US, UK, and Dutch Agencies Warn of Actively Exploited Citrix NetScaler Zero-Days
Incident responders began warning of potential vulnerabilities in NetScaler Gateway products on Saturday, September 26, 2026, after a private, TLP:AMBER pre-notification from the Dutch National Cyber Security Centre (NCSC-NL) prompted some administrators to be told to shut their appliances down. On Sunday, September 27, cybersecurity agencies in the Netherlands, United States, and United Kingdom released public advisories confirming the vulnerabilities, and Citrix simultaneously published security bulletin CTX697096, confirming eight new vulnerabilities in NetScaler ADC and NetScaler Gateway. Two of the eight — CVE-2026-88771 and CVE-2026-88772 — were confirmed as actively exploited zero-days, with attackers reportedly abusing them for weeks before a fix existed.
Incident Details
| Attribute | Value |
|---|---|
| Disclosure date | September 27, 2026 (Citrix bulletin CTX697096) |
| Vulnerabilities disclosed | 8 total (CVE-2026-88771 through CVE-2026-88778) |
| Actively exploited (zero-days) | CVE-2026-88771, CVE-2026-88772 |
| Highest severity | CVSS 4.0 9.5 (Critical) — CVE-2026-88771 and CVE-2026-88772 |
| Affected products | Citrix NetScaler ADC and NetScaler Gateway |
| Agencies issuing advisories | CISA (US), NCSC-UK, NCSC-NL |
| CISA KEV addition | September 27, 2026 |
| Federal patch deadline | September 30, 2026 (BOD 26-04) |
| Estimated internet-exposed instances | Roughly 22,000–23,000 (Shadowserver scan data) |
| Discoverer / early public warning | watchTowr Labs, researcher Kevin Beaumont |
How It Worked
The exploited flaws
CVE-2026-88771 is an improper input-validation flaw that Citrix confirmed allows a remote, unauthenticated attacker to execute arbitrary commands on a vulnerable device. Citrix stated that "all NetScaler ADC and NetScaler Gateway deployments are affected, including the default configuration, and no additional features need to be enabled" — meaning internet-facing appliances did not need any non-default setup to be at risk. NCSC-NL described the impact bluntly: the vulnerability "gives attackers full control of the gateway, providing direct access to the internal corporate network behind it."
CVE-2026-88772 is a memory-overflow vulnerability that can lead to remote code execution or denial of service, but only when Datagram Transport Layer Security (DTLS) is enabled — a setting that is on by default for NetScaler Gateway virtual VPN servers, meaning a large share of deployments were still exposed.
According to watchTowr Labs, both flaws require only network reachability to the appliance — "not a valid account" — making them attractive for opportunistic, internet-wide scanning and exploitation.
The remaining six disclosures
Citrix's bulletin also patched six additional, non-exploited vulnerabilities in the same release: CVE-2026-88773 (HTTP request smuggling, CVSS 9.3), CVE-2026-88774 (configuration-dependent flaw, CVSS 7.0), CVE-2026-88775, CVE-2026-88776, and CVE-2026-88777 (configuration-dependent memory-overflow issues, each CVSS 8.8), and CVE-2026-88778 (predictable value generation tied to the Enhanced Initial Sequence Number feature, CVSS 8.8). None of these six have been confirmed exploited to date, but agencies urged patching all eight together since a single cumulative build addresses them.
Exploitation timeline and webshells
Reporting from The Record, watchTowr, and Help Net Security indicates exploitation of CVE-2026-88771 traces back through much of September 2026, before any public advisory or patch existed — a genuine pre-disclosure zero-day. Attackers who compromised devices reportedly planted unique webshells per compromised appliance and ran anti-forensics commands to cover their tracks. Citrix and researchers identified detection indicators including base64-encoded strings appended after the HTTP User-Agent header and the strings "pitboss" and "IFS" associated with the malicious activity. Citrix cautioned that its own compromise-detection script "only functions if logs haven't rotated since the attack," meaning a clean scan result does not prove a device was never compromised.
Scale of exposure
Internet-scanning data cited by multiple outlets, including figures attributed to Shadowserver, put exposed NetScaler instances at roughly 22,000 to 23,000 globally — including nearly 22,000 NetScaler ADC appliances and more than 1,500 Gateway instances — with a large share located in the United States. Researchers cautioned that confirmed compromises appear narrower than the exposure count, though the true scope may not be known for some time given the anti-forensics activity observed.
Impact Assessment
| Impact Area | Description |
|---|---|
| Confidentiality | Unauthenticated RCE (CVE-2026-88771) grants full device control, exposing internal network access behind the gateway |
| Availability | CVE-2026-88772 can trigger denial of service on DTLS-enabled VPN virtual servers |
| Forensic visibility | Patching before evidence collection can destroy logs and memory artifacts needed to determine compromise |
| Federal exposure | CISA's Known Exploited Vulnerabilities listing carries a mandatory Binding Operational Directive 26-04 remediation deadline for US federal civilian agencies |
| Enterprise exposure | NetScaler Gateway is widely used for remote-access VPN, making compromised appliances a direct pivot point into corporate networks |
| End-of-life risk | NetScaler versions 12.1 and 13.0 are end-of-life and receive no fix; they must be replaced, not patched |
Recommendations
For administrators of NetScaler ADC/Gateway
- Identify all NetScaler ADC and NetScaler Gateway appliances, including Secure Private Access Hybrid deployments, and confirm their build numbers.
- Upgrade immediately to the fixed builds: 14.1-73.37 or later, 13.1-64.23 or later, NetScaler ADC 14.1-FIPS build 14.1-73.37 FIPS or later, and 13.1-FIPS/13.1-NDcPP build 13.1-37.279 or later, per Citrix bulletin CTX697096.
- Replace any appliance still running NetScaler 12.1 or 13.0 — these branches are end-of-life and will not receive a fix.
- Before patching, capture device memory, log files (covering at least the prior month), support bundles, and core dumps to preserve forensic evidence, per NCSC-NL guidance.
- On 13.1 builds, run
show ns variableprior to the upgrade, as recommended by watchTowr's advisory.
For security teams
- Run Citrix's indicator-of-compromise scan via the NetScaler Console Security Advisory page (requires build 14.1-73.36 or later with telemetry enabled), or request indicators directly from Citrix Support — but treat a clean result as inconclusive if logs have already rotated.
- Hunt for webshell indicators, including base64-encoded strings appended after the
User-Agentheader and the strings "pitboss" and "IFS" in appliance logs. - Forward NetScaler logs to a SIEM going forward, and restrict management interfaces from direct public internet exposure.
- Rotate credentials, session secrets, and certificates on any appliance suspected of compromise, since attackers with device-level access can harvest these values.
- Engage a forensic investigator for any device showing signs of compromise given the anti-forensics behavior observed in these attacks.
For end users and downstream organizations
- If your organization relies on a third party's NetScaler Gateway for remote access (VPN, partner access), ask the provider to confirm patch status and compromise-assessment results.
- Be alert to unusual authentication prompts, session resets, or credential-rotation notices from services that sit behind NetScaler Gateway, as these may follow a provider's incident response.
- Report any suspicious login activity on accounts that use VPN or remote-access services fronted by NetScaler, particularly in the days following September 26, 2026.
Key Takeaways
- CVE-2026-88771 and CVE-2026-88772 (both CVSS 9.5) were exploited as true zero-days against Citrix NetScaler ADC and Gateway before any patch existed, with exploitation reportedly underway for weeks in September 2026.
- Citrix disclosed eight vulnerabilities in total (CVE-2026-88771 through CVE-2026-88778) in security bulletin CTX697096 on September 27, 2026; only the first two are confirmed exploited.
- CVE-2026-88771 affects all deployments in default configuration with no authentication required; CVE-2026-88772 requires DTLS, which is on by default for Gateway VPN virtual servers.
- CISA added both flaws to its Known Exploited Vulnerabilities catalog and, under Binding Operational Directive 26-04, gave US federal civilian agencies until September 30, 2026 to remediate.
- Roughly 22,000–23,000 NetScaler instances remain internet-exposed globally according to scan data; attackers have planted webshells and used anti-forensics techniques on compromised appliances.
- Organizations must preserve forensic evidence before patching — capturing memory, logs, and support bundles first — because the update itself can erase the artifacts needed to confirm compromise, and NetScaler 12.1/13.0 must be replaced outright as they are end-of-life.
Sources
- US, UK warn of Citrix NetScaler zero-day bug — The Record
- Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC and Gateway — CISA
- Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway — NCSC-UK
- Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin CTX697096 — Citrix
- Citrix NetScaler Zero-Day RCE FAQ: CVE-2026-88771 and CVE-2026-88772 — watchTowr
- Citrix NetScaler RCE zero-days exploited globally for weeks — Help Net Security
- CISA orders feds to patch exploited Citrix flaws by Wednesday — BleepingComputer