Citrix NetScaler: two zero-days, and patching alone is not enough
Two zero-days in Citrix NetScaler ADC and Gateway are under active exploitation: which builds are affected and what to do before and after updating.
- by blacklens.io Team
- Published
- 4 min read

For many organisations, Citrix NetScaler Gateway is the door through which staff reach the corporate network from outside. Since at least early September, attackers have been opening that door through previously unknown flaws, without logging in and ending up with root. Citrix released updates on 27 September. They close the flaws, but not a backdoor that is already on the device.
What is known about the NetScaler zero-days?
CVE-2026-88771 and CVE-2026-88772 are two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway that let attackers run their own code on the device without authenticating. Citrix published them on 27 September 2026 in security bulletin CTX697096, together with six further flaws, and rated both CVSS 9.5 (v4). Citrix has observed both being exploited on unmitigated deployments. The US agency CISA added them to its KEV catalogue the same day, and Germany's BSI and Austria's CERT.at issued warnings.
The flaws affect customer-managed deployments of these versions; Citrix updates the cloud services it runs itself:
- NetScaler ADC and Gateway 14.1 before
14.1-73.37 - NetScaler ADC and Gateway 13.1 before
13.1-64.23 - NetScaler ADC FIPS 14.1 before
14.1-73.37 FIPS - NetScaler ADC FIPS and NDcPP 13.1 before
13.1-37.279
The Shadowserver Foundation counts more than 20,000 NetScaler instances reachable from the internet and potentially at risk. How many were compromised is unknown. Citrix has disclosed neither the scope nor the timing of the attacks, and as of 30 September no threat actor had been named.
How the attacks on NetScaler work
Both flaws end in command execution on the device before anyone has logged in, by different routes.
CVE-2026-88771, commands via the device's own log: It affects every deployment in its default configuration. CERT-EU's analysis describes a script that, after a Packet Engine failure, searches the log files for the name of the crash dump and inserts the match unquoted into a shell command. Attackers write crafted lines into the log without authenticating, and the script executes them.CVE-2026-88772, memory overflow via DTLS: It requires DTLS, which is enabled by default on VPN virtual servers and therefore on most gateways. According to Mandiant and Google Threat Intelligence, attackers send fragmented, malformed DTLS packets to UDP port 443. These corrupt the Packet Engine's heap memory and yield root privileges on the underlying FreeBSD system.
Mandiant has documented what happens next at government bodies, financial services firms, education institutions and legal and professional services firms in North America and Europe. The attackers modify the web server configuration /etc/httpd.conf so that files ending in .sig and .deb run as PHP. The WHIPSHOT web shell then receives Base64-encoded commands in HTTP headers such as NSC_LDAP. The Python tool SLAPSHOT serves as a tunnel into the internal network: for reconnaissance, credential theft and moving on to other systems.
Why the update alone is not enough
The update closes the flaws but removes neither a web shell nor stolen credentials. Mandiant states explicitly that patching does not remove an existing compromise. By Mandiant's account, the attacks have been running since at least early September, and security researcher Kevin Beaumont describes attacks unfolding throughout the month. CERT-EU therefore recommends a compromise assessment for every internet-facing appliance running an affected build.
The August update is a second trap. On 19 August, Citrix fixed CVE-2026-19490, an authentication bypass (CVSS 9.3), in builds 14.1-73.32 and 13.1-63.21. Those builds are below the new minimum versions and remain vulnerable. Patching quickly in August is not enough now.
A NetScaler Gateway also accepts VPN logins and queries LDAP or RADIUS servers behind it. Anyone with root on it sees the credentials and sessions passing through. The pattern is familiar from FortiBleed: the compromised perimeter device becomes a collection point for credentials.
What helps – and why visibility is decisive
Order matters, because the reboot after the update wipes evidence held in memory:
- Check the inventory: record every NetScaler instance, including test, disaster-recovery and HA partner devices, and compare the build number against the minimum versions above.
- Preserve evidence: before updating, the Dutch NCSC advises backing up memory and at least one month of log files. For virtual appliances, Mandiant recommends a snapshot that includes memory.
- Check for compromise: unfamiliar
AddHandlerorAliasMatchentries in/etc/httpd.conf, PHP files under/var/netscaler/gui/, a SUID bit on/bin/sh, and log entries reading "PPE missed too many heartbeats" alongside Base64 text in the User-Agent. Mandiant provides hunting commands and YARA rules. - Update: to
14.1-73.37or13.1-64.23, or the corresponding FIPS and NDcPP builds. ForCVE-2026-88778, CERT.at (in German) also recommendsset ns tcpparam -enhancedISNgeneration ENABLED. - Renew credentials: rotate admin passwords, SSH keys, TLS certificates and LDAP, RADIUS and API credentials, and terminate active admin, VPN and ICA sessions.
If you cannot update immediately, disabling DTLS or blocking UDP port 443 upstream reduces the risk from CVE-2026-88772. It does nothing against CVE-2026-88771: that flaw has no precondition, and Citrix lists no workaround.
In weeks like this, the inventory takes the longest: which NetScaler instances exist and which are reachable from the internet. blacklens.io builds that inventory continuously from the outside through Attack Surface Management, including devices nobody internally remembers. The Threat Center matches new CVEs like these against the detected technologies, flags KEV entries with the date added and due date, and confirms affected systems with a verification scan where a verification template exists. It does not detect a web shell on the device; that check remains work on the appliance itself.
Frequently asked questions
- CVE-2026-88771 and CVE-2026-88772 are two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway, rated CVSS 9.5, that let attackers run code on the device without authenticating. Citrix released updates on 27 September 2026 and confirms active exploitation. CVE-2026-88771 affects every deployment in its default configuration; CVE-2026-88772 affects devices with DTLS enabled, the default on VPN virtual servers. Both are fixed from builds 14.1-73.37 and 13.1-64.23.
More articles

Threat Center: From CVE alarm to confirmed exposure
The blacklens.io Threat Center is your early warning system for new vulnerabilities: it shows which CVEs affect your systems and confirms it by scan.
- 3 min read

NISG 2026: Austria's NIS2 deadlines from 1 October
Austria's NISG 2026 enters into force on 1 October. Which deadlines apply for registration and self-declaration, and what evidence you need to produce them.
- 5 min read

What First? Intelligent Vulnerability Prioritisation with blacklens
What first, why, and how? blacklens turns open findings into a prioritised remediation plan – sorted by risk reduction, with context on every finding.
- 5 min read
See your attack surface within 24 hours.
We set up your workspace and walk you through the first findings.
- 14 days free, all features
- No credit card required
- We walk you through your first findings