Back to News

Attackers Exploited Two Citrix NetScaler Flaws Before Disclosure, Affecting More Than 100 Organizations

Attackers Exploited Two Citrix NetScaler Flaws Before Disclosure, Affecting More Than 100 Organizations

Two Citrix NetScaler vulnerabilities, CVE-2026-88771 and CVE-2026-88772, were actively exploited for weeks before their public disclosure, Citrix confirmed on September 27, 2026. CISA added both flaws to its Known Exploited Vulnerabilities catalog the same day, while the release of a proof of concept and root-cause analysis triggered mass “spray-and-pray” scanning against internet-facing NetScaler appliances.

Key Points

  • CVE-2026-88771 enables unauthenticated remote code execution through improper input validation and affects default configurations.
  • CVE-2026-88772 is a memory boundary violation reachable when DTLS is enabled, which is the default on NetScaler VPN virtual servers.
  • Censys identified about 42,000 internet-facing NetScaler hosts, while Kevin Beaumont, reported that fewer than 10% were patched and more than 100 organizations had been affected.
  • Observed attacks included log poisoning, webshell deployment, credential and session-token theft, persistence, and data exfiltration.
  • Citrix and responders advised organizations to capture forensic evidence, isolate potentially compromised appliances, rotate secrets, and rebuild affected systems after applying fixed firmware.

Exploitation began before disclosure

Citrix NetScaler ADC and NetScaler Gateway are application delivery controllers and SSL VPN gateways that sit at enterprise and government network perimeters. The appliances mediate remote access and authentication, making a pre-authentication compromise capable of exposing internal networks, session tokens, credentials, and SSL certificates and private keys.

GreyNoise detected attempted zero-day exploitation against a NetScaler Gateway on September 24, more than three days before Citrix disclosed the vulnerabilities. Citrix’s September 27 bulletin covered eight vulnerabilities, CVE-2026-88771 through CVE-2026-88778, and confirmed active exploitation of CVE-2026-88771 and CVE-2026-88772.

CISA added both vulnerabilities to its Known Exploited Vulnerabilities catalog on September 27 and directed federal civilian agencies to patch or disconnect affected appliances by September 30. After watchTowr Labs and other researchers published proof-of-concept material and technical analysis, large-scale scanning and exploitation attempts appeared within minutes of the disclosures.

Technical details

CVE-2026-88771 is an improper input-validation vulnerability that permits unauthenticated remote code execution before authentication. The reported CVSS v4.0 score is 9.5. The flaw allows an attacker to run arbitrary commands on affected appliances running default configurations and does not require a special feature to be enabled.

watchTowr Labs’ analysis described log-poisoning techniques in which attackers injected data through HTTP headers and login fields, including the User-Agent header and requests to /nf/auth/doAuthentication.do, causing NetScaler processes to interpret attacker-controlled data as commands. Observed payloads included base64-encoded content appended directly after the User-Agent value without a separating space, along with log entries containing “pitboss” followed by shell-interpolation patterns.

Attackers used the technique to deploy webshells, obtain administrative access, conceal persistence behind fake stylesheet addresses, manipulate or erase log evidence, restart servers, and extract sensitive material. Kevin Beaumont, an independent security researcher reported that the webshell deployed on each compromised appliance appeared to be unique, making remote signature-based scanning difficult.

CVE-2026-88772 is a memory buffer boundary violation that can be reached when DTLS is enabled. DTLS is enabled by default on NetScaler VPN virtual servers, leaving many Gateway deployments exposed. Citrix and CISA confirmed exploitation of the flaw, although observed exploitation volume trailed activity involving CVE-2026-88771. The reported CVSS v4.0 score is also 9.5.

Scale and indicators

Censys identified approximately 42,000 internet-facing hosts running NetScaler ADC or Gateway. About 13,549 were in the United States, representing roughly 32% of the total, and about 5,678 were in Germany, representing roughly 13%. Microsoft-hosted systems accounted for approximately 4,254 hosts, or 10%, while Amazon-hosted systems accounted for about 3,013, or 7%.

Beaumont reported that fewer than 10% of exposed hosts had been patched at the time of his analysis and tracked more than 100 victim organizations. No named threat group was publicly attributed to the exploitation. The observed activity included attempts to steal credentials and session tokens, extract private keys, establish persistence, and exfiltrate data.

GreyNoise, Lupovis, and other responders identified several hunting cues. These included base64-encoded strings appended directly to User-Agent headers, “pitboss” entries followed by shell-interpolation patterns, and suspicious request bodies sent to POST /nf/auth/doAuthentication.do. Responders also identified DNS lookups ending in instances.httpworkbench.com and outbound connections or exfiltration traffic involving the Hetzner-hosted address 138.199.200.90.

The indicators are not exhaustive. Citrix warned that its published detection script might fail to identify actual compromises, while the unique webshells observed on individual appliances complicate fleet-wide signature scans.

Xavier Bellekens of Lupovis described the continuing exposure risk:

“If you run NetScaler and you haven’t patched, assume you are already being probed.” – Xavier Bellekens, Lupovis

Mitigation and response

Citrix published fixed builds including 14.1-73.37 and later on the 14.1 branch and 13.1-64.23 and later on the 13.1 branch. Administrators must consult the Citrix bulletin for exact fixed builds covering FIPS and NDcPP variants. Versions 12.1 and 13.0 were not listed among the patched branches and were identified for emergency migration to a supported branch.

Citrix and incident responders advised administrators to capture configuration exports, authentication and session logs, memory, and crash dumps where feasible before patching because an update can remove forensic artifacts. Organizations with suspected or confirmed compromise were advised to isolate the appliance, rotate credentials and API keys accessible from it, revoke and reissue session tokens, replace SSL certificates and private keys stored on the device, and rebuild the appliance from a known-good firmware image rather than relying solely on patching to remove persistence.

Internet-facing unpatched NetScaler appliances that were reachable during the exploitation window should be treated as potentially compromised. Organizations were advised to verify firmware versions, hunt for the reported indicators across their fleets, compress patch timelines, and perform detection and containment activities in addition to applying the vendor updates.

Sources

Mayank Mehra

Written by

Mayank Mehra is a cybersecurity professional with 8+ years of hands-on experience in application security, penetration testing, vulnerability assessment, and AI security. He holds CEH, CAPEN, and CRTP certifications and specialises in identifying and mitigating security risks across applications and AI-powered systems.

View all posts →