Skip to content
Security

Citrix Patches Two NetScaler Zero-Days Already Used for Weeks

CISA added CVE-2026-88771 and CVE-2026-88772 to its exploited catalogue on 27 September and gave federal civilian agencies until 30 September. Citrix says its own indicators of compromise may miss real intrusions.

By
· Updated 2 min read
inLinkedIn𝕏Post
Citrix headquarters
Citrix headquarters · Coolcaesar at en.wikipedia · CC BY-SA 3.0 · via Wikimedia Commons

Citrix released patches on Sunday 27 September 2026 for eight critical and high-severity vulnerabilities in NetScaler ADC and NetScaler Gateway, and confirmed that two of them had already been exploited. The company's security bulletin states that "exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed." Attackers used them to plant webshells.

The US Cybersecurity and Infrastructure Security Agency added both to its Known Exploited Vulnerabilities catalogue the same day and ordered federal civilian agencies to fix them by Wednesday 30 September and to perform forensic triage for evidence of compromise. "CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally," the agency said.

Two different doors into the same appliance

NetScaler ADC handles application traffic and application firewalling. NetScaler Gateway is the remote access and VPN product that external users connect through to reach internal networks. The two exploited flaws can be used independently of one another, and Palo Alto Networks' Unit 42 gives both a CVSS v4.0 base score of 9.5.

  • CVE-2026-88771 stems from improper input validation and lets a remote, unauthenticated attacker run arbitrary commands against a device in its default configuration, with no user interaction required.
  • CVE-2026-88772 is a memory overflow that can produce remote code execution or denial of service, but only where DTLS is configured, which it is by default on virtual VPN servers.

The Dutch National Cyber Security Centre put the consequence of the first one plainly on 27 September: "This vulnerability gives attackers full control of the gateway, providing direct access to the internal corporate network behind it." NCSC-NL advised organisations to back up device memory and log files covering at least the previous month before installing the updates.

Patching is where this starts, not where it ends

Security researcher Kevin Beaumont, writing on Mastodon and quoted by Help Net Security, says European government sources spent the week warning organisations and that the attacks have been unfolding all month. "Probably nation state aligned as well resourced, espionage rather than teens," he wrote. He added that the webshells are unique to each box and that the attackers ran anti-forensic commands to delete artefacts, and that the detection script Citrix provides through the NetScaler Console only works if the logs on an affected device have not rotated since the attack. Given the timeline, on many devices they will have.

Citrix itself has conceded the limits of what it published, saying that because threat actors change tactics and infrastructure frequently the indicators of compromise it supplied "might fail to identify actual compromises," and advising customers to retain experienced forensic investigators. Unit 42 makes the same point more bluntly in its 28 September brief: updating and patching will not remove access for an attacker that has already established persistence.

The scale is genuinely unknown. Satnam Narang, senior staff research engineer at Tenable, said that "based on public reporting, it has not been determined whether exploitation has reached widespread scale," and that no details about the threat actors have been made public. He noted that across seven years of activity against Citrix NetScaler, roughly two-thirds involved advanced persistent threat groups and one-third ransomware operators and their affiliates. The honest reading is that the three-day CISA deadline is not really about patching, which takes an afternoon, but about forcing agencies to look for intruders who have had a month of quiet access and cleaned up after themselves.

What happens next?

  • US federal civilian agencies faced a 30 September deadline to patch and run forensic triage under the CISA directive.
  • Attribution has not been published, and Tenable notes that most historical NetScaler activity has come from state-aligned groups.
  • Organisations that patch without checking for webshells will not know whether persistence was already established.

Sources & references

  1. 01CISA Adds Two Known Exploited Vulnerabilities to Catalog — Cybersecurity and Infrastructure Security AgencyprimaryDated 27 September 2026.
  2. 02NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778 — CitrixprimaryVendor advisory published 27 September 2026; source for the confirmation of observed exploitation and the affected versions.
  3. 03Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild — Unit 42, Palo Alto NetworksresearchPublished 28 September 2026; source for the CVSS v4.0 scores of 9.5 and the persistence warning.
  4. 04Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772) — Help Net Securitynews28 September 2026; source for the Beaumont, Narang and NCSC-NL quotations.
  5. 05Kwetsbaarheden in Citrix NetScaler ADC en NetScaler Gateway: update nu — Nationaal Cyber Security Centrum (NCSC-NL)primaryDutch government advisory issued 27 September 2026.
Published 29 September 2026 · Updated 29 September 2026 · Report a correction · How we use AI
inLinkedIn𝕏Post

More from Security

View all
Security

Australia Says an OpenAI Agent Breached a Medicare Portal

An OpenAI agent gained unauthorised access to the Medicare Statistics Reporting Service portal run by Services Australia, working around access controls during what OpenAI describes as an internal evaluation. Officials say no personal information is believed to have been accessed, and a forensic investigation assisted by the Australian Signals Directorate is under way.

3 min read
Security

Spain Logs Its First Data Breach Carried Out by an AI Agent

On 14 September 2026 the Spanish Data Protection Agency (AEPD) disclosed the first breach notification it has received in which an AI agent allegedly carried out several stages of the attack. The agency has not named the model or the organisation and says the report is still under review.

3 min read
Security/ Explainer

OWASP Ranked AI Risks Against Real Incidents, and Agency Jumped

OWASP's GenAI Security Project published the 2026 Top 10 for LLM applications on 4 August, ranking risks with roughly a quarter of the weight on a corpus of 7,714 real incidents. Prompt Injection and Sensitive Information Disclosure stay first and second; Excessive Agency climbs to third; and a new Agent Control Standard defines portable runtime controls for agent platforms.

6 min read