CVE-2026-88771 & CVE-2026-88772 (CVSSv4 9.5): Citrix NetScaler Zero-Days Planted Webshells on 50,000+ Gateways — Patch Emergency Declared
Since at least mid-September 2026 — weeks before Citrix published a single line of advisory — threat actors have been quietly planting webshells inside production Citrix NetScaler ADC and Gateway appliances around the world. The mechanism: two freshly confirmed zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, both carrying a CVSSv4 score of 9.5 Critical. On September 27, 2026, Citrix rushed out security bulletin CTX697096 and patched eight flaws simultaneously. CISA added the two actively exploited bugs to its Known Exploited Vulnerabilities catalog the same day and issued an urgent patching directive for federal agencies.
With 50,277 vulnerable NetScaler instances still reachable over the internet as of the disclosure date (per Palo Alto Networks Cortex Xpanse telemetry), this is not a vulnerability you schedule for your next maintenance window. These appliances are Internet-facing edge devices — the very front door to your enterprise network. If attackers have already moved through yours, patching alone will not evict them.
- CVE-2026-88771 (CVSSv4 9.5) — Unauthenticated RCE via improper input validation; exploitable on all NetScaler ADC/Gateway deployments in default configuration.
- CVE-2026-88772 (CVSSv4 9.5) — Memory overflow leading to RCE or DoS when DTLS is enabled; DTLS is on by default on VPN virtual servers.
- Both bugs exploited as zero-days before Citrix disclosure — webshells confirmed on compromised devices.
- Affected: NetScaler ADC/Gateway 14.1 before 14.1-73.37 and 13.1 before 13.1-64.23 (plus FIPS variants).
- Fixed versions: 14.1-73.37 and 13.1-64.23 (and corresponding FIPS/NDcPP releases).
- CISA has added both CVEs to the KEV catalog; federal mandatory patching deadline in effect.
- Check for compromise before you patch — the upgrade may overwrite forensic evidence.
The Zero-Day Timeline: Exploitation Preceded Disclosure by Weeks
The Dutch National Cyber Security Centre (NCSC-NL) issued private pre-disclosure warnings to partner organisations over the weekend of September 26–27 — days ahead of Citrix’s own public bulletin. Help Net Security reported that exploitation had been ongoing for several weeks, meaning many organisations may have been compromised long before any patch was available. Webshells — persistent backdoor scripts that survive reboots — were found on compromised appliances, confirming that attackers were establishing long-term access rather than just running one-off commands.
This pre-patch exploitation window is the most dangerous phase of any zero-day: there is nothing to install, nothing to update, and no official indicator of compromise until the vendor acknowledges the issue. It is precisely why a layered architecture that treats even trusted perimeter devices as potentially hostile — rather than relying solely on reactive patch management — is the only sustainable security posture. We explored this principle in detail in our zero-trust campus deployment deep-dive.
The pattern is also becoming familiar. Just four days ago, we reported on the Check Point VPN zero-days under active attack. Network edge appliances — VPN gateways, load balancers, SSL offloaders — are now primary targets for advanced threat actors because they are high-value, always Internet-facing, and often under-monitored.
Technical Breakdown: How CVE-2026-88771 and CVE-2026-88772 Work
Understanding the mechanics helps security teams correctly scope the exposure and prioritise response steps.
CVE-2026-88771 — Unauthenticated Command Injection (CVSSv4 9.5)
This flaw is an improper input validation vulnerability in NetScaler’s HTTP request processing stack. An unauthenticated remote attacker sends crafted HTTP requests containing command injection payloads to the appliance’s interface. The injected commands execute with the privileges of the NetScaler packet processing engine, which has deep system access. No special configuration is required, no unusual features need to be enabled, and no prior authentication is needed. Every NetScaler ADC and Gateway instance on a vulnerable build is affected in its default out-of-box state. This is the higher-risk of the two bugs for most organisations because its attack complexity is low and it requires no preconditions whatsoever.
CVE-2026-88772 — DTLS Memory Overflow Leading to RCE/DoS (CVSSv4 9.5)
This is a memory corruption flaw in the DTLS (Datagram Transport Layer Security) protocol processing path. DTLS is enabled by default on VPN virtual servers in NetScaler Gateway, meaning the vast majority of Gateway deployments meet the exploitation precondition without any manual configuration. An attacker sends malformed DTLS packets; depending on heap layout, the overflow can yield remote code execution or crash the appliance in a denial-of-service. The higher attack complexity (relative to CVE-2026-88771) makes it slightly harder to weaponise reliably, but the CVSS score is identical because the potential impact is equally catastrophic.
| CVE | CVSSv4 | Vulnerability Type | Auth? | Status |
|---|---|---|---|---|
| CVE-2026-88771 | 9.5 Critical | Improper Input Validation → RCE | None | Actively Exploited |
| CVE-2026-88772 | 9.5 Critical | Memory Overflow → RCE/DoS (DTLS) | None | Actively Exploited |
| CVE-2026-88773 | 9.3 Critical | TBD | TBD | No exploitation confirmed |
| CVE-2026-88774 through 88778 | 7.0–8.8 High | Various | Varies | No exploitation confirmed |
Scale of Exposure: 50,000 Gateways, India Included
As of September 27, 2026, Palo Alto Networks Unit 42 identified 50,277 internet-exposed NetScaler instances that remain potentially vulnerable based on build-version fingerprinting telemetry. This is a conservative figure — appliances that suppress version banners may be undetected.
Citrix NetScaler is pervasive across Indian enterprise infrastructure. BFSI (banking, financial services, and insurance), IT/ITeS, healthcare, and government sectors all rely heavily on NetScaler as the load balancing, SSL offloading, and remote-access layer in front of critical applications. Many organisations deployed NetScaler Gateway as their primary SSL-VPN solution during the work-from-home era — and those deployments remain in production today as the backbone of hybrid-work remote access for tens of thousands of employees.
In that architecture, a successful exploit against CVE-2026-88771 or CVE-2026-88772 gives an attacker a persistent, privileged foothold behind the perimeter, with the ability to inspect all traffic transiting the device — including authentication credentials, session tokens, and sensitive application data. India’s CERT-In has not yet issued a separate advisory as of September 29, 2026, but given the global scale and the device’s prevalence in Indian enterprise environments, organisations should not wait for a local advisory before acting.
What You Should Do Right Now: Emergency Response
This situation requires emergency-basis action, not standard change-management scheduling. Here is a prioritised checklist:
- Inventory every NetScaler instance immediately. Run
nsapimgr -ys versionon each appliance and compare against the affected version list. Prioritise Internet-facing appliances and those fronting payment systems, HR systems, or privileged-access portals. - Assess for compromise before patching. Citrix has published compromise assessment guidance accessible through NetScaler Console. Critically: patching may overwrite forensic evidence — webshells, modified binaries, and attacker tooling can be obscured or removed during an in-place upgrade. Preserve logs, capture relevant file-system artefacts, and run a compromise assessment first. If active compromise is found, treat the appliance as untrusted and invoke your IR process.
- Apply the fixed builds:
- NetScaler ADC/Gateway 14.1 → upgrade to 14.1-73.37 or later
- NetScaler ADC/Gateway 13.1 → upgrade to 13.1-64.23 or later
- NetScaler ADC FIPS (14.1) → upgrade to 14.1-73.37 FIPS or later
- NetScaler ADC FIPS/NDcPP (13.1) → upgrade to 13.1.37.279 or later
- If immediate patching is not possible: Restrict access to the appliance’s management interface and move it behind an out-of-band management VLAN with no public reachability. For CVE-2026-88772 specifically, explicitly disable DTLS on VPN virtual servers if that feature is not required — this removes the attack vector for that particular bug, though it does not mitigate CVE-2026-88771.
- Deploy IDS/IPS detection. Rapid7 published Suricata detection rules for CVE-2026-88771 through their Intelligence Hub as of September 29, 2026. Load these rules into any IDS/IPS sensors facing NetScaler appliances.
- Rotate all credentials transiting the appliance. If compromise is suspected, treat every credential that has passed through the NetScaler as potentially stolen: service account passwords, certificates, Kerberos tickets, RADIUS shared secrets. Rotate immediately and audit for anomalous access.
- Review east-west paths and lateral movement. Assume attackers with weeks of undetected access may have pivoted internally. Review SIEM logs for unusual connections originating from the NetScaler’s IP ranges and audit firewall rules governing what the appliance can reach inside the network.
Frequently Asked Questions
Are cloud-hosted and Citrix Cloud deployments also affected?
The vulnerabilities exist in the NetScaler ADC and NetScaler Gateway software itself, regardless of where it runs — on-premises hardware appliances, VPX virtual appliances on VMware or Hyper-V, and cloud-marketplace images (AWS, Azure, GCP) running affected build versions are all vulnerable. Organisations using a fully managed Citrix Cloud service where Citrix controls the infrastructure should confirm patching status directly with their Citrix account team; Citrix typically applies updates to managed infrastructure through its own maintenance windows.
How can I tell if my appliance was already compromised?
Attackers have planted webshells — persistent file-based backdoors — in web-accessible directories on compromised appliances. Check for unexpected files in the NetScaler file system, particularly under /netscaler/ and web root paths. Review process listings for unusual parent-child process relationships, examine outbound TCP connections from the management IP, and run Citrix’s compromise assessment tool available through NetScaler Console. Rapid7’s Suricata rules for CVE-2026-88771 can also detect ongoing exploitation attempts in network traffic.
Does disabling DTLS mitigate both vulnerabilities?
No. Disabling DTLS on VPN virtual servers mitigates CVE-2026-88772 specifically, because that bug requires DTLS to be enabled. It has no effect on CVE-2026-88771, which exploits the HTTP request processing path and requires no special features or protocols. Both vulnerabilities require applying the patched builds to be fully remediated.
Is there a public proof-of-concept exploit available?
As of September 29, 2026, no public PoC exploit code has been published for either CVE. However, both bugs were actively exploited in the wild for weeks before Citrix’s disclosure, meaning functional exploit code clearly exists in threat-actor hands. The absence of a public PoC does not reduce the urgency — waiting for one before patching is an outdated mental model for zero-days in active exploitation.
Citrix NetScaler is the front door to thousands of enterprise networks. If your appliance has not been patched — or not been checked for compromise — that door may already be standing open. At P J Networks, we help organisations across India assess perimeter-device exposure, conduct forensic investigations on suspected compromises, and design zero-trust architectures that limit the blast radius when perimeter devices fall under attack.
Contact us today for an emergency security assessment — particularly if you run Citrix NetScaler in your environment and have not yet confirmed your patch and compromise status.