Citrix NetScaler Zero-Days CVE-2026-88771 and CVE-2026-88772 Under Active Exploitation: CISA Gives Federal Agencies Until September 30

Citrix NetScaler Zero-Days CVE-2026-88771 and CVE-2026-88772 Under Active Exploitation: CISA Gives Federal Agencies Until September 30

Citrix NetScaler Zero-Days CVE-2026-88771 and CVE-2026-88772 Under Active Exploitation: CISA Gives Federal Agencies Until September 30

Citrix has confirmed that two critical NetScaler zero-days are being exploited in the wild, and CISA has added both to its Known Exploited Vulnerabilities (KEV) catalog — giving Federal Civilian Executive Branch agencies until September 30, 2026 to apply fixes. The disclosure followed an unusual weekend of private warnings in which Citrix administrators reported that IT suppliers, CERTs and national cybersecurity agencies were contacting them directly and advising them to shut down their NetScaler appliances. "We got a call from our IT supplier's security team, they couldn't give any details but they advised to shut our Netscalers down immediately," one admin wrote on Reddit. The Dutch NCSC-NL had sent a pre-notification to organizations warning of two critical flaws, saying Citrix discovered them while investigating incidents in customer environments and had filed a notification under the EU's Cyber Resilience Act.

The two flaws, both carrying a CVSS score of 9.5, are CVE-2026-88771, an improper input validation issue that lets an unauthenticated attacker execute arbitrary commands on all NetScaler ADC and NetScaler Gateway deployments — including default configurations — and CVE-2026-88772, a memory buffer issue that allows remote code execution or denial of service when DTLS is enabled, an option that is on by default on VPN virtual servers. watchTowr Labs traced CVE-2026-88771 to a Perl script named ns_monuploadd_err.pl that processes NetScaler crash and error data: the script builds a shell command from data an attacker can influence, so a single pre-authentication POST to /nf/auth/doAuthentication.do with crafted log content becomes command injection running as root.

Patches shipped with security bulletin CTX697096: NetScaler ADC and Gateway 14.1-73.37 and later, 13.1-64.23 and later, 14.1-73.37 FIPS and later, and 13.1-37.279 for 13.1-FIPS and NDcPP. The bulletin fixes six other NetScaler flaws as well, and Citrix is upgrading its own managed cloud services. Palo Alto Networks Unit 42 counted more than 50,277 publicly exposed potentially vulnerable instances as of September 27. GreyNoise recorded the earliest exploitation attempt against its sensors on September 24, from IP 149.104.78[.]141: the attacker tried to set the setuid and setgid bits on /bin/sh for a root shell and to install a password-protected web shell that communicates via cookie values to keep commands out of web logs, even configuring the web server to treat a dot file named ".ctxs.receiver" as PHP through a crafted AliasMatch rule.

What Should You Do?

  1. Upgrade now. Affected builds are 14.1 before 14.1-73.37, 13.1 before 13.1-64.23, 14.1-FIPS before 14.1-73.37 FIPS, and 13.1-FIPS/NDcPP before 13.1-37.279; Secure Private Access hybrid deployments must also be upgraded. Because updates can require downtime, CISA's alert exists precisely to force scheduling priority — federal agencies have until September 30.
  2. If you cannot patch immediately, reduce internet exposure of the appliance where operationally possible.
  3. Check Citrix's IoCs in NetScaler Console to determine whether your deployment was impacted.
  4. If compromise is suspected: preserve evidence, isolate the device, revoke credentials and access, investigate every system the NetScaler connected to, rebuild and update the firmware, rotate all local account passwords, Key Encryption Keys and restored SSL certificates, then harden the device per Citrix's best practices.

The WAF Angle

NetScaler sits at the very edge — the application delivery controller and VPN gateway that front the apps your WAF protects — so this is the bug class your WAF will never see coming: the perimeter device itself is the target. Two details deserve a defender's attention. First, the injection works through a second-order path: attacker-controlled bytes land in logs, and a housekeeping script later feeds them to a shell — a reminder that request data outlives the request. Second, the observed post-exploitation is deliberately log-blind: a web shell reachable through an AliasMatch route and cookie-based commands chosen specifically so nothing lands in standard web logs. A WAF in front of NetScaler management traffic helps, but the honest answer is that no request inspection compensates for an unpatched ADC; this is the second unauthenticated NetScaler RCE cycle this quarter, after CVE-2026-8452 was exploited following a PoC release in August. Patch the edge first, then the apps behind it.

Sources