# Citrix NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772): Patch, Then Hunt

> Two NetScaler ADC and Gateway flaws were exploited before Citrix disclosed them on September 27, 2026. Upgrading closes the hole. It does not tell you whether someone already came through it.

- URL: https://firewallsync.com/posts/citrix-netscaler-zero-days-cve-2026-88771-cve-2026-88772-patch-and-hunt/
- Site: FirewallSync (https://firewallsync.com/)
- Topic: Security Operations
- Tags: vulnerability management, incident response
- Published: 2026-10-03
- Author: FirewallSync Editorial

## Key takeaways

- Fixed builds are NetScaler ADC and Gateway 14.1-73.37 and 13.1-64.23, plus 14.1-73.37 FIPS and 13.1-37.279 FIPS/NDcPP. Anything older on those branches is affected.
- Both flaws were exploited before the September 27, 2026 bulletin, so an appliance that was internet-facing in September needs a compromise check, not only an upgrade.
- CVE-2026-88772 is reached over DTLS on UDP port 443, which NetScaler documentation says is on by default for SSL VPN virtual servers.
- Attackers were seen copying the appliance configuration directory, so treat stored credentials, certificates and private keys as exposed if you find signs of compromise.
- The three-day CISA deadline binds US federal civilian agencies only, but it is a fair indicator of how urgent this is for everyone else.



If you run Citrix NetScaler ADC or NetScaler Gateway and are not yet on one of the fixed builds listed below, upgrade now. If the appliance was reachable from the internet at any point in September, also assume the upgrade is only half the job: both flaws were being exploited before Citrix disclosed them, and none of the vendor reports says an upgrade removes what attackers installed.

This article covers what is confirmed, where the vendor reports differ, and the order to work in.

## What Citrix disclosed

On September 27, 2026, Citrix published security bulletin [CTX697096](https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096) covering eight vulnerabilities, CVE-2026-88771 through CVE-2026-88778. Two of them were already under attack. BleepingComputer quotes the bulletin as saying exploits of CVE-2026-88771 and CVE-2026-88772 "on unmitigated NetScaler deployments have been observed."

The details below come from the CVE records that NetScaler itself published as the CVE Numbering Authority (the organization authorized to assign and describe CVE IDs for its own products).

| | CVE-2026-88771 | CVE-2026-88772 |
|---|---|---|
| Weakness | Improper input validation (CWE-20) | Memory buffer bounds error (CWE-119) |
| Impact | Unauthenticated attacker can execute arbitrary commands | Remote code execution or denial of service |
| CVSS 4.0 base score | 9.5 (Critical) | 9.5 (Critical) |
| Attack complexity | Low | High |
| Privileges required | None | None |
| Record published | September 27, 2026 | September 27, 2026 |

CVSS (Common Vulnerability Scoring System) is the industry-standard 0 to 10 severity scale; these scores use version 4.0.

The other six CVEs in the bulletin, CVE-2026-88773 through CVE-2026-88778, carry CVSS 4.0 base scores between 7.0 and 9.3 in their CVE records. As of October 3, 2026, none of the six is in CISA's Known Exploited Vulnerabilities catalog. All eight records list the same fixed builds.

### Affected and fixed builds

| Product branch | Affected | Fixed in |
|---|---|---|
| NetScaler ADC and Gateway 14.1 | Before 14.1-73.37 | 14.1-73.37 and later |
| NetScaler ADC and Gateway 13.1 | Before 13.1-64.23 | 13.1-64.23 and later |
| NetScaler ADC 14.1-FIPS | Before 14.1-73.37 FIPS | 14.1-73.37 FIPS and later |
| NetScaler ADC 13.1-FIPS and 13.1-NDcPP | Before 13.1-37.279 | 13.1-37.279 and later |

A formatting note: seven of the eight CVE records write the last build as "13.1.37.279", while the record for CVE-2026-88773 and Tenable's summary write "13.1-37.279", the format NetScaler build numbers normally use. We read these as the same build; confirm the exact build string on the Citrix download page before upgrading a FIPS or NDcPP appliance.

Versions 12.1 and 13.0 are end-of-life and receive no security updates. Tenable noted on September 27 that Citrix had not said whether they are affected. If you still run either, the absence of a statement is not evidence of safety; plan the migration rather than waiting for one.

### The DTLS precondition

Rapid7 and Tenable both report that CVE-2026-88771 affects default configurations, while CVE-2026-88772 requires DTLS to be enabled. DTLS (Datagram Transport Layer Security) is TLS adapted for UDP, and NetScaler Gateway uses it on UDP port 443 alongside the usual TCP port 443.

That precondition narrows less than it sounds. [NetScaler's own documentation](https://docs.netscaler.com/en-us/netscaler-gateway/current-release/configure-dtls-virtual-server-using-ssl-virtual-server) states: "By default, the DTLS functionality is set to ON for the existing SSL VPN virtual server." Unless someone turned it off, a Gateway deployment meets the condition.

## What is known about exploitation

Three security vendors have published observations. They do not contradict each other, but each describes only what its own telemetry or incident response work showed, so the dates differ.

| Source | What it reports | Dates |
|---|---|---|
| Palo Alto Networks Unit 42 | Requests that fingerprint NetScaler Gateway appliances | From August 21, 2026 |
| Unit 42 | Repeated requests to files in the appliance's `/vpn/scripts/linux/` folder | September 4 to 24, 2026 |
| Google Threat Intelligence Group and Mandiant | Exploitation campaign against organizations in North America and Europe | Since at least early September 2026 |
| Rapid7 | Earliest exploitation it reports: a command that archived the configuration directory into a web-readable path | September 20, 2026, 14:28 UTC |
| Unit 42 | PHP web shell dropped in three stages against a US-based target | September 21, 2026 |

The practical reading: the exposure window for an unpatched, internet-facing appliance opened weeks before the bulletin, not on the day of it. Unit 42 does not attribute the activity to a named group.

On scale, Unit 42 says its Cortex Xpanse scanning "identified 50,277 exposed instances that could potentially be vulnerable" as of September 27, 2026. That is a count of exposed appliances, not of confirmed compromises.

Tenable reported no public proof-of-concept exploit for either flaw as of September 27, 2026. Rapid7 reports that exploitation widened after disclosure. Treat the September 27 statement as a point in time, not a current guarantee.

### What attackers did after getting in

The behavior described by Google and Rapid7 explains why patching alone is not enough:

- **Configuration theft.** Rapid7 observed `tar czf /var/netscaler/gui/vpn/c -C /flash nsconfig`, which packs the configuration directory into a location the web server will hand out. Rapid7 notes that directory holds encrypted administrator passwords, SSL certificates and private keys, and SSH host keys.
- **Web shells behind innocent-looking extensions.** Google documented changes to `/etc/httpd.conf` that make Apache run `.deb` and `.sig` files as PHP, plus an `AliasMatch` rule that maps `.ico` requests under `/vpn/media/` onto those files. The shells answer with HTTP 404, so they look like misses in a casual log review.
- **Root persistence.** Google observed `chmod u+s /bin/sh`, which sets the SUID bit so later web requests execute with root privileges.
- **Tunneling into the network.** Google named two tools: WHIPSHOT, a PHP web shell acting as a tunnel front end, and SLAPSHOT, a Python proxy that listens on a loopback port and records it in `/tmp/.uxdport`.

## What to do, in order

### 1. Preserve evidence before you change anything

If the appliance is a virtual machine, take a snapshot that includes memory before rebooting or upgrading. Google recommends this explicitly, and [Citrix's guidance for a suspected compromise](https://support.citrix.com/external/article/CTX694799/steps-to-take-if-netscaler-adc-is-suspec.html) lists a snapshot, a technical support bundle and a packet engine core dump as the first step. An upgrade reboots the device and discards memory-only evidence.

### 2. Upgrade to a fixed build

Move to the fixed build for your branch from the table above. Google lists the upgrade as its recommended option and advises opening a Severity 1 support case with Citrix if you cannot locate the right build.

If you cannot upgrade immediately, Google describes compensating controls for CVE-2026-88772 only:

- Disable DTLS on internet-facing Gateway virtual servers where you do not need it. The documented command is `set vpn vserver <name> -dtls off`.
- Block inbound UDP port 443 on the perimeter firewall or edge router. Google warns that ACLs on the appliance are not sufficient, because the traffic reaches the vulnerable packet engine first.

Neither control addresses CVE-2026-88771. They buy time for one of the two bugs; they are not a substitute for the upgrade.

### 3. Hunt for compromise

Run these on the appliance shell. All commands are taken from [Google's published hunting guidance](https://cloud.google.com/blog/topics/threat-intelligence/defending-against-active-exploitation-of-citrix-netscaler-adc-and-gateway-appliances). A clean result reduces the likelihood of this specific tooling; it does not prove the device is clean.

Check for tampering in the web server configuration:

```bash
grep -En -i "application/x-httpd-php|php_flag|AliasMatch" /etc/httpd.conf
```

Look for handlers that register non-PHP extensions such as `.deb` or `.sig` as PHP, and for `AliasMatch` rules pointing `/vpn/media/`, `/vpn/theme/` or `/vpn/images/` at script directories.

Search the web directories for PHP where none belongs:

```bash
grep -rlE "<\?php|eval\(|base64_decode\(|shell_exec\(" /var/netscaler/gui/ /netscaler/ns_gui/ /var/vpn/ /netscaler/portal/ 2>/dev/null
```

Check for the tunneling tool's files, the SUID shell and stray Python processes:

```bash
ls -la /tmp/.uxdport* /tmp/.uxdlock
ls -l /bin/sh
ps aux | grep -E "python.*(\.uxd|uxdport|uxdlock|base64)"
```

Permissions of `-rwsr-xr-x` on `/bin/sh` indicate the SUID change. Either `/tmp/.uxd*` file means the proxy is running or ran recently.

Also check for two artifacts from Rapid7's report: a file at `/var/netscaler/gui/vpn/c`, which is the output path of the archive command it observed, and a web shell at `/var/netscaler/logon/LogonPoint/custom/.ctxs.receiver`.

In logs, Google flags two patterns worth alerting on. The first is a DTLS handshake failure with `ClientVersion DTLSv1.0` and the reason "Handshake failure-Internal Error", followed within minutes by a crash of NSPPE (the NetScaler Packet Processing Engine) in `/var/log/messages`. The second is HTTP 404 responses to `/vpn/media/*.ico` that carry multi-kilobyte bodies.

Network indicators such as IP addresses and file hashes change quickly. Pull current lists from the [Google](https://cloud.google.com/blog/topics/threat-intelligence/defending-against-active-exploitation-of-citrix-netscaler-adc-and-gateway-appliances), [Rapid7](https://www.rapid7.com/blog/post/etr-zero-day-exploitation-of-citrix-netscaler-adc-and-gateway-cve-2026-88771-and-cve-2026-88772/) and [Unit 42](https://unit42.paloaltonetworks.com/netscaler-zero-days-exploited/) reports rather than a copy in an article. Google also publishes YARA rules for the web shells and the configuration tampering.

### 4. If you find anything, rebuild rather than clean

Citrix's guidance for a suspected compromise is to remove the appliance from the network, erase and reinstall firmware, upgrade to the latest version, and restore a known good backup that predates the compromise. Google adds one step that is easy to miss in a high-availability pair: disable HA synchronization and assess each node on its own, so a tampered configuration is not replicated to the healthy node.

Given the early September exploitation dates above, a "known good" backup should predate early September 2026 at a minimum, not merely the bulletin. That is our inference from the reported timeline, not vendor guidance.

### 5. Rotate what the appliance knew

Because the configuration directory was a target, Google advises assuming credentials on a compromised appliance are exposed, and rotating them after the appliance is patched:

- NetScaler administrator and local account passwords, and SSH keys
- TLS certificates and their private keys
- LDAP bind and service accounts, RADIUS shared secrets, TACACS credentials
- SNMP community strings and NITRO API credentials

Invalidate active administrative, Gateway and VPN sessions as well. Citrix's guidance goes further on restored devices: rotate the Key Encryption Keys and replace all SSL certificates.

Then look downstream. Google recommends reviewing StoreFront servers, Delivery Controllers and virtual desktop hosts for unexpected interactive logons, RDP activity and signs of credential dumping, since the appliance sits directly in front of them.

## What the CISA deadline means for you

CISA added both CVEs to its Known Exploited Vulnerabilities (KEV) catalog on September 27, 2026, with a due date of September 30, 2026. The catalog entry also requires forensic triage, noting that "customers must conduct forensic triage as directed by BOD 26-04."

Two points of scope. First, according to Tenable's analysis of Binding Operational Directive 26-04, CISA issued the directive on June 10, 2026, it applies to US Federal Civilian Executive Branch agencies, and it is not binding on the private sector, though CISA encourages adoption. Second, the due date has already passed. For an organization outside the federal government, the deadline is useful as a signal: three days is the shortest remediation window in the directive as Tenable describes it, and CISA paired the patch with a mandatory compromise check, which is the same sequence recommended above.

## The pattern worth fixing after the incident

This section is editorial analysis rather than reported fact.

Edge appliances are attractive targets for structural reasons: they face the internet by design, they hold credentials for the directory and authentication systems behind them, and most cannot run the endpoint detection agents that cover servers and laptops. Three changes reduce the cost of the next advisory of this kind:

- **Ship appliance logs off the device.** The hunting steps above depend on `ns.log`, `/var/log/messages` and the HTTP access and error logs. Logs that live only on the appliance are available to whoever compromises it. Our piece on [logging for incidents rather than dashboards](/posts/logging-for-incidents-not-for-dashboards/) covers what to retain.
- **Default-deny outbound traffic from the appliance.** Google recommends permitting only approved destinations such as DNS, NTP, certificate status checks and the backend applications. A tunneling tool is far less useful on a device that cannot open arbitrary connections.
- **Keep management interfaces off the internet.** Restrict the NSIP management address, SSH and the NITRO API to administrative networks.

For triage of the rest of your queue, an actively exploited flaw on an internet-facing device is the case that should jump every line. We cover that prioritization in [the vulnerability backlog that never shrinks](/posts/the-vulnerability-backlog-that-never-shrinks/), and the general response sequence in [what a zero-day is and how to respond to one](/posts/what-is-a-zero-day-vulnerability-and-how-should-you-actually-respond-to-one/).

## Sources and verification

Checked on October 3, 2026. We could not load the Citrix bulletin page directly, so bulletin details are taken from the CVE records NetScaler published and from vendors quoting the bulletin; those rows are marked Qualified.

| Important claim | Source | Verification |
|---|---|---|
| CVE-2026-88771 lets an unauthenticated attacker execute arbitrary commands; CVSS 4.0 base score 9.5 | [CVE record, NetScaler CNA](https://www.cve.org/CVERecord?id=CVE-2026-88771), published September 27, 2026 | Verified |
| CVE-2026-88772 can lead to remote code execution or denial of service; CVSS 4.0 base score 9.5 | [CVE record, NetScaler CNA](https://www.cve.org/CVERecord?id=CVE-2026-88772), published September 27, 2026 | Verified |
| Fixed builds: 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, 13.1-37.279 FIPS/NDcPP | Same CVE records | Verified |
| Citrix states exploitation of both CVEs has been observed | Bulletin [CTX697096](https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096), as quoted by [BleepingComputer](https://www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/) | Qualified: quoted secondhand |
| CVE-2026-88772 requires DTLS to be enabled | Bulletin, as reported by [Rapid7](https://www.rapid7.com/blog/post/etr-zero-day-exploitation-of-citrix-netscaler-adc-and-gateway-cve-2026-88771-and-cve-2026-88772/) and [Tenable](https://www.tenable.com/blog/frequently-asked-questions-about-reported-citrix-netscaler-zero-day-vulnerabilities) | Qualified: reported secondhand |
| DTLS is on by default for an SSL VPN virtual server | [NetScaler Gateway documentation](https://docs.netscaler.com/en-us/netscaler-gateway/current-release/configure-dtls-virtual-server-using-ssl-virtual-server) | Verified |
| Both CVEs added to CISA KEV on September 27, 2026, due September 30, 2026 | [CISA KEV catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-88771), catalog version 2026.10.02 | Verified |
| BOD 26-04 binds US federal civilian agencies only | [Tenable analysis of BOD 26-04](https://www.tenable.com/blog/cisa-bod-26-04-FAQ-vulnerability-remediation-impact) | Qualified: secondary source |
| Exploitation activity predates disclosure | [Google](https://cloud.google.com/blog/topics/threat-intelligence/defending-against-active-exploitation-of-citrix-netscaler-adc-and-gateway-appliances), [Rapid7](https://www.rapid7.com/blog/post/etr-zero-day-exploitation-of-citrix-netscaler-adc-and-gateway-cve-2026-88771-and-cve-2026-88772/), [Unit 42](https://unit42.paloaltonetworks.com/netscaler-zero-days-exploited/) | Qualified: each vendor reports its own visibility; dates differ |
| 50,277 exposed instances potentially vulnerable | [Unit 42](https://unit42.paloaltonetworks.com/netscaler-zero-days-exploited/), as of September 27, 2026 | Qualified: one vendor's scan, exposure not compromise |
| Hunting commands and post-exploitation behavior | [Google Threat Intelligence Group and Mandiant](https://cloud.google.com/blog/topics/threat-intelligence/defending-against-active-exploitation-of-citrix-netscaler-adc-and-gateway-appliances), September 29, 2026 | Verified against the source; not run by us |
| Steps for a suspected compromise | [Citrix CTX694799](https://support.citrix.com/external/article/CTX694799/steps-to-take-if-netscaler-adc-is-suspec.html) | Verified |

FirewallSync has not tested these vulnerabilities or run the hunting commands against a compromised appliance. This is research-based analysis of the sources above.

## Frequently asked questions

### Which NetScaler versions fix CVE-2026-88771 and CVE-2026-88772?

According to the CVE records published by NetScaler, the fixed builds are NetScaler ADC and NetScaler Gateway 14.1-73.37 and 13.1-64.23, NetScaler ADC 14.1-73.37 FIPS, and NetScaler ADC 13.1-37.279 FIPS and NDcPP. Earlier builds on those branches are affected.

### Does upgrading remove an attacker who is already on the appliance?

No vendor source says it does. Google's incident responders documented web shells, an altered Apache configuration and a SUID bit set on /bin/sh. Citrix's guidance for a suspected compromise is to preserve evidence, isolate the device, erase and reinstall firmware, restore a backup that predates the compromise and rotate secrets.

### Do I have to meet the CISA deadline of September 30, 2026?

Only if you are a US Federal Civilian Executive Branch agency. Binding Operational Directive 26-04 applies to those agencies. Private companies are not bound by it, although CISA encourages them to follow the same prioritization.

### Is disabling DTLS enough?

No. Disabling DTLS or blocking inbound UDP port 443 upstream addresses the path used for CVE-2026-88772 only. CVE-2026-88771 is a separate command execution flaw that does not depend on DTLS, so the upgrade is still required.


Image credit: Photo by [Kirill Sh](https://unsplash.com/photos/eVWWr6nmDf8) on Unsplash
