[ZERO-DAY] Your VPN Login Page Was Exploited for Weeks Before Anyone Got a Patch: Citrix NetScaler CVE-2026-88772
$ ./edge_exposure_audit.sh --product=netscaler --window=2026-09-24..10-01
> Pulling Citrix bulletin CTX697096 [published 09-27]...
> Pulling CISA KEV + NVD record for CVE-2026-88772...
> Pulling Mandiant/GTIG, Unit 42, GreyNoise reporting...
[KEV_LISTED] [FORENSIC_TRIAGE_REQUIRED]
TARGET:
> Citrix NetScaler Gateway -- remote access / VPN that
lets external users reach internal apps and networks
> Citrix NetScaler ADC -- application delivery platform
> Scope: CUSTOMER-MANAGED appliances. Citrix-managed
cloud services are updated by Cloud Software Group
THE TWO EXPLOITED FLAWS (of 8 in the bulletin):
> CVE-2026-88772 CVSS 4.0: 9.5 CWE-119
Memory overflow -> remote code execution or DoS
Precondition: DTLS enabled -- ON BY DEFAULT on
VPN virtual servers
> CVE-2026-88771 CVSS 4.0: 9.5 CWE-20
Unauthenticated command execution
Precondition: none -- default configuration hit
> Citrix: "Exploits of CVE-2026-88771 and
CVE-2026-88772 on unmitigated NetScaler
deployments have been observed."
FIXED BUILDS:
> 14.1-73.37 and later
> 13.1-64.23 and later
> 14.1-73.37 FIPS and later
> 13.1-37.279 FIPS / NDcPP and later
CONFIRMED TIMELINE:
$ timeline --source=vendor_cisa_researchers
> 08-21 Unit 42: first fingerprinting requests
against a US NetScaler Gateway
> early Sep Mandiant/GTIG: CVE-2026-88772
exploitation ongoing since at least here
> 09-04..24 Unit 42: repeated web shell file requests
on a targeted appliance
> 09-24 GreyNoise: exploitation attempt seen,
3 days before disclosure
> 09-26 Customers start getting warnings to
disconnect appliances (Cybersecurity Dive)
> 09-27 Citrix bulletin + fixes published
> 09-27 CISA adds 88771 + 88772 to KEV
> 09-28 Shadowserver: aware of successful
exploitation attempts; 20,000+ instances
visible and potentially vulnerable
> 09-30 CISA federal deadline (with forensic
triage, per BOD 26-04)
ATTACKER CLAIMS / RESEARCHER ASSESSMENTS:
> Mandiant CTO: "Advanced and suspected
state-sponsored threat actors" behind initial
CVE-2026-88772 intrusions; dozens of orgs in
North America + Europe
> Post-exploit (Mandiant/GTIG, Unit 42, GreyNoise):
web shells disguised as CSS/image requests,
setuid root on /bin/sh, tunneling into internal
networks, credential theft
> Mandiant: broad, opportunistic exploitation
of both flaws expected
STILL NOT KNOWN:
$ unknowns --list
> Which actor(s) -- no public attribution
> Whether healthcare was hit -- not in Mandiant's
published sector list. That is not a clean bill
PATTERN (4th + 5th NetScaler KEV entries of 2026):
> 03-30 CVE-2026-3055 out-of-bounds read
> 08-26 CVE-2026-8452 memory buffer flaw (DoS)
> 09-09 CVE-2026-19490 authentication bypass
> 09-27 CVE-2026-88771 + CVE-2026-88772
> Lineage: CVE-2023-4966 "Citrix Bleed" and
CVE-2025-5777 -- both KEV, both flagged
known ransomware use
WHY THIS MATTERS AT 12 EMPLOYEES:
$ assess --pattern=edge_device_compromise
> The gateway sits on the internet edge, often
without EDR (BleepingComputer)
> Patching does not evict an attacker already in
> Everyone who logged in through it is exposed
[VERDICT: EXPLOITED // PATCH + HUNT + ROTATE_CREDENTIALS]
Here is what is confirmed. On Sunday, September 27, Cloud Software Group published Citrix security bulletin CTX697096, covering eight vulnerabilities in NetScaler ADC and NetScaler Gateway. Two were already under attack. CVE-2026-88772 is a memory overflow (CWE-119) that can lead to remote code execution or denial of service. It needs DTLS to be enabled, and Citrix notes that DTLS is enabled by default on VPN virtual servers: a Gateway is vulnerable unless DTLS has been explicitly turned off. CVE-2026-88771 is worse on paper. It is an input-validation flaw that lets an unauthenticated attacker run commands, and it affects every deployment, including the default configuration. Citrix scores both 9.5 under CVSS 4.0 and states that "exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed." The fixed builds are 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS and 13.1-37.279 for FIPS and NDcPP, or later. The bulletin covers customer-managed appliances only. Citrix-managed cloud services are updated by Cloud Software Group, and Secure Private Access hybrid deployments that use NetScaler instances are affected too. CISA added both CVEs to its Known Exploited Vulnerabilities catalog the same day. Federal civilian agencies had until September 30 to act, and both entries are flagged as requiring forensic triage under BOD 26-04, not just a patch.
The patch came well after the attacks started. Mandiant and Google Threat Intelligence Group say exploitation of CVE-2026-88772 has been going on since at least early September. Mandiant CTO Charles Carmakal attributes the first targeted intrusions to "advanced and suspected state-sponsored threat actors" and says dozens of organizations in North America and Europe were hit, in government, financial services, education, telecommunications, and legal and professional services. Palo Alto Networks' Unit 42 traced version-fingerprinting requests against a US-based NetScaler Gateway back to August 21, and, from September 4 to September 24, repeated requests for web shell files hosted on a targeted appliance. GreyNoise caught an exploitation attempt on September 24, three days before disclosure. In the days before the bulletin, administrators reported on Reddit that their IT suppliers, CERTs and MDR providers were telling them to shut their appliances down, often without saying why. Some of those warnings traced back to a private pre-notification from the Dutch National Cyber Security Centre. On September 28, the Shadowserver Foundation said it was aware of successful exploitation attempts and could see more than 20,000 instances that were potentially vulnerable. Unit 42 counted 50,277 exposed instances that could potentially be vulnerable as of September 27. The two counts use different methods.
Researchers describe what the attackers did once they were in, and defenders need that part. Mandiant says exploiting CVE-2026-88772 bypasses authentication and gives initial root-level access. The attackers then planted web shells disguised as ordinary CSS or image requests, used setuid on /bin/sh to keep root, and ran a Python tunneling tool Mandiant calls SLAPSHOT to proxy into internal networks. In at least one intrusion they used it to steal credentials. Researcher Kevin Beaumont says the web shells were unique to each appliance and the attackers ran anti-forensics commands. He also warns that Citrix's detection script only works if the appliance's logs have not rotated since the attack, and the activity began weeks ago. Citrix itself says its indicators "might fail to identify actual compromises." Two things follow. Patching closes the hole but does not remove anyone already inside: Carmakal says upgrading is not enough to evict the attackers and does nothing about stolen credentials. And the stopgap Mandiant suggests for teams that cannot patch yet (disable DTLS, block inbound UDP/443) covers only CVE-2026-88772, not CVE-2026-88771. Mandiant expects broad, opportunistic exploitation of both. Help Net Security reports that "spray and pray" exploitation of CVE-2026-88771 has already started now that a proof of concept is public.
None of this is new for NetScaler. These are the fourth and fifth NetScaler CVEs CISA has added to KEV in 2026, after CVE-2026-3055 in March, CVE-2026-8452 in August and an authentication bypass, CVE-2026-19490, on September 9. Before that came CVE-2023-4966, which CISA calls Citrix Bleed, and CVE-2025-5777. CISA's catalog flags both as known to be used in ransomware campaigns. Tenable's Satnam Narang says about two-thirds of the threat activity against NetScaler over the last seven years involved APT groups and one-third involved ransomware groups and their affiliates. For a small organization, the gateway is the remote-access front door. It is how staff reach the file server, the line-of-business app or, at a clinic, the EHR from home. As BleepingComputer notes, these appliances face the internet, sit at the edge of the internal network and often lack the EDR coverage other systems get. If someone has root on the gateway, every password typed into its login page is at risk. Healthcare does not appear in Mandiant's published sector list. That is not a clean bill of health, because CVE-2026-88771 needs no special configuration and opportunistic scanning is now underway. If your remote-access login page says Citrix or NetScaler and your MSP runs it, the advisory went to them, not to you.
What to do this week, on your side or in writing to your MSP:
- Find out whether you run it. Ask your MSP, or check yourself: is our remote access, VPN or published-app portal a Citrix NetScaler Gateway or ADC that we or you manage? If it is Citrix-managed cloud, Cloud Software Group handles the update. If it is an appliance or VPX, the rest of this list applies.
- Get the build number and the date. "Patched" is not an answer. You need 14.1-73.37, 13.1-64.23, or the FIPS/NDcPP equivalents in Citrix's bulletin, and the date and time it was installed. The bulletin lists only the 14.1 and 13.1 branches. If your appliance is on anything older, ask your MSP directly what the upgrade plan is.
- Hunt before or alongside the patch. CISA encourages checking for compromise before patching where possible, and Carmakal says the same. The Dutch NCSC advised backing up the appliance's memory and logs, going back at least a month, before installing the update. Ask your MSP to run Citrix's IOC scanner and to check the indicators Mandiant, Unit 42 and GreyNoise published: unexpected PHP handlers or aliases in httpd.conf, setuid on /bin/sh, unexplained packet-engine (NSPPE) crashes. Because local logs may have rotated, ask whether they also searched centrally forwarded syslog/SIEM data. Ask for the results in writing.
- If it was compromised, follow Citrix's rebuild steps rather than just patching. Citrix's compromise guidance says to preserve evidence, isolate the appliance, change service-account passwords and secrets stored on it (LDAP, RADIUS, API keys), change passwords for every user who authenticated through it, revoke its certificates, rebuild or replace it, and monitor for at least 90 days. Investigate the internal systems it connected to, starting with authentication servers.
- Rotate the passwords that went through the front door. Even without a confirmed compromise, if your appliance was unpatched and internet-facing through September, treat the passwords of staff who logged in through it as exposed. Prioritise admin and EHR/finance accounts, and make sure MFA is enforced on remote access.
- Keep the management side off the internet. Citrix says NetScaler management services should never be exposed to the public internet. Ask your MSP to confirm that, and to confirm they get Citrix security bulletin alerts directly so the next one does not reach you via Reddit.
- Healthcare: put this in the BAA conversation. If your MSP runs the gateway staff use to reach patient systems, ask what their notification commitment is when a device with that access is found vulnerable or compromised.
The pattern is now familiar: an internet-facing gateway, weeks of quiet exploitation, a weekend of private warnings, then a patch that does not undo what already happened. For a small organization, the useful response is three questions, not a forensics team on retainer: what build is it on, did anyone look for web shells first, and which passwords went through it. Ask them today.
[SOURCES]
- Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778 (CTX697096) — Cloud Software Group, 2026-09-27
- Steps to take if NetScaler ADC is suspected to be compromised (CTX694799) — Cloud Software Group, 2026-05-13
- Known Exploited Vulnerabilities Catalog, entry CVE-2026-88772 (added 2026-09-27, due 2026-09-30) — CISA
- CVE-2026-88772 detail — NIST National Vulnerability Database, published 2026-09-27
- Guidance for Addressing Citrix NetScaler ADC and Gateway Vulnerability CVE-2023-4966, Citrix Bleed — CISA, accessed 2026-10-01
- Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772) — Help Net Security, 2026-09-28
- Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug — SecurityWeek, 2026-09-28
- Citrix NetScaler exploitation began days before public notification — Cybersecurity Dive, 2026-09-29
- Hackers exploit Citrix NetScaler zero-day to deploy web shells — BleepingComputer, 2026-09-29
- Suspected state-sponsored hackers exploited NetScaler zero-day since early September (CVE-2026-88772) — Help Net Security, 2026-09-30
- Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild — Unit 42, Palo Alto Networks, 2026-09-30