CISA Warns: Critical Citrix NetScaler Zero-Days Demand Immediate Patching Action

5

CISA Warns of Global Exploitation of Two Critical Citrix NetScaler Zero-Days

Federal agencies have until September 30 to patch vulnerabilities affecting tens of thousands of exposed devices worldwide.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two critical Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog on Sunday after confirming active global exploitation of both zero-days.

The urgency of this alert cannot be overstated. With more than 50,000 publicly exposed Citrix NetScaler devices potentially vulnerable and threat actors already deploying sophisticated persistence techniques, organizations relying on NetScaler infrastructure face an immediate and credible risk of full system compromise. For security teams still treating this as a routine patch cycle, the window for that luxury has already closed.


The Vulnerabilities: What They Do and Who Is at Risk

Both flaws carry a CVSS score of 9.5 and affect Citrix NetScaler ADC and NetScaler Gateway — widely used networking products deployed across enterprise and government environments for application delivery and secure remote access.

CVE-2026-88771: Unauthenticated Command Execution

The first vulnerability, tracked as CVE-2026-88771, is an improper input validation flaw that allows an unauthenticated attacker to execute arbitrary commands. It affects all NetScaler ADC and NetScaler Gateway deployments without exception — meaning no configuration variation provides a natural safeguard against exposure.

CVE-2026-88772: Remote Code Execution via Memory Buffer Flaw

The second, CVE-2026-88772, is a memory buffer restriction flaw enabling remote code execution or denial-of-service. This vulnerability specifically affects deployments where DTLS configuration is enabled — a setting that is turned on by default on VPN virtual servers, significantly broadening its potential attack surface.

Palo Alto Networks Unit 42 identified 50,277 publicly exposed Citrix NetScaler instances potentially vulnerable to both zero-days as of September 27, 2026. That figure represents a massive target landscape for threat actors operating at scale. Understanding your own exposure begins with a structured vulnerability assessment process for enterprise infrastructure — organizations that have not recently audited their NetScaler deployments should treat that as an immediate priority alongside patching.


How Attackers Are Actively Exploiting These Flaws

The Technical Attack Chain

Security research firm watchTowr Labs published technical findings on September 28 revealing that CVE-2026-88771 originates in a Perl script named ns_monuploadd_err.pl used to process NetScaler crash and error information. The script constructs a shell command using attacker-influenced input, enabling remote code execution with root privileges.

An unauthenticated attacker can inject arbitrary shell commands through data that NetScaler writes to its logs. That data is then fed into a shell command, triggering command injection. The attack requires only a pre-authentication POST request to the /nf/auth/doAuthentication.do endpoint — a low barrier that makes exploitation accessible to a wide range of threat actors, not only sophisticated nation-state groups.

Observed Exploitation Activity in the Wild

Threat intelligence firm GreyNoise reported that the earliest known exploitation attempt against its sensor occurred on September 24, 2026, originating from IP address 149.104.78[.]141. While that initial attempt was unsuccessful, the tactics observed were notably sophisticated.

"The MCA attempted to set both the Set User ID and Set Group ID bits on /bin/sh to obtain a root shell and install a password-protected webshell that accepts communication by the cookie value sent by the adversary," GreyNoise reported. "This may be to avoid persisting their commands in web logs."

The threat actor also attempted to configure the web server to treat an installed hidden dot file — .ctxs.receiver — as a PHP file without a .php extension, and created routing aliases to disguise web shell access behind what appeared to be a standard CSS file request. The attacker then attempted to kill the httpd process to restart the server and activate the changes.

These are not the hallmarks of opportunistic, low-skill exploitation. The persistence techniques observed — hidden web shells, disguised routing, process manipulation — reflect a deliberate effort to maintain long-term access while evading detection. The scale and sophistication of this campaign echoes the kind of infrastructure targeting seen in high-profile nation-state operations in recent years, signalling that passive monitoring alone is wholly insufficient.

The broader implications extend beyond NetScaler environments. Attacks of this nature frequently serve as entry points for lateral movement across connected systems. Organisations that want to understand how to prevent a data breach following infrastructure compromise should review containment and forensic procedures as part of their immediate incident response planning.


What Organizations Must Do Right Now

Apply Patches Immediately — Without Exception

CISA has directed Federal Civilian Executive Branch agencies to apply patches by September 30, 2026. For private sector organizations, the message is equally clear — remediation should be treated as an emergency priority, not scheduled into a standard maintenance window.

Citrix has released patched versions addressing both vulnerabilities. Affected organizations should update to the following releases or later:

  • NetScaler ADC and Gateway 14.1-73.37
  • NetScaler ADC and Gateway 13.1-64.23
  • NetScaler ADC 14.1-FIPS 14.1-73.37
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.279

"Because updating Citrix NetScaler appliances can be complex and may require downtime, CISA is issuing this alert to help organizations assess exposure, prioritize mitigation, and account for these vulnerabilities into their risk-management activities," the agency stated.

Assessing Whether You Have Already Been Compromised

Citrix has made generic indicators of compromise available through NetScaler Console to help customers assess whether their deployments have been affected. Use this tooling immediately — establishing whether your environment has already been touched is the first step before any remediation decision can be made with confidence.

Organizations that suspect a compromise should take the following steps without delay:

  1. Preserve forensic evidence from affected instances before making any changes
  2. Isolate the device from the network to prevent further lateral movement
  3. Revoke all credentials and access tied to the compromised device
  4. Investigate every server and system the NetScaler ADC connected to for signs of lateral movement
  5. Rebuild firmware to the latest version from scratch rather than restoring from a potentially tainted backup
  6. Rotate all local account passwords and Key Encryption Keys
  7. Replace restored SSL certificates if recovering from backup

Active Threat Hunting Across Connected Infrastructure

Treat any NetScaler device connected to sensitive internal systems as potentially compromised until investigation confirms otherwise. The tactics observed in active exploitation campaigns specifically target persistence and lateral movement — meaning a clean patch on the NetScaler appliance itself does not guarantee the broader environment is unaffected.

Active threat hunting across connected infrastructure is essential. Security teams should also document remediation steps carefully. Regulatory bodies and cyber insurers will increasingly expect evidence of structured incident response when critical infrastructure vulnerabilities are exploited at this scale. For teams building or refining that response capability, understanding why cybersecurity resilience matters at the organisational level provides important context for securing executive support and resources during high-pressure response windows.

For additional technical guidance on the Citrix NetScaler vulnerabilities and the latest IoC updates, the CISA Known Exploited Vulnerabilities catalog provides authoritative and regularly updated information for security teams managing remediation at scale.

You might also like