BlackTree Security · Infrastructure · Automation · AI

Attackers Are Already Exploiting the NetScaler Flaws Citrix Just Patched

Citrix has released fixes for eight vulnerabilities in NetScaler ADC and NetScaler Gateway, and says attackers are already exploiting two of them on unmitigated systems. This is not a routine patch bundle. One of the exploited flaws gives an unauthenticated attacker a path to arbitrary command execution across every customer-managed deployment, including default configurations.

The critical issue is CVE-2026-88771, an improper input-validation vulnerability with a CVSS v4 score of 9.5. Citrix says no optional feature needs to be enabled. If the appliance is running an affected build, the precondition is met.

Citrix has also observed exploitation of CVE-2026-88772, another CVSS 9.5 flaw. It is a memory-overflow vulnerability that can lead to remote code execution or denial of service when DTLS is enabled. DTLS is enabled by default on VPN virtual servers unless administrators explicitly turn it off.

The patch window is already an incident-response window

Citrix’s CTX697096 security bulletin states plainly that exploits of CVE-2026-88771 and CVE-2026-88772 have been observed on unmitigated deployments.

Update, 29 September: intruders reached beyond the gateway

Google Threat Intelligence Group and Mandiant link successful intrusions to CVE-2026-88772 since at least early September. Likely impacts span North America and Europe, including government, finance, education and professional services. Google has no exploit code; its assessment of root-level compromise rests on telemetry.

Intruders deployed WHIPSHOT and SLAPSHOT. In at least one intrusion, a tunnel supported internal reconnaissance and credential theft. That does not establish every victim’s outcome.

Treat the upgrade and the compromise assessment as separate jobs. Patching closes the known vulnerable paths, but it cannot prove that an internet-facing appliance was clean before the upgrade. Organisations with exposed NetScaler gateways should run the upgrade and compromise assessment as parallel workstreams.

The urgency is amplified by where these products sit. NetScaler Gateway controls remote access and often fronts authentication, VPN and application traffic. An unauthenticated command-execution path at that boundary can turn a security control into an initial foothold.

Update, 4 October: targeted SAML attacks now have fixed builds

Citrix identifies CVE-2026-88779 as a CVSS v4.0 8.7 memory overflow. Citrix says targeted attacks against unmitigated deployments can cause denial of service and repeated unavailability; it has not identified customer-data integrity impact.

The precondition is a customer-managed Gateway or AAA deployment configured as a SAML SP with add authentication samlAction, or a SAML IdP with add authentication samlIdPProfile. Hybrid NetScaler instances are included; Citrix-managed services receive vendor updates.

Upgrade ADC and Gateway 14.1 to 14.1-73.41, ADC and Gateway 13.1 to 13.1-64.28, ADC 14.1 FIPS to 14.1-73.41 FIPS, or ADC 13.1 FIPS and NDcPP to 13.1-37.282, or later within each branch. Deployments already upgraded for CTX697096 must upgrade again when this SAML precondition applies. The vendor statement covers availability; it does not establish remote code execution, data theft or compromise.

Update, 4 October: CISA adds the flaw to KEV

CISA added CVE-2026-88779 to its Known Exploited Vulnerabilities catalogue on 4 October. The entry lists 7 October as its remediation due date, marks forensic triage Yes and lists ransomware use as Unknown.

For US Federal Civilian Executive Branch agencies, BOD 26-04 applies asset by asset and the agency makes the final exposure determination. The catalogue date is not a universal legal deadline. Other exposed operators can treat the KEV addition as a prioritisation signal: upgrade, preserve volatile evidence where practical and assess whether the environment was affected.

CISA’s implementation guidance recommends scoping affected assets, preserving relevant evidence before remediation where possible, then stabilising, containing, analysing and documenting the escalation decision. Its step-specific target times are recommended practices; the directive requires adequate forensic triage, not those exact intermediate timings.

Which CTX697096 builds were required on 27 September

Citrix lists the following customer-managed releases as affected:

Product branchAffected buildsFixed build
NetScaler ADC and NetScaler Gateway 14.1Before 14.1-73.3714.1-73.37 or later
NetScaler ADC and NetScaler Gateway 13.1Before 13.1-64.2313.1-64.23 or later
NetScaler ADC 14.1 FIPSBefore 14.1-73.37 FIPS14.1-73.37 FIPS or later
NetScaler ADC 13.1 FIPS and NDcPPBefore 13.1-37.27913.1-37.279 or later

Secure Private Access Hybrid deployments that use NetScaler instances are also affected and require those instances to be upgraded. Citrix says its managed cloud services and managed Adaptive Authentication service are being upgraded by Cloud Software Group. Customers should not assume that statement covers appliances they manage themselves as part of a hybrid deployment.

Eight flaws, but the first two set the triage order

VulnerabilityImpactPreconditionCVSS v4
CVE-2026-88771Unauthenticated arbitrary command execution through improper input validationEvery deployment, including the default configuration9.5
CVE-2026-88772Memory overflow leading to remote code execution or denial of serviceDTLS enabled, including by default on VPN virtual servers9.5
CVE-2026-88773HTTP request smugglingHTTP configuration enabled9.3
CVE-2026-88774Feature-policy bypass caused by HTTP URL expression useA policy uses an HTTP URL-based expression7.0
CVE-2026-88775Memory overflow causing erroneous behaviour or denial of serviceGateway or AAA virtual-server configuration8.8
CVE-2026-88776Memory overflow causing erroneous behaviour or denial of serviceOracle-type load-balancing virtual server8.8
CVE-2026-88777Memory overflow causing erroneous behaviour or denial of serviceCertain non-HTTP Layer 7 features on LB, CS, CGNAT-LSN or NAT64 configurations8.8
CVE-2026-88778Predictable TCP initial sequence numbersTCP configuration enabled and enhanced ISN generation disabled8.8

The table should not become a reason to patch only the two known-exploited flaws. The fixed builds address all eight. The preconditions are useful for exposure assessment and investigation, but upgrading remains the primary control.

What defenders should do now

  • Identify every customer-managed appliance. Include high-availability peers, disaster-recovery systems, FIPS and NDcPP appliances, test systems with external reachability and NetScaler instances used by Secure Private Access Hybrid.
  • Upgrade to the fixed build immediately. Do not wait for a normal monthly maintenance window when CVE-2026-88771 affects the default configuration and exploitation is already confirmed.
  • Check DTLS exposure. Treat VPN virtual servers as meeting the CVE-2026-88772 precondition unless DTLS was explicitly disabled. Other DTLS virtual servers also require review. Disabling DTLS or blocking upstream UDP/443 reduces only CVE-2026-88772 exposure. It does not protect against CVE-2026-88771.
  • Enable enhanced ISN generation where required. Citrix says deployments affected by CVE-2026-88778 must apply the documented TCP configuration change as well as moving to a fixed build.
  • Preserve evidence before it disappears. Record current build numbers, running configuration, exposed services, administrative changes, authentication anomalies and available system and network logs. Take a forensic snapshot where operationally safe.
  • Investigate, do not merely verify the reboot. Follow Google’s hunting guide. Prioritise unexpected NSPPE termination after DTLS failures, unauthorised PHP handlers, .deb or .sig PHP files, /tmp/.uxdport, /tmp/.uxdlock, suspicious Python and setuid /bin/sh.
  • Escalate suspected compromise. Citrix’s compromise-response guidance recommends removing a suspected appliance from the network, rebuilding from a trusted image and changing accounts that may have authenticated through it. On suspected compromise, isolate the node, pause HA synchronisation, assess both peers, terminate sessions and rotate appliance and integration secrets after patching.

Do not confuse this release with the August NetScaler warning

BlackTree previously covered active targeting of a separate NetScaler authentication-bypass vulnerability. The new bulletin is not a revision of that incident. It introduces eight different identifiers, different fixed builds and a broader default-configuration risk through CVE-2026-88771.

That distinction matters operationally. A team that patched the August release can still be vulnerable today. The correct question is not whether NetScaler was updated recently, but whether every customer-managed instance is now running one of the builds named in CTX697096.

What remains unknown

Attribution and precise scope remain unresolved despite the new evidence.

GreyNoise separately recorded an unsuccessful 24 September sensor attempt against CVE-2026-88771, which must not be merged with Mandiant’s successful-intrusion evidence for CVE-2026-88772.

Those gaps limit attribution and campaign analysis. They do not weaken the patching decision. When a vendor confirms exploitation of an unauthenticated command-execution flaw affecting default deployments, exposed appliances should be treated as urgent remediation and review targets.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *