Citrix patches exploited NetScaler zero-days (CVE-2026-88771, CVSS 9.5)
Citrix patched eight NetScaler ADC/Gateway flaws, two exploited as zero-days. CVE-2026-88771 hits default configs; a public PoC exists and web shells are being dropped.
Citrix has patched eight vulnerabilities in NetScaler ADC and Gateway, at least two of them exploited as zero-days before fixes shipped. The critical one, CVE-2026-88771, is an unauthenticated command injection scored CVSS 9.5 that works against appliances in their default configuration — and a public proof-of-concept is already circulating.
Citrix released the fixes and advisory CTX697096 on September 27. The company held off on official confirmation for roughly a day and a half while CERTs and researchers warned users without vendor acknowledgement — a delay several practitioners called out publicly.
What's affected
France's CERT-FR (CERTFR-2026-ALE-011) lists the full set, CVE-2026-88771 through CVE-2026-88778. The two that matter most:
- CVE-2026-88771 — unauthenticated command injection, RCE, affects default configs.
- CVE-2026-88772 — memory overflow reachable when DTLS is enabled, leading to RCE or denial of service.
Fixed builds, per the Citrix advisory and CERT-FR:
- NetScaler ADC / Gateway 14.1 — 14.1-73.37 (and 14.1-73.37 FIPS)
- NetScaler ADC / Gateway 13.1 — 13.1-64.23
- 13.1-FIPS / NDcPP — 13.1-NDcPP 13.1.37.279
Versions 13.0 and 12.1 are end-of-life and receive no fix. Palo Alto Networks counted more than 50,000 publicly exposed NetScaler instances on September 27.
Exploitation status
Exploitation is confirmed and predates the patch. GreyNoise logged an exploitation attempt against a NetScaler Gateway on September 24 — five days before Citrix confirmed anything — and researchers believe activity started earlier. Mandiant is tracking post-exploitation tooling on compromised appliances:
- WHIPSHOT — a PHP web shell, disguised as a Debian package, used as an HTTP proxy.
- SLAPSHOT — a Python TCP tunneling tool for pivoting into internal networks.
Per Mandiant's reporting relayed by BleepingComputer, operators dropped web shells at paths such as /var/netscaler/logon/LogonPoint/custom/.ctxs.receiver and edited httpd.conf to make the requests look like fetches for CSS or image files. Reported host-side indicators:
/var/netscaler/logon/LogonPoint/custom/.ctxs.receiver (web shell)
/etc/httpd.conf (Alias/AliasMatch entries added)
/bin/sh (setuid root)
/tmp/.uxdport, /tmp/.uxdlock (attacker artifacts)
Treat these as leads from the vendor writeup, not a complete detection package — pull the primary advisory before building rules.
Action checklist
- Upgrade to 14.1-73.37 or 13.1-64.23 (FIPS: 14.1-73.37 FIPS / 13.1-NDcPP 13.1.37.279) — today. Anything on 13.0 or 12.1 needs a migration, not a patch.
- Because CVE-2026-88771 hits default configs and a PoC is public, assume any internet-reachable appliance was a target. Hunt before you trust the patch.
- Check for
.ctxs.receiverand other custom files underLogonPoint/custom/, unexpectedAlias/AliasMatchlines inhttpd.conf, and a setuid-root/bin/sh. - If you find evidence of compromise, rotate all secrets the appliance held (session keys, LDAP/RADIUS creds, certificates) and terminate active sessions. A patched-but-breached box is still breached.
- Restrict management-plane exposure — the management interface should never face the internet.
Context
This is the second NetScaler zero-day story we've covered this cycle, after the CitrixBleed-style CVE-2026-8451 disclosure. NetScaler's pattern is consistent: internet-facing, high-value, and exploited fast once a PoC lands. The delayed-confirmation angle is the new wrinkle — for 36 hours the only warnings came from CERTs, not the vendor, which is exactly the window operators can't afford to lose.