Threat Landscape

Citrix NetScaler zero-days CVE-2026-88771 / 88772 — confirmed ITW; CISA KEV; FCEB patch by Sep 30.

Citrix published CTX697096 on Sunday, September 27, 2026 for eight NetScaler ADC / Gateway flaws. Confirmed in-the-wild exploitation of CVE-2026-88771 and CVE-2026-88772 (CVSS 9.5 each): unauthenticated RCE on default configs, and RCE-or-DoS when DTLS is on (default on VPN vServers). CISA added both to KEV the same day; FCEB BOD deadline September 30. Pre-patch weekend: NCSC-NL private warnings and admins told to shut appliances (Sat Sep 26). Shadowserver: ~23k internet-exposed NetScaler fingerprints — not a confirmed vulnerable count.

Sep 28, 2026 · 3 min read

Edge appliance, unauth RCE, vendor-confirmed exploitation, federal clock already running. That is the Monday lead.

Primary: Citrix security bulletin CTX697096 (initial publication 2026-09-27). Table of eight CVEs; the two with observed exploits:

CVE-2026-88771 — improper input validation (CWE-20) → unauthenticated arbitrary command execution. Pre-condition: all NetScaler ADC and Gateway deployments, including default configuration; no extra feature required. CVSS v4 base 9.5.

CVE-2026-88772 — memory overflow (CWE-119) → remote code execution or denial of service. Pre-condition: DTLS enabled on ADC/Gateway; Citrix notes DTLS is enabled by default on VPN virtual servers. CVSS v4 base 9.5.

Citrix wording on exploitation: “Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed.” Cloud Software Group “strongly urges” affected customers to install updated builds ASAP. Fixed builds cited in the bulletin: 14.1-73.37+, 13.1-64.23+, 14.1-FIPS 14.1-73.37 FIPS+, 13.1-FIPS / 13.1-NDcPP 13.1.37.279+. Affected: those branches before those builds. Secure Private Access Hybrid NetScaler instances also need the recommended builds. Bulletin scope: customer-managed ADC/Gateway; Citrix-managed cloud / Adaptive Authentication is handled by Cloud SG. Victim census / actor attribution: Undisclosed.

The other six in the same bulletin (not the KEV pair): CVE-2026-88773 HTTP request smuggling (9.3); CVE-2026-88774 feature policy bypass (7.0); CVE-2026-88775 / 88776 / 88777 memory-overflow DoS / erratic behavior paths (8.8 each, config-gated); CVE-2026-88778 TCP ISN prediction (8.8) — mitigated via enhanced ISN generation TCP config change per NetScaler docs, not only a build bump. No ITW claims for those six; Citrix’s observed-exploit sentence names 88771 and 88772 only.

CISA same day (Sep 27): alert amplifying the eight CVEs and confirming active exploitation of the two critical zero-days “globally”; separate KEV notice adding CVE-2026-88771 (improper input validation) and CVE-2026-88772 (improper restriction of operations within the bounds of a memory buffer). Per BOD 26-04, FCEB agencies must remediate KEV entries on publicly exposed assets that grant total control post-exploitation — secondary reporting (BleepingComputer Sep 28) puts the Citrix deadline at September 30. CISA also: check for IoC before patching when possible; preserve forensics if compromise is suspected (updates can wipe visibility). Citrix ships “generic” IoCs via NetScaler Console and has published compromise-assessment guidance — vendor itself warns those IoCs “might be of limited forensic value.”

Pre-disclosure weekend (secondary, consistent across SecurityWeek / BC): starting Saturday, September 26, NetScaler admins reported IT suppliers, CERT/MDR, and national agencies telling them to shut appliances immediately, often without public detail. Thread material traced to a private NCSC-NL pre-notification (reportedly TLP:AMBER) describing two critical NetScaler zero-days without CVE IDs, exploitation identified at multiple Citrix customers worldwide, and Citrix discovering issues while investigating customer incidents. NCSC-NL declined to confirm the circulated notice to non-constituency press. watchTowr publicly flagged credible rumors of multiple unpatched NetScaler RCEs before the bulletin landed. Reddit/TLP copies are not primary; Citrix + CISA are the sources for the confirmed CVEs and ITW.

Exposure vs vulnerability: Shadowserver tracks roughly 23,000 IP addresses with NetScaler fingerprints on the public internet (BC breakdown: nearly ~22k ADC fingerprints and just over ~1.5k Gateway). That is an internet-exposed fingerprint count, not a confirmed vulnerable-install census — honeypots, already-patched boxes, and non-vulnerable configs are not separated in that figure. Successful-compromise count: Undisclosed.

Update Sep 29: CERT-EU published a root-cause write-up (Mon Sep 28, 19:30 CEST) for CVE-2026-88771: a log-injection path. Attackers stuff base64 bash payloads into HTTP User-Agent strings, then hammer authentication logs with a crafted username containing the string PPE missed too many heartbeats; when NetScaler’s ns_monuploadd_err.pl script greps the logs for that line, the value is interpolated unquoted into a shell command and executed. Observed post-compromise: /etc/httpd.conf modified to enable PHP, then a web shell dropped in an internet-reachable path. CERT-EU credits colleagues at the European Court of Auditors and European Central Bank for spotting the attacker IPs in NetScaler logs (CERT-EU does not state either was compromised). Hunt: auth logs for that heartbeat string, base64 in User-Agent fields, httpd.conf integrity — then patch. With the mechanism now public, expect faster weaponization ahead of the Sep 30 FCEB deadline.

Update Sep 29 evening — Mandiant / GTIG primary: Google Cloud blog Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances (Sep 29). Mandiant Consulting + GTIG: active ITW on CVE-2026-88772 since at least early September; sectors observed as likely impacted: North America and Europe — government, financial services, technology, education, legal and professional services. Exact victim census: Undisclosed in the blog (CyberScoop quotes Mandiant Consulting CTO Charles Carmakal: “dozens of impacted organizations”; LinkedIn post attributes to “advanced and suspected state-sponsored threat actors”; those phrases are Carmakal/CyberScoop’s, not a CyberMerge count). Post-exploitation toolkit newly named: WHIPSHOT (PHP web shell; Base64 C2 in HTTP headers; can launch companion) and SLAPSHOT (Python TCP tunneler into internal nets for recon/credential theft). Persistence patterns: httpd.conf handlers for .deb / .sig, icon AliasMatch under /vpn/media/, setuid on /bin/sh, artifacts /tmp/.uxdport and /tmp/.uxdlock. Mandiant notes Citrix also disclosed ITW on CVE-2026-88771; DTLS/UDP-443 mitigations address 88772 only — fixed builds required for both. GreyNoise (via BC): 88771 exploit attempt observed Sep 24 from 149.104.78.141. FCEB BOD deadline remains September 30 — hunt before you overwrite forensics if you can.

POV: Patch CTX697096 builds now; treat internet-facing ADC/Gateway as KEV-urgent through Sep 30 for FCEB and as board-urgent for everyone else. Hunt/IoC via NetScaler Console before you overwrite disks if you can. Shadowserver’s ~23k exposed fingerprints do not equal “23k vulnerable.” Sources: CTX697096 + CISA Sep 27 alerts; the pre-patch shutdown timeline is per BC / SecurityWeek / watchTowr.

Sources