{"id":275,"date":"2026-09-30T00:39:21","date_gmt":"2026-09-30T00:39:21","guid":{"rendered":"https:\/\/managedt.com\/blog\/citrix-netscaler-zero-days-exploited-weeks-before-patch\/"},"modified":"2026-09-30T00:39:22","modified_gmt":"2026-09-30T00:39:22","slug":"citrix-netscaler-zero-days-exploited-weeks-before-patch","status":"publish","type":"post","link":"https:\/\/managedt.com\/blog\/citrix-netscaler-zero-days-exploited-weeks-before-patch\/","title":{"rendered":"Citrix NetScaler zero-days exploited for weeks before patch (CVE-2026-88771, CVE-2026-88772)"},"content":{"rendered":"<p>Citrix has patched eight vulnerabilities in NetScaler ADC and NetScaler Gateway, and two of them, CVE-2026-88771 and CVE-2026-88772, were already being exploited in zero-day attacks to plant webshells on unmitigated devices before fixes shipped. The exploitation ran for roughly a month before public disclosure, and the activity has since been confirmed by the Dutch National Cyber Security Center (NCSC-NL), the US Cybersecurity and Infrastructure Security Agency (CISA), and outside researchers.<\/p>\n<h2>What the two exploited flaws actually do<\/h2>\n<p>CVE-2026-88771 is an improper input validation bug that allows remote, unauthenticated attackers to execute arbitrary commands on devices running a default configuration, with no user interaction required. NCSC-NL warned that the flaw gives attackers full control of the gateway, opening a direct path to the internal corporate network behind it.<\/p>\n<p>CVE-2026-88772 is a memory overflow vulnerability that can lead to remote code execution or denial of service. It is remotely exploitable without user interaction, but only when DTLS is enabled, which is on by default for virtual VPN servers. The two bugs can be exploited independently.<\/p>\n<h2>Which deployments are affected?<\/h2>\n<p>The vulnerabilities hit customer-managed installations of:<\/p>\n<ul>\n<li>Citrix NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37, and 13.1 before 13.1-64.23<\/li>\n<li>NetScaler ADC FIPS before 14.1-73.37 FIPS, and FIPS and NDcPP before 13.1-37.279<\/li>\n<li>Secure Private Access Hybrid deployments using NetScaler instances<\/li>\n<\/ul>\n<p>Citrix has urged customers to upgrade to a fixed version, then check for evidence of compromise and run incident response if anything is found.<\/p>\n<h2>How long were these flaws in active use?<\/h2>\n<p>Rumors about the bugs and their in-the-wild exploitation surfaced on Reddit on Friday, after IT suppliers circulated warnings they had received from NCSC-NL. European government sources have been alerting organizations about active attacks all week, and the activity itself has been running this entire month, which lines up with the note from outside researchers that exploitation pre-dated the patch by several weeks.<\/p>\n<p>The profile of the attacker activity points away from opportunistic cybercrime. Public reporting has described the operators as well resourced and likely nation-state aligned, with an espionage motive rather than ransomware. About two-thirds of threat actor activity against Citrix NetScaler over the last seven years has involved APT groups, with the remaining one-third tied to ransomware affiliates, according to published research from Tenable. No threat actor has been publicly named.<\/p>\n<h2>How to check whether a device was compromised<\/h2>\n<p>Detection is harder than usual here because the attacks started weeks ago. The detection script Citrix ships through the NetScaler Console only works if logs on the affected devices have not rotated since the attack, and they probably have. Outside researchers have suggested digging through SIEM logs for base64 strings placed directly after the User-Agent field, and for log lines containing the string pitboss followed by IFS (written as pitboss*IFS) or by b64decode (pitboss*b64decode). The webshells planted on each device are unique, and the attackers ran anti-forensics commands to delete artefacts, which is why a deeper review is often needed.<\/p>\n<p>Citrix has acknowledged that its published indicators of compromise may fail to catch real compromises because threat actors shift tactics, techniques, and infrastructure frequently, and it recommends bringing in experienced forensic investigators for a full environment assessment. NCSC-NL has separately advised backing up device memory and log files going back at least a month before installing the updates, and watching for suspicious traffic or anomalous actions even after upgrade.<\/p>\n<h2>What US federal agencies have been ordered to do<\/h2>\n<p>CISA added both actively exploited flaws to its Known Exploited Vulnerabilities catalog on Sunday and ordered US federal civilian agencies to remediate by Wednesday, September 30, 2026, with forensic triage to confirm or rule out compromise. CISA said it had received reports and partner threat intelligence confirming that threat actors are actively exploiting the vulnerabilities globally.<\/p>\n<h2>What defenders should do next<\/h2>\n<p>For any organization running affected NetScaler versions, the priority is to patch to a fixed build immediately, then treat every previously unpatched appliance as potentially compromised. Memory and log captures taken before patching give investigators something to work with if logs have already rotated, and post-upgrade monitoring matters because the same access paths that made exploitation possible are still present in any unpatched spare or standby device left on the network.<\/p>\n<h2>FAQ<\/h2>\n<h3>What are CVE-2026-88771 and CVE-2026-88772?<\/h3>\n<p>They are two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway. CVE-2026-88771 is an improper input validation flaw that lets unauthenticated remote attackers run arbitrary commands on default-configured devices. CVE-2026-88772 is a memory overflow that can lead to remote code execution or denial of service when DTLS is enabled, which is the default on virtual VPN servers.<\/p>\n<h3>How long were the Citrix NetScaler zero-days being exploited before the patch?<\/h3>\n<p>Based on public reporting, exploitation had been underway for roughly a month before Citrix released fixes on Sunday, September 27, 2026. Warnings from European government sources and IT suppliers had been circulating through the week before disclosure.<\/p>\n<h3>What should organizations do after patching NetScaler?<\/h3>\n<p>Upgrade to a fixed NetScaler version, then check every previously unpatched device for evidence of compromise. Back up memory and log files going back at least a month before installing updates, review SIEM logs for indicators like base64 strings after the User-Agent field and pitboss*IFS or pitboss*b64decode log lines, and engage forensic investigators if any signs of compromise appear.<\/p>\n<p><script type=\"application\/ld+json\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"FAQPage\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"What are CVE-2026-88771 and CVE-2026-88772?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"They are two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway. CVE-2026-88771 is an improper input validation flaw that lets unauthenticated remote attackers run arbitrary commands on default-configured devices. CVE-2026-88772 is a memory overflow that can lead to remote code execution or denial of service when DTLS is enabled, which is the default on virtual VPN servers.\"}},{\"@type\":\"Question\",\"name\":\"How long were the Citrix NetScaler zero-days being exploited before the patch?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Based on public reporting, exploitation had been underway for roughly a month before Citrix released fixes on Sunday, September 27, 2026. Warnings from European government sources and IT suppliers had been circulating through the week before disclosure.\"}},{\"@type\":\"Question\",\"name\":\"What should organizations do after patching NetScaler?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Upgrade to a fixed NetScaler version, then check every previously unpatched device for evidence of compromise. Back up memory and log files going back at least a month before installing updates, review SIEM logs for indicators like base64 strings after the User-Agent field and pitboss*IFS or pitboss*b64decode log lines, and engage forensic investigators if any signs of compromise appear.\"}}]}]}<\/script><\/p>\n<hr style=\"margin:2.5em 0 1em;opacity:.35\" \/>\n<p style=\"font-size:.85em;opacity:.7\">This article summarizes reporting from <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/09\/28\/citrix-netscaler-rce-zero-days-exploited-for-weeks-cve-2026-88771-cve-2026-88772\/\" target=\"_blank\" rel=\"nofollow noopener\">helpnetsecurity.com<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Two critical NetScaler ADC and Gateway flaws have been exploited in zero-day attacks to plant webshells for weeks. Patches are out, and CISA has ordered federal<\/p>\n","protected":false},"author":3,"featured_media":274,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-275","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/275","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/comments?post=275"}],"version-history":[{"count":1,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/275\/revisions"}],"predecessor-version":[{"id":276,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/275\/revisions\/276"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/media\/274"}],"wp:attachment":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/media?parent=275"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/categories?post=275"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/tags?post=275"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}