletin.
Tech Times goes further. It reports exploitation of CVE-2026-88771 from early September, three weeks before any patch, and says GreyNoise recorded attempts on September 24. It also dates a Citrix patch to September 24, while watchTowr and CISA both point to September 27. The September 24 patch date is single-sourced and is not confirmed by the bulletin dates elsewhere. The early-September start is likewise Tech Times' account alone.
The same report says watchTowr Labs published a detailed proof-of-concept exploit on September 29, and that mass opportunistic exploitation followed within minutes. watchTowr's FAQ, as retrieved, does not mention a public proof of concept.
The patch does not clean the box
The score overstates nothing here, but it also misses the part that hurts operators most. Tech Times reports more than 100 victim organisations with unique implanted web shells, and says attackers edited httpd.conf so that non-standard file types execute as PHP. That edit lives outside the software the update replaces.
Security researcher Kevin Beaumont is quoted there as saying "patching alone is not sufficient." CISA's own guidance points the same way: check for indicators of compromise before patching, and preserve forensic evidence first, because "updates may result in loss of forensic visibility."
Both bugs lead to root, the report says, because NetScaler runs its packet-processing engine as root on FreeBSD. That is the report's technical claim, and the bulletin text we retrieved does not repeat it.
How many are exposed
Counts differ by method. Tech Times cites 50,277 internet-exposed instances identified as potentially vulnerable by Palo Alto Networks' Cortex Xpanse, and more than 23,000 exposed IP addresses from Shadowserver. It says fewer than 10% of exposed hosts were patched as of September 29.
- Cortex Xpanse (potentially vulnerable)50K instances
- Shadowserver (exposed IPs)23K instances
Source: Tech Times citing Palo Alto Networks Cortex Xpanse and Shadowserver, accessed 2026-10-04
The two figures count different things, so they should not be added together. Shadowserver's is a floor, reported as "more than".
The site has covered the defender-side AI argument elsewhere: Gemini 4 Argon is going to cyber defenders first, and the GPT-6.1 Sol system card rates cyber risk Critical. Neither changes the arithmetic on an appliance that was exploited before its patch existed.
Operators on 14.1 or 13.1 should move to the fixed builds in the table above, and should do so only after capturing logs and checking Citrix's indicators of compromise. A patched appliance that was already compromised stays compromised until the web shells are found and removed.
Sources
More in Security
- 01NetScaler CVE-2026-88779 Is Rated Denial of Service, but a Researcher Reports a Payload DownloadCitrix patched a SAML memory overflow on October 3 and 4 after attacks began. CISA gave agencies until October 7, and the appliances patched last week for CVE-2026-88771 through CVE-2026-88778 need updating again.
- 02Cisco SD-WAN Manager Flaw CVE-2026-76504 Needs One Encoded Character for Admin API Access, With No WorkaroundCisco's PSIRT found exploitation during a support case in September. Six release trains have fixes, and the vendor and two security firms count Cisco's earlier SD-WAN flaws differently.
- 03Two Zammad Zero-Days Took an Attacker From Session Hijack to Root at the Dutch Institute for Vulnerability DisclosureCISA put CVE-2026-102489 and CVE-2026-102490 in its exploited catalog on October 2. DIVD says an AI agent, not a person, ran the intrusion it found on its own ticketing system.
- 04FortiMail CVE-2026-104286 Is Exploited With No Fixed Release, and the Workaround Is Turning Off a FeatureAn unauthenticated path-traversal bug scoring 9.8 lets an attacker write files to FortiMail 7.2 through 8.0. CISA's deadline is October 4; Fortinet had no patch when the advisory went out.