Unauthenticated RCE/DoS in Citrix NetScaler ADC and Gateway
CISA: Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
CVSS 4.0
9.5critical
EPSS
1%p69
Published
()
KEV added
AI analysis
CVE-2026-88772 is a critical flaw in Citrix NetScaler ADC and NetScaler Gateway that can lead to remote code execution or denial of service. It is reachable over the network with no privileges and no user interaction, though attack complexity is rated high; successful exploitation can fully compromise the appliance and affect systems behind it. Affected builds are ADC before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP, and Gateway before 14.1-73.37 and before 13.1-64.23. Organizations running those releases as internet-facing ADC or VPN gateways are at risk. Citrix-linked reporting describes active zero-day exploitation; no public proof-of-concept is known and the issue is not listed in CISA KEV.
What to do: Upgrade NetScaler ADC and Gateway to 14.1-73.37 or 13.1-64.23 (or later), and FIPS/NDcPP ADC builds to 14.1-73.37 FIPS or 13.1.37.279 FIPS and NDcPP (or later). Treat unpatched internet-facing appliances as potentially compromised: review admin and VPN logs, config changes, and unusual processes, and restrict management interfaces until patched.
Affected
Citrix NetScaler ADC
before 14.1-73.37; before 13.1-64.23; before 14.1-73.37 FIPS; before 13.1.37.279 FIPS and NDcPP
Citrix NetScaler Gateway
before 14.1-73.37; before 13.1-64.23
Estimated exposure
largetens of thousands of internet-exposed appliances (vulnerable subset unknown) — NetScaler ADC and Gateway are widely deployed enterprise load-balancer and VPN appliances; historical public internet scans have typically shown on the order of tens of thousands of exposed instances, though the share still on these…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service
CISA Known Exploited Vulnerability
Affected
Citrix NetScaler
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Suspected state-sponsored actors mass-exploited Citrix NetScaler zero-day CVE-2026-88772 undetected for over three weeks, hitting dozens of organizations.
Mandiant reports earliest known exploitation of Citrix NetScaler zero-day CVE-2026-88772 occurred Sept. 3, with dozens of organizations in North America and Europe across government, financial services, education, telecom, legal and professional services compromised before attacks were confirmed late last week. A second zero-day, CVE-2026-88771, has been exploited since at least Sept. 24 per GreyNoise. Citrix patched both flaws plus six additional vulnerabilities Sunday; Mandiant expects broad, opportunistic exploitation of both zero-days by varied threat actors.
Unknown attackers exploited critical Citrix NetScaler zero-days CVE-2026-88771/88772 since early September, deploying custom WHIPSHOT and SLAPSHOT malware for persistence and tunneling.
Citrix disclosed eight CVEs including critical CVE-2026-88771 and CVE-2026-88772 (CVSS 9.5) in NetScaler ADC and NetScaler Gateway, both exploited as zero-days before public disclosure. Google Threat Intelligence and Mandiant say the campaign, ongoing since at least early September, hit government, financial services, education, and legal/professional services organizations across North America and Europe. Post-exploitation tooling includes WHIPSHOT, a PHP web shell disguised as a Debian package hiding base64-encoded C2 in HTTP headers, and SLAPSHOT, a Python TCP tunneling tool that proxies traffic into internal networks. No attribution has been made; Mandiant urges customers to hunt for compromise before patching.
Attackers are exploiting critical Citrix NetScaler zero-days CVE-2026-88771 and CVE-2026-88772 for unauthenticated remote code execution.
On September 27, 2026, Citrix disclosed eight NetScaler ADC and Gateway flaws, including two critical unauthenticated RCEs scored CVSS 9.5. CVE-2026-88771 yields remote code execution in the default configuration with low attack complexity, while CVE-2026-88772 is a DTLS memory-corruption RCE with high complexity. CISA confirmed both were exploited as zero-days before disclosure and added them to the KEV catalog; CVE-2026-88773 through CVE-2026-88778 are not confirmed exploited. Patches are in 14.1-73.37, 13.1-64.23, and corresponding FIPS and NDcPP builds.
Citrix patched two actively exploited NetScaler zero-days (CVE-2026-88771/88772, CVSS 9.5); CISA added both to KEV amid global attacks.
Citrix rushed out weekend patches for eight NetScaler ADC and NetScaler Gateway vulnerabilities, including two zero-days confirmed exploited in the wild: CVE-2026-88771, an unauthenticated remote code execution flaw affecting all ADC/Gateway deployments including default configuration, and CVE-2026-88772, a memory overflow enabling RCE or DoS on DTLS-enabled appliances (default on VPN virtual servers), both CVSS 9.5. CISA added both CVEs to its KEV catalog and issued an alert warning that threat actors are actively exploiting them globally. A private TLP:AMBER NCSC-NL notification, sourced from a European partner CERT, reported exploitation at multiple Citrix customers worldwide, prompting some administrators to take appliances offline. Citrix has published indicators of compromise.
CISA says attackers are globally exploiting critical Citrix NetScaler flaws CVE-2026-88771 and CVE-2026-88772.
CISA added CVE-2026-88771 and CVE-2026-88772, both CVSS 9.5, to the Known Exploited Vulnerabilities catalog after confirming global exploitation against Citrix NetScaler ADC and Gateway. CVE-2026-88771 is improper input validation that allows unauthenticated command execution on all deployments; CVE-2026-88772 is a memory-buffer flaw enabling remote code execution or denial of service when DTLS is enabled, the default on VPN virtual servers. Fixes are in 14.1-73.37 and 13.1-64.23 and later, plus listed FIPS and NDcPP builds. Federal Civilian Executive Branch agencies must apply fixes by September 30, 2026.
Citrix confirms two critical NetScaler zero-days, CVE-2026-88771 and CVE-2026-88772, are actively exploited for remote code execution.
Citrix released emergency updates in bulletin CTX697096 after confirming active exploitation of CVE-2026-88771 and CVE-2026-88772, both CVSS 9.5, on customer-managed NetScaler ADC and Gateway appliances. CVE-2026-88771 allows unauthenticated remote command execution on default configurations, while CVE-2026-88772 is a memory overflow that can cause remote code execution or denial of service when DTLS is enabled, which is default on VPN virtual servers. The bulletin also fixes six more flaws, including HTTP request smuggling CVE-2026-88773, in releases 14.1-73.37, 13.1-64.23, and specified FIPS builds.
Attackers exploited Citrix NetScaler zero-days CVE-2026-88771 and CVE-2026-88772 to plant web shells and tunnel into networks.
Attackers exploited two Citrix NetScaler zero-days, CVE-2026-88771 and CVE-2026-88772, sometimes called PitScaler, to gain root on ADC and Gateway appliances and move into internal networks. CVE-2026-88771 is unauthenticated remote code execution on all deployments, while CVE-2026-88772 is a DTLS memory-overflow flaw that can yield code execution or denial of service. Mandiant says activity began by early September against organizations in North America and Europe across government, financial services, education, legal, and professional services. Intruders installed PHP web shells, including new families WHIPSHOT and SLAPSHOT, rewrote httpd.conf so benign-looking files executed PHP, and set the setuid bit on /bin/sh.
Citrix NetScaler zero-day CVE-2026-88771 is under mass exploitation after a public proof of concept.
Exploitation of internet-exposed Citrix NetScaler ADC and Gateway appliances has escalated from stealthy zero-day use to widespread scanning after watchTowr Labs published a proof of concept for CVE-2026-88771. Citrix patched eight flaws, including zero-days CVE-2026-88771 and CVE-2026-88772; GreyNoise observed an attempt on September 24, before public disclosure. Attackers seek admin access, hide unique webshells, poison logs, and exfiltrate data, including to a Hetzner server. Censys sees about 42,000 exposed hosts, fewer than 10% appear patched, and more than 100 victim organizations are being tracked.
Agencies warn exploited Citrix NetScaler zero-days CVE-2026-88771 and CVE-2026-88772 require immediate patching and forensic triage.
US, UK, and Dutch agencies warned that Citrix NetScaler ADC and Gateway zero-days are under active exploitation. Citrix confirmed eight new vulnerabilities; CVE-2026-88771 and CVE-2026-88772, both scored 9.5, have been exploited, and patches are available. CISA ordered US federal agencies to patch the two exploited bugs by Wednesday and to perform forensic triage, citing intelligence of global exploitation. watchTowr said CVE-2026-88771 was exploited before a fix existed and released a susceptibility-check tool.
Citrix patched NetScaler zero-days CVE-2026-88771 and CVE-2026-88772 after weeks of global exploitation planting webshells.
Citrix patched eight NetScaler ADC and Gateway flaws, including actively exploited zero-days CVE-2026-88771 and CVE-2026-88772 used for weeks to plant webshells. CVE-2026-88771 is unauthenticated remote command execution on default configurations; CVE-2026-88772 is a memory overflow leading to RCE or denial of service when DTLS is enabled. CISA added both to the KEV catalog and ordered US federal civilian agencies to remediate and triage by September 30, 2026. Citrix says customer-managed 14.1 and 13.1 builds, FIPS variants, and Secure Private Access Hybrid deployments are affected.
Actively exploited Citrix NetScaler zero-days CVE-2026-88772/88771 give attackers root access; Mandiant uncovers WHIPSHOT web shells and SLAPSHOT tunneler in ongoing campaign.
In late September 2026, Mandiant and Google Threat Intelligence identified active in-the-wild exploitation of zero-day CVE-2026-88772 in Citrix NetScaler ADC and NetScaler Gateway, ongoing since at least early September. The flaw bypasses authentication and triggers unhandled termination of the NetScaler Packet Processing Engine to achieve root-level shellcode execution on the underlying FreeBSD platform. Impacted organizations span North America and Europe across government, financial services, education, legal, and professional services sectors. The actor deploys the custom WHIPSHOT PHP web shell, which disguises Base64-encoded C2 payloads in HTTP headers, and the SLAPSHOT Python tunneler for internal reconnaissance and credential theft; a second zero-day, CVE-2026-88771, is also actively exploited per vendor disclosure.
Citrix reports NetScaler ADC and Gateway zero-days CVE-2026-88771/88772 (CVSS 9.5) exploited in the wild, with over 50,000 exposed instances.
Unit 42 warns that CVE-2026-88771, an unauthenticated remote code execution flaw from improper input validation, and CVE-2026-88772, a memory overflow enabling RCE or DoS in the DTLS configuration, are being exploited in the wild against NetScaler ADC and NetScaler Gateway. Both carry CVSS v4.0 base scores of 9.5. Palo Alto Networks Cortex Xpanse identified over 50,277 potentially vulnerable exposed instances as of September 27, 2026. Unit 42 urges immediate patching, exposure confirmation, isolation, and evidence preservation, noting patching will not evict attackers with established persistence.
Citrix and CISA warn NetScaler ADC and Gateway zero-days CVE-2026-88771 and CVE-2026-88772 are under active attack.
Citrix confirmed two critical unauthenticated RCE zero-days in NetScaler ADC and Gateway, CVE-2026-88771 and CVE-2026-88772, both CVSS 9.5, were exploited before fixes shipped. CVE-2026-88771 affects every deployment, including default configurations; CVE-2026-88772 requires DTLS, which is enabled by default on VPN virtual servers. CISA added both to the KEV catalog, and fixes are in 14.1-73.37, 13.1-64.23, and matching FIPS and NDcPP builds. Six further flaws, CVE-2026-88773 through CVE-2026-88778, were patched the same day but are configuration-dependent and not reported as exploited.
On 27 September Citrix released fixes for eight vulnerabilities in customer-managed NetScaler ADC and NetScaler Gateway, with CVSS scores from 7.0 to 9.5. CVE-2026-88771 is an unauthenticated remote code execution flaw from improper input validation on default configurations, and CVE-2026-88772 is a memory overflow that can cause RCE or denial of service when DTLS is enabled. Citrix said exploitation of both has been observed. CVE-2026-88773 is an HTTP request-smuggling flaw scored 9.3. Australia’s ACSC issued a critical alert, and CISA ordered US federal agencies to patch by 30 September. The actor behind the current exploitation is unknown.
CISA ordered federal agencies to patch two exploited critical Citrix NetScaler RCE flaws by September 30.
CISA added CVE-2026-88771 and CVE-2026-88772 to the Known Exploited Vulnerabilities catalog and ordered federal civilian agencies to secure Citrix NetScaler systems by September 30 under BOD 26-04. Citrix confirmed zero-day exploitation; both flaws allow unauthenticated remote code execution, the first on default ADC and Gateway configurations and the second when DTLS is enabled, which is default on VPN virtual servers. Shadowserver tracks more than 23,000 exposed NetScaler addresses, nearly 22,000 ADC and about 1,500 Gateway. Citrix warned its indicators of compromise may miss intrusions and advised preserving forensic evidence before patching.
Citrix confirms attackers are exploiting two critical unauthenticated NetScaler RCE zero-days, CVE-2026-88771 and CVE-2026-88772.
Citrix released emergency updates after confirming attackers are exploiting two critical unauthenticated remote code execution flaws in NetScaler ADC and NetScaler Gateway. CVE-2026-88771 (CVSS 9.5) is improper input validation enabling arbitrary command execution on all deployments, including defaults. CVE-2026-88772 (CVSS 9.5) is a memory overflow that can cause RCE or denial of service when DTLS is enabled, which is default on VPN virtual servers. Six more issues, including HTTP request smuggling CVE-2026-88773 (9.3), are patched in 14.1-73.37 and 13.1-64.23; updating does not remove artifacts from prior compromise.
Citrix patched actively exploited NetScaler zero-days CVE-2026-88771 and CVE-2026-88772 after a weekend of silence, and CISA added both to KEV.
Citrix on Sunday confirmed attackers were exploiting two critical NetScaler ADC and Gateway zero-days, CVE-2026-88771 and CVE-2026-88772, both CVSS 9.5 and allowing remote code execution, and patched those plus six other defects. CVE-2026-88771 is a command-injection flaw affecting appliances in the default configuration, and a public proof of concept is available. Palo Alto Networks reported more than 50,000 exposed instances potentially vulnerable; GreyNoise observed an exploitation attempt on Sept. 24. CISA added both CVEs to its known exploited vulnerabilities catalog after nearly two days of unofficial warnings.
Canada's Cyber Centre warns critical Citrix NetScaler flaws CVE-2026-88771 and CVE-2026-88772 are being exploited worldwide.
The Canadian Centre for Cyber Security issued alert AL26-024 on September 27, 2026, covering critical flaws in Citrix NetScaler ADC and NetScaler Gateway. CVE-2026-88771 (CWE-20) lets a remote unauthenticated attacker execute arbitrary code, potentially compromising the appliance, stealing credentials, and enabling lateral movement. CVE-2026-88772 (CWE-119) is a buffer overflow that may cause code execution, memory corruption, or denial of service. Reports say both are being exploited in multiple customer environments worldwide, though the full scope is unknown.
Two critical Citrix NetScaler zero-days, CVE-2026-88771 and CVE-2026-88772, are exploited for remote code execution.
CISA amplified Citrix’s disclosure of eight vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway, CVE-2026-88771 through CVE-2026-88778. CVE-2026-88771 and CVE-2026-88772 were added to the Known Exploited Vulnerabilities Catalog; both are critical zero-days that can independently enable remote code execution. CISA and partner intelligence confirm threat actors are actively exploiting these vulnerabilities globally. CISA urges administrators to review Citrix’s bulletin, check for compromise before patching, and preserve forensic evidence because updates may remove visibility. Citrix published indicators of compromise through NetScaler Console.
watchTowr details CVE-2026-88771, a pre-auth command injection in Citrix NetScaler ADC/Gateway patched in bulletin CTX697096 and already exploited as a zero-day.
watchTowr reverse-engineers CVE-2026-88771, a pre-auth command injection (CVSS 9.5) affecting the default configuration of Citrix NetScaler ADC and Gateway, which was exploited in the wild as a zero-day before any fix existed. The flaw is one of eight fixed in bulletin CTX697096, including memory-overflow RCE CVE-2026-88772 (also exploited) and HTTP request smuggling CVE-2026-88773. Diffing firmware 14.1-73.30 versus 14.1-73.37 revealed the root cause in Perl scripts (ns_monuploadd_err.pl) rather than the usual NSPPE binary. Fixed versions include NetScaler ADC/Gateway 14.1-73.37 and 13.1-64.23 plus FIPS builds.