Suspected State Hackers Exploited Citrix NetScaler for Weeks. 50,000 Devices May Still Be Exposed.
Two critical NetScaler zero-days, CVE-2026-88771 and CVE-2026-88772, were used against organizations worldwide before a patch existed. CISA’s deadline is today. Patching alone will not tell you whether you were already breached.
What: Two unauthenticated remote-code-execution flaws in Citrix NetScaler ADC and NetScaler Gateway, both CVSS 9.5.
Status: Exploited as zero-days. Listed in CISA’s Known Exploited Vulnerabilities catalog.
Deadline: Federal civilian agencies must remediate and perform forensic triage by today, September 30, 2026.
Fix: Upgrade to 14.1-73.37 or 13.1-64.23 (FIPS/NDcPP: 13.1-37.279). Then hunt for compromise.
Executive Summary
The front door to your network was open, and someone walked through it before anyone knew it was unlocked.
On September 27, Citrix published security bulletin CTX697096, patching eight vulnerabilities in NetScaler ADC and NetScaler Gateway. Two of them had already been exploited as zero-days. CVE-2026-88771 lets an unauthenticated attacker run arbitrary commands on any affected appliance, including one running the default configuration. CVE-2026-88772, a memory overflow, can lead to code execution or a crash on appliances with DTLS enabled, which is the default on VPN virtual servers.
The timeline is what should worry boards. GreyNoise saw exploitation attempts the Thursday before disclosure. Mandiant CTO Charles Carmakal said Google’s threat intelligence group and Mandiant traced exploitation of CVE-2026-88772 back to early September, by suspected state-linked actors. The Netherlands’ national cyber center reported exploitation at multiple Citrix customers worldwide.
And the exposure is large. Palo Alto Networks’ Unit 42 counted more than 50,000 internet-exposed NetScaler instances that could potentially be vulnerable.
The bottom line: if you run customer-managed NetScaler appliances and patched after the exploitation window opened, treat this as a potential incident, not a maintenance ticket.
Why This Matters to CISOs and Security Leaders
NetScaler is the gateway to everything behind it. Organizations use these appliances to give staff remote access to internal networks. An attacker with root on the gateway sits in front of your VPN sessions, your authentication flow and your internal applications.
It sits outside your EDR. Most endpoint tools do not run on network appliances, so the device that sees the most sensitive traffic is often the one you have the least visibility into.
It has happened before, and the aftermath lasted months. Every major NetScaler flaw since 2023 has been exploited quickly after disclosure. Organizations that patched without hunting in previous waves later found attackers who had already moved on from the appliance into the wider network.
CISA did not just ask agencies to patch. It ordered them to perform forensic triage for evidence of compromise. When the federal government’s own directive assumes you may already be breached, your incident response plan should assume the same.
So how exactly did this unfold, and how far ahead were the attackers?
The Timeline: How the Zero-Days Unfolded
| Date (2026) | What happened |
|---|---|
| Early September | Suspected state-linked actors begin exploiting CVE-2026-88772, according to Mandiant and Google’s threat intelligence group |
| Thursday, Sept 24 | GreyNoise observes a malicious actor attempting to exploit a NetScaler zero-day |
| Saturday, Sept 26 | NetScaler customers start receiving warnings to disconnect appliances over suspected exploitation |
| Sunday, Sept 27 | Citrix publishes bulletin CTX697096 and patches; CISA issues an alert and adds both CVEs to the KEV catalog |
| Sept 27–28 | Unit 42 counts more than 50,000 potentially vulnerable exposed instances |
| Wednesday, Sept 30 | CISA remediation and forensic-triage deadline for federal civilian agencies |
By the time the patch shipped, the attackers had been working for roughly three weeks.
Vulnerability & Exploit Analysis
CVE-2026-88771: unauthenticated command execution
An improper input validation flaw (CWE-20) that lets a remote attacker execute arbitrary commands without logging in. Citrix says it affects all NetScaler ADC and NetScaler Gateway deployments on affected versions, including the default configuration, with no additional feature required. CVSS v4.0: 9.5.
CVE-2026-88772: memory overflow via DTLS
A memory-bounds flaw (CWE-119) that can lead to remote code execution or denial of service. It requires DTLS to be enabled, which Citrix notes is the default on VPN virtual servers. So most NetScaler Gateway deployments are affected unless DTLS was explicitly turned off. CVSS v4.0: 9.5.
Turning off DTLS is not a fix. It may close the path to CVE-2026-88772, but CVE-2026-88771 is independently exploitable on the same appliance with no special configuration. Only the upgrade closes both.
Affected and fixed versions
| Product | Vulnerable | Upgrade to |
|---|---|---|
| NetScaler ADC & Gateway 14.1 | Before 14.1-73.37 | 14.1-73.37 or later |
| NetScaler ADC & Gateway 13.1 | Before 13.1-64.23 | 13.1-64.23 or later |
| NetScaler ADC 14.1 FIPS | Before 14.1-73.37 FIPS | 14.1-73.37 FIPS or later |
| NetScaler ADC 13.1 FIPS and NDcPP | Before 13.1-37.279 | 13.1-37.279 or later |
| Citrix-managed cloud instances | Patched by Citrix | No customer action |
The bulletin also fixes six additional flaws (CVE-2026-88773 through CVE-2026-88778). Citrix has not reported exploitation of those, but the same upgrade covers them. Appliances on end-of-life branches should be moved to a supported release.
Threat Intelligence Breakdown
Attribution: Citrix has not said who is behind the attacks. Mandiant’s early assessment points to suspected state-linked actors for the earliest CVE-2026-88772 activity. Once patches are public, expect opportunistic and ransomware-aligned groups to follow, as they have in past NetScaler waves.
Post-exploitation: Reporting indicates attackers planted web shells on compromised appliances. One threat research write-up also described custom web shells and tunneling malware deployed against organizations in North America and Europe; treat those specific tool names as preliminary until confirmed by Citrix or major incident response firms.
Public exploit status: As of September 28, SOCRadar reported no credible, independently verified weaponized public exploit. That window rarely lasts long once patches can be reverse-engineered.
Indicators: Citrix has published indicators of compromise alongside its bulletin. Pull them into your SIEM and hunting queries today.
Enterprise Impact: What’s Actually at Risk
Identity: A compromised gateway can expose session tokens and credentials passing through it, giving attackers valid access that survives the patch.
Ransomware: Remote-access appliances are a leading initial-access route for ransomware crews. August 2026 was already the year’s biggest ransomware month.
Regulatory exposure: If forensic review finds compromise, disclosure clocks may start. Document every step now, including when you patched and what you checked.
Cyber insurance: Insurers increasingly ask about patching of known exploited vulnerabilities. A KEV-listed edge flaw left open past its deadline is the kind of fact that complicates a claim.
Supply chain: Ask critical vendors and managed service providers whether they run NetScaler, whether they have patched, and whether they have hunted.
What Security Leaders Should Do Next
Right now
- Inventory every NetScaler ADC and Gateway, including forgotten lab, DR and regional appliances. Unit 42’s exposure count suggests many organizations have more than they think.
- Preserve evidence before you upgrade. Unit 42 recommends capturing a VPX instance snapshot and preserving logs on remote syslog servers and NetScaler Console.
- Upgrade to 14.1-73.37 or 13.1-64.23 (FIPS/NDcPP: 13.1-37.279).
Within 48 hours
- Hunt using Citrix’s published indicators: look for web shells, unexpected files, unusual processes and unexplained outbound connections from the appliance.
- Review logs back to at least early September, matching the earliest reported exploitation.
- If anything looks wrong, treat it as an incident: rebuild the appliance from a clean image, rotate credentials and certificates handled by it, and terminate active sessions.
This quarter
- Put edge appliances under the same ownership and SLAs as servers, with a named owner for every device.
- Pre-approve an emergency patch path for KEV-listed edge flaws so no change board delays a zero-day response.
- Evaluate phishing-resistant, identity-centric remote access to shrink how much trust any single gateway holds.
Get zero-day alerts before they hit the headlines
DataWater’s executive threat briefing: the exploited CVEs, the deadlines and the first three actions to take.
Winners and Losers
| Better positioned | More exposed |
|---|---|
| Citrix-managed cloud customers, already patched | Customer-managed on-prem appliances patched late |
| Teams that preserved evidence and hunted back to early September | Teams that upgraded and closed the ticket |
| Organizations with a full appliance inventory | Organizations with orphaned DR, lab or regional gateways |
| Remote-log shipping from every appliance | Appliances whose only logs live on the box |
Final Executive Takeaway
This is not a patch story. It is a breach-assessment story.
Attackers had roughly three weeks on an appliance that sits in front of your entire remote workforce. The upgrade stops the next attacker. Only a hunt tells you about the last one.
Patch today. Hunt back to early September. Brief your board on what you found.
Frequently Asked Questions
What are CVE-2026-88771 and CVE-2026-88772?
Two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway, both rated CVSS 9.5. CVE-2026-88771 allows unauthenticated command execution on any affected deployment. CVE-2026-88772 is a memory overflow that can lead to remote code execution or denial of service when DTLS is enabled. Both were exploited as zero-days.
Which NetScaler versions fix the vulnerabilities?
NetScaler ADC and Gateway 14.1-73.37 and 13.1-64.23 or later, NetScaler ADC 14.1-73.37 FIPS, and 13.1-37.279 or later for FIPS and NDcPP builds. Citrix-managed cloud instances are already patched.
Is disabling DTLS enough to protect NetScaler?
No. Disabling DTLS may block CVE-2026-88772, but CVE-2026-88771 is exploitable on default configurations without DTLS. Upgrading is the only complete fix.
What is the CISA deadline for the Citrix NetScaler zero-days?
CISA added both flaws to its Known Exploited Vulnerabilities catalog on September 27, 2026, and ordered federal civilian agencies to remediate and perform forensic triage by September 30, 2026.
How do I know if my NetScaler was compromised?
Preserve a snapshot and remote logs, then hunt using Citrix’s published indicators of compromise. Look for web shells, unexpected files or processes, and unusual outbound connections, reviewing activity back to early September 2026.
How many NetScaler devices are exposed?
Palo Alto Networks Unit 42 reported more than 50,000 internet-exposed NetScaler instances that could potentially be vulnerable as of September 27, 2026.
Sources
Citrix security bulletin CTX697096; CISA Known Exploited Vulnerabilities catalog; Palo Alto Networks Unit 42 threat brief; Cybersecurity Dive (GreyNoise and Mandiant reporting); SecurityWeek (NCSC-NL); BleepingComputer; Help Net Security; The Hacker News; SOCRadar; The Next Web; Aviatrix threat research. Reflects public reporting as of September 30, 2026. Check the Citrix bulletin for the latest fixed versions and indicators.

