{"id":388,"date":"2026-10-06T11:15:14","date_gmt":"2026-10-06T11:15:14","guid":{"rendered":"https:\/\/managedt.com\/blog\/cisa-citrix-netscaler-critical-flaws-exploited\/"},"modified":"2026-10-09T02:43:47","modified_gmt":"2026-10-09T02:43:47","slug":"cisa-citrix-netscaler-critical-flaws-exploited","status":"publish","type":"post","link":"https:\/\/managedt.com\/blog\/cisa-citrix-netscaler-critical-flaws-exploited\/","title":{"rendered":"CISA Confirms Active Exploitation of Two Critical Citrix NetScaler Flaws"},"content":{"rendered":"<p>Network defenders running Citrix NetScaler ADC and NetScaler Gateway appliances now have a clear, time-bound reason to patch: CISA has confirmed global active exploitation of two newly added critical flaws and given federal agencies until September 30, 2026 to remediate. Both vulnerabilities carry a CVSS score of 9.5 and allow unauthenticated attackers to take over appliances that front enterprise VPN and application delivery traffic.<\/p>\n<h2>What CISA added to the KEV catalog<\/h2>\n<p>On September 27, 2026, CISA added the following two vulnerabilities to its Known Exploited Vulnerabilities catalog, citing partner threat intelligence confirming active exploitation worldwide:<\/p>\n<ul>\n<li><strong>CVE-2026-88771<\/strong> (CVSS 9.5): an improper input validation flaw that allows an unauthenticated attacker to execute arbitrary commands. It affects all NetScaler ADC and NetScaler Gateway deployments.<\/li>\n<li><strong>CVE-2026-88772<\/strong> (CVSS 9.5): an improper restriction of operations within the bounds of a memory buffer flaw that can lead to remote code execution or denial of service. Exploitation requires DTLS to be enabled, an option that is on by default for VPN virtual servers.<\/li>\n<\/ul>\n<p>CISA noted that updating NetScaler appliances can be complex and may require downtime, and published the alert to help organizations assess exposure, prioritize mitigation, and account for these flaws in risk-management activities.<\/p>\n<h2>Which NetScaler versions are affected<\/h2>\n<p>No rewrite needed.<\/p>\n<ul>\n<li>NetScaler ADC and NetScaler Gateway 14.1-73.37 and later<\/li>\n<li>NetScaler ADC and NetScaler Gateway 13.1-64.23 and later releases of 13.1<\/li>\n<li>NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later<\/li>\n<li>NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.279 and later<\/li>\n<\/ul>\n<p>Federal Civilian Executive Branch agencies have been given until September 30, 2026 to apply the fixes, with private-sector operators strongly encouraged to follow the same timeline.<\/p>\n<h2>How the command injection flaw works<\/h2>\n<p>Technical analysis published on September 28, 2026 traced CVE-2026-88771 to a Perl script, ns_monuploadd_err.pl, which processes NetScaler crash and error information. The script builds a shell command using input that can be shaped by an attacker, and the attacker-controlled data ends up in NetScaler logs that get fed back into the script as input. The result is unauthenticated remote code execution as root.<\/p>\n<p>Triggering the flaw is a single pre-authentication request to the \/nf\/auth\/doAuthentication.do endpoint. A crafted POST body carries an injected shell command that runs as the appliance&#8217;s root user, giving the attacker the same level of control as an administrator on the box.<\/p>\n<h2>How exposed are NetScaler appliances right now?<\/h2>\n<p>Telemetry from Palo Alto Networks Unit 42 identified more than 50,277 publicly exposed NetScaler ADC and Gateway instances that appeared potentially vulnerable to both zero-days as of September 27, 2026. That number gives a sense of the attack surface available to whoever learns to weaponize the flaws reliably.<\/p>\n<p>GreyNoise recorded the earliest known exploitation attempt against its sensors on September 24, originating from IP address 149.104.78[.]141. That initial attempt did not succeed, but it confirmed pre-patch probing in the wild.<\/p>\n<h2>What attackers are trying to do<\/h2>\n<p>GreyNoise described a multi-step intrusion attempt aimed at persistence and stealth. The actor tried to set the setuid and setgid bits on \/bin\/sh to obtain a root shell, then install a password-protected webshell that activates only when a specific cookie value is present, a pattern that helps hide commands from standard web-server logs.<\/p>\n<p>Further attempts included configuring the web server to treat a dot file (.ctxs.receiver) as a PHP file without giving it a .php extension, creating URL aliases that route requests for a non-existent cascading style sheet (receiver.min.css) to that web shell, and adding a flexible AliasMatch pattern so variable characters added to receiver.min.[0-9a-f].css paths would still reach the shell. The actor also attempted to kill the httpd process to restart the server, likely to load the new configuration. The goal across these steps is durable, low-noise access to the appliance.<\/p>\n<h2>What to do if a NetScaler may already be compromised<\/h2>\n<p>Citrix has published generic indicators of compromise through the NetScaler Console to help customers determine whether their deployments have been touched. If compromise is suspected, the recommended response is to preserve evidence, isolate the device, revoke credentials and access, and investigate every server and system the NetScaler ADC talked to for signs of further compromise. From there, rebuild and update the firmware to the latest fixed version, and if a restore from a known good backup is required, rotate every local account password, regenerate Key Encryption Keys (KEK), and replace all restored SSL certificates. Finally, harden the device against future attacks.<\/p>\n<h2>FAQ<\/h2>\n<h3>What are CVE-2026-88771 and CVE-2026-88772?<\/h3>\n<p>They are two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway. CVE-2026-88771 is an unauthenticated command injection flaw, and CVE-2026-88772 is a memory-bound flaw that can lead to remote code execution or denial of service. Both carry a CVSS score of 9.5.<\/p>\n<h3>Are these NetScaler vulnerabilities being actively exploited?<\/h3>\n<p>Yes. CISA confirmed global active exploitation and added both flaws to the Known Exploited Vulnerabilities catalog on September 27, 2026. GreyNoise recorded an exploitation attempt against its sensors as early as September 24.<\/p>\n<h3>Which NetScaler versions fix the flaws and how urgently should they be patched?<\/h3>\n<p>Fixed versions include NetScaler ADC and Gateway 14.1-73.37 and later, 13.1-64.23 and later, 14.1-FIPS 14.1-73.37, and 13.1-FIPS and 13.1-NDcPP 13.1.37.279. CISA gave federal agencies until September 30, 2026 to apply the fixes, and private organizations are urged to follow the same timeline.<\/p>\n<p><script type=\"application\/ld+json\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"FAQPage\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"What are CVE-2026-88771 and CVE-2026-88772?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"They are two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway. CVE-2026-88771 is an unauthenticated command injection flaw, and CVE-2026-88772 is a memory-bound flaw that can lead to remote code execution or denial of service. Both carry a CVSS score of 9.5.\"}},{\"@type\":\"Question\",\"name\":\"Are these NetScaler vulnerabilities being actively exploited?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Yes. CISA confirmed global active exploitation and added both flaws to the Known Exploited Vulnerabilities catalog on September 27, 2026. GreyNoise recorded an exploitation attempt against its sensors as early as September 24.\"}},{\"@type\":\"Question\",\"name\":\"Which NetScaler versions fix the flaws and how urgently should they be patched?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Fixed versions include NetScaler ADC and Gateway 14.1-73.37 and later, 13.1-64.23 and later, 14.1-FIPS 14.1-73.37, and 13.1-FIPS and 13.1-NDcPP 13.1.37.279. CISA gave federal agencies until September 30, 2026 to apply the fixes, and private organizations are urged to follow the same timeline.\"}}]}]}<\/script><\/p>\n<hr style=\"margin:2.5em 0 1em;opacity:.35\" \/>\n<p style=\"font-size:.85em;opacity:.7\">This article summarizes reporting from <a href=\"https:\/\/thehackernews.com\/2026\/09\/cisa-says-attackers-are-exploiting-two.html\" target=\"_blank\" rel=\"nofollow noopener\">thehackernews.com<\/a>.<\/p>\n<p><!-- seo-pro:slop-fixed --><\/p>\n","protected":false},"excerpt":{"rendered":"<p>CISA adds two critical Citrix NetScaler vulnerabilities (CVSS 9.5) to its KEV catalog after confirming global active exploitation. Patching guidance inside.<\/p>\n","protected":false},"author":3,"featured_media":387,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-388","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/388","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/comments?post=388"}],"version-history":[{"count":2,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/388\/revisions"}],"predecessor-version":[{"id":491,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/388\/revisions\/491"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/media\/387"}],"wp:attachment":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/media?parent=388"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/categories?post=388"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/tags?post=388"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}