If your organisation runs a Citrix NetScaler and it has been reachable from the internet at any point in the last month, you should assume an attacker could already have been inside it, and you should check before you do anything else. Two flaws in these appliances were being used in real attacks for weeks before Citrix said a word, and one of them works against every NetScaler straight out of the box, with nothing special switched on. The usual advice to patch at the next maintenance window does not apply here. The window closed before the fix existed.
A NetScaler is the box that lets staff work remotely and steers traffic to the right internal systems; it sits at the very edge of the network, facing the open internet, which is what makes it such a prize. The two vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772 and nicknamed "PitScaler" by some researchers, both carry a CVSS v4 score of 9.5 and both let a remote attacker with no password run code on the appliance. Citrix disclosed them on September 27, 2026, and by then attackers had already used them to gain full control of appliances, steal data, and burrow into internal networks at government agencies, banks, and professional services firms. This is a stop-what-you-are-doing situation, and the sections below explain exactly what to check and in what order.
Why this one matters to leadership, not just the security team
A NetScaler is, in practical terms, the front door and the receptionist for a lot of what an organisation does online. It decides who gets in, hands them off to the right internal system, and keeps the lights on by spreading traffic around. When an attacker takes control of that one box, they do not just get a foothold on a server somewhere; they get a position that sees and touches a great deal of trusted traffic, often without the monitoring tools that watch laptops and servers. Benjamin Harris, CEO of security firm watchTowr, put the stakes plainly: an attacker exploiting these flaws has a skeleton key to every organisation running a Citrix NetScaler, and they are actually using it.
Two things make this situation unusually serious. First, one of the two flaws affects every NetScaler in its out-of-the-box state, with no special configuration required, so "we didn't turn on anything unusual" is not a defence. Second, because the attacks were under way before any patch existed, simply installing the update does not answer the more important question: did someone already get in? That is a question for the business, not only for IT, because the answer shapes incident response, legal and regulatory obligations, and customer communications.
How this came to light
The first public signs were not a vendor advisory but a scramble. Over the weekend of September 26 and 27, NetScaler administrators began posting on Reddit that their IT suppliers, managed security providers, national CERTs, and in some cases law enforcement were quietly telling them to shut their NetScaler appliances down immediately, often without explaining why. One administrator wrote that their IT supplier's security team had called and, unable to give details, advised shutting the NetScalers down at once; others in the thread said their organisations had done the same.
Some of those warnings traced back to a private pre-notification from the Dutch National Cyber Security Centre (NCSC-NL), shared under restrictive handling rules, that said it had learned of two zero-days from a European partner CERT and that exploitation had been identified at multiple Citrix customers worldwide. On September 26, watchTowr went public, saying it was reacting to credible rumours that multiple unpatched NetScaler RCE vulnerabilities were circulating in the wild.
Citrix published its bulletin, CTX697096, on September 27, confirming both flaws, releasing patches, and stating that exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments had been observed. The U.S. Cybersecurity and Infrastructure Security Agency added both to its Known Exploited Vulnerabilities catalog the same day, warning that threat actors are actively exploiting these vulnerabilities globally and setting a short federal remediation deadline.
The timeline matters because of the gap in it. GreyNoise observed an exploitation attempt against a NetScaler Gateway on September 24, three days before public disclosure, and Google's Threat Intelligence Group and Mandiant later concluded the campaign had been ongoing since at least early September. watchTowr's Harris noted that the patch his team analysed was dated September 24, suggesting Citrix knew of the activity the week before it told customers, and he criticised the vendor's silence as, in his words, "almost purposeful". Harris was blunt about why that silence costs defenders: in an era of rapidly shrinking exploitation windows, hours matter, to say nothing of several days.
What the two critical flaws actually are
Both critical flaws live in the NetScaler Packet Processing Engine (NSPPE), the core component that handles network traffic, and both end in the same place: code running as root on the appliance's underlying FreeBSD operating system.
CVE-2026-88771: unauthenticated command injection (CVSS 9.5)
This is the one that should worry the broadest set of organisations. It stems from improper input validation and can permit arbitrary command execution, and its exposure is unusually broad: every NetScaler ADC and NetScaler Gateway deployment is affected, including default configurations, with no optional feature required. In plain terms, an attacker who can reach the appliance over the network can make it run commands of their choosing, without logging in. There is no precondition to check and no feature to disable; if it is a NetScaler on a vulnerable version, it is exposed. A public proof-of-concept exploit for this flaw has already been released.
CVE-2026-88772: a DTLS memory overflow (CVSS 9.5)
The second flaw is a memory overflow in how NetScaler handles DTLS, a version of the TLS encryption protocol used for certain VPN traffic. It is a memory overflow bug in the DTLS protocol handling that is rooted in the NSPPE, and it can lead to remote code execution or a denial of service. The important catch for prioritisation is the precondition: it affects appliances with DTLS enabled, and DTLS is on by default for VPN virtual servers, so a NetScaler Gateway is affected unless DTLS has been explicitly turned off.
For readers who want the mechanism, the researchers at watchTowr described it clearly. NetScaler reassembles DTLS handshake messages that arrive in fragments, and it trusts the fragment's declared size while separately being told the whole message is larger. A 120-byte handshake message can be made to arrive as 120 separate fragments, each one claiming to supply only a single byte; once every position has arrived, the server treats the message as complete. But the appliance keeps almost the entire content of each fragment in memory, so after 120 such records, the supposedly 120-byte message is backed by around 174 KB of data. That data is stitched into a single working buffer of only about 35,840 bytes, and because the vulnerable version never checks whether the next piece fits, data spills past the end of the buffer. watchTowr demonstrated that the overflow can be turned into full code execution with root privileges.
The six other flaws in the same bulletin
PitScaler arrived alongside six more NetScaler vulnerabilities, all fixed in the same release. None are confirmed as exploited, and most require specific configurations to be reachable, but they should be remediated by the same upgrade.
| CVE | CVSS v4 | Type | Precondition |
|---|---|---|---|
| CVE-2026-88771 | 9.5 (Critical) | Unauthenticated RCE (improper input validation) | All deployments, default config |
| CVE-2026-88772 | 9.5 (Critical) | Memory overflow, RCE or DoS | DTLS enabled (default on VPN vServers) |
| CVE-2026-88773 | 9.3 (Critical) | HTTP request smuggling | HTTP/SSL virtual servers configured |
| CVE-2026-88774 | 7.0 (High) | Policy bypass via HTTP URL expression | Policy using an HTTP URL-based expression |
| CVE-2026-88775 | 8.8 (High) | Memory overflow, erratic behaviour or DoS | Gateway (SSL VPN, ICA/CVPN/RDP Proxy) or AAA vServer |
| CVE-2026-88776 | 8.8 (High) | Memory overflow, erratic behaviour or DoS | Load balancing vServer of type Oracle |
| CVE-2026-88777 | 8.8 (High) | Memory overflow, erratic behaviour or DoS | LB/CS or CGNAT-LSN/NAT64 with non-HTTP L7 feature |
| CVE-2026-88778 | 8.8 (High) | TCP Initial Sequence Number prediction | TCP virtual server with Enhanced ISN Generation disabled |
CVE-2026-88773, the HTTP request smuggling flaw, is worth a second look for anyone relying on a web application firewall in front of NetScaler, since smuggling attacks are designed to slip past exactly that kind of front-end control. CVE-2026-88778 is handled a little differently from the rest: rather than relying solely on the upgrade, Citrix advises enabling Enhanced ISN Generation as a configuration change.
Who is affected
The vulnerabilities affect the following supported versions of customer-managed NetScaler ADC and NetScaler Gateway. If your appliance runs a version below the fixed build for its branch, assume it is affected.
| Branch | Affected | Fixed in |
|---|---|---|
| 14.1 | Before 14.1-73.37 | 14.1-73.37 |
| 13.1 | Before 13.1-64.23 | 13.1-64.23 |
| 14.1-FIPS | Before 14.1-73.37 FIPS | 14.1-73.37 FIPS |
| 13.1-FIPS / 13.1-NDcPP | Before 13.1-37.279 | 13.1-37.279 |
Two points deserve emphasis. Appliances running 14.1-73.32 and 13.1-63.21, the builds that fixed the NetScaler authentication bypass in August, fall inside the affected range and still need this new update; being current as of last month is not the same as being safe now. And Secure Private Access Hybrid deployments that use NetScaler instances are also affected and must be upgraded. Citrix-managed cloud services and Citrix-managed Adaptive Authentication are updated by Cloud Software Group itself; this bulletin is for the appliances you run.
As for scale, Palo Alto Networks reported roughly 50,000 potentially exposed NetScaler instances on the internet as of September 27. Not all of those meet the precondition for the DTLS flaw, but CVE-2026-88771 needs no precondition at all.
What the attackers are doing once they are in
This is not theoretical, and the post-exploitation activity is well documented. Mandiant and Google's Threat Intelligence Group found that the exploits bypass authentication and cause the NetScaler Packet Processing Engine to terminate unexpectedly, giving attackers root-level access. From there, a consistent playbook emerges.
Custom malware built for NetScaler. The intruders deployed two previously undocumented malware families. WHIPSHOT is a PHP web shell disguised as a Debian package and stored in the NetScaler VPN scripts directory; it acts as an HTTP proxy for SLAPSHOT, a Python-based TCP tunnelling tool that bridges the compromised appliance and internal devices, allowing attackers to spread deeper into the network. The two work together to give attackers a path from the appliance into the victim's internal network, enabling reconnaissance, lateral movement, and credential theft.
Web shells disguised as ordinary web files. Attackers edited the NetScaler web server configuration so that requests which look like harmless images or stylesheets are instead processed as attacker code. In one intrusion they modified the web server config so that .deb files would execute as PHP; in others they mapped requests for .ico images under /vpn/media/ to malicious PHP. Some of the web shells returned fake HTTP 404 responses while executing commands, to further disguise the activity. A separate analysis by LevelBlue observed a payload that maps the web shell to URLs resembling legitimate NetScaler CSS resources.
Rooting the shell and stealing the config. Because commands from a web shell normally run as a lower-privileged web server account, the attackers reset permissions on the system shell to keep root. To establish persistent root-level execution, the threat actor set the setuid bit on the /bin/sh executable. LevelBlue also documented second-stage scripts that create a local superuser account named sec_monitor, archive the NetScaler configuration directory and upload it to an external server, then delete the archive and erase themselves to reduce the forensic footprint.
Who is behind it. No public attribution has been made. Harris noted that historically, NetScaler vulnerabilities have been exploited by both state-sponsored groups and ransomware operators. Mandiant's Charles Carmakal said dozens of organisations have been hit, including by suspected state-sponsored actors, and warned to expect broad and opportunistic exploitation of both CVEs by a variety of threat actors in the near term. The confirmed targets so far span government agencies, financial services firms, education organisations, and legal and professional services across North America and Europe.
What you should do
1. Before you patch, check for compromise
This is the step that separates a NetScaler incident from an ordinary patch cycle, and it is easy to skip in the rush to update. Because exploitation preceded the patch, upgrading a compromised appliance closes the door but leaves the intruder inside. Mandiant's Carmakal was explicit: given active exploitation, NetScaler customers should prioritise examining systems for compromise before upgrading, preserve evidence if web shells or malicious files are found, and investigate scope, because patching alone may not eradicate the threat actor.
Hunt for the indicators that researchers have published, including:
- Unauthorised PHP handlers,
Alias, orAliasMatchentries in/etc/httpd.conf, especially ones mapping image, CSS,.deb, or.sigfiles to PHP. - A web shell at paths such as
/var/netscaler/logon/LogonPoint/custom/.ctxs.receiveror/var/netscaler/logon/LogonPoint/.local_journal. /bin/shmodified to run setuid (and setgid) root./tmp/.uxdportor/tmp/.uxdlockfiles associated with SLAPSHOT, and suspicious Python processes launched withnohupor carrying Base64 payloads.- An unexpected local superuser account such as
sec_monitorinns.conf. - Unexplained NSPPE crashes and unusual HTTP 404 patterns in the logs.
Citrix also provides generic indicators of compromise through the NetScaler Console's Security Advisory workflow, though it cautions these checks cannot cover every technique.
2. Patch to a fixed build immediately
Upgrade to 14.1-73.37 or later, 13.1-64.23 or later, or the corresponding FIPS/NDcPP builds. Treat this as an incident-response priority, not routine maintenance. One operational caveat from Citrix: a deployment running 13.1-64.23 may enter a reboot loop during upgrade when NetScaler variables are configured; administrators can run show ns variable, and if variables are returned, plan for 13.1-64.24.
3. If you genuinely cannot patch yet, reduce exposure, but understand the limits
For CVE-2026-88772 only, Mandiant recommends disabling DTLS where operationally feasible and blocking inbound UDP/443 upstream when DTLS is not required. Be clear-eyed about what that buys you: those mitigations apply only to CVE-2026-88772 and do not protect against CVE-2026-88771, and installing the security updates is the only way to address both flaws. Because the command injection flaw affects default installations, there is no configuration change that closes it. If you cannot patch and cannot otherwise contain the risk, the drastic step of taking the appliance offline may be justified; several organisations did exactly that over the disclosure weekend.
4. Keep the management interface off the internet
A standing piece of Citrix guidance that this episode reinforces: the NetScaler management services should never be exposed to the public internet. If yours are, fix that regardless of patch status.
5. If you find evidence of compromise, assume the attacker went deeper
A compromised NetScaler is a launch point, not the destination. If you confirm a breach, the config file the attackers tried to exfiltrate contains secrets worth rotating. Following Citrix's suspected-compromise guidance, change every service account password and secret stored on the appliance, reset the passwords of users who authenticated through it, revoke its certificates and private keys, and review internal systems for the lateral movement and credential theft that WHIPSHOT and SLAPSHOT are built to enable.
A note on the pattern
Edge devices like NetScaler are attractive precisely because of what makes them useful: they face the internet, they sit at the boundary of the internal network, and they rarely run the endpoint detection software that watches everything else. That combination lets an attacker turn a single unauthenticated request into a quiet, privileged position with a view into the whole organisation. NetScaler in particular has a long history here, appearing on the Five Eyes agencies' most-exploited lists for years running and drawing a fresh round of critical, actively exploited bugs on a near-annual cadence. The lesson is not that NetScaler is uniquely bad, but that internet-facing infrastructure of this kind deserves the same patch discipline, logging, and scrutiny as any crown-jewel system, plus a standing assumption that when a critical flaw lands, exploitation may already have started.
Summary
| CVEs | CVE-2026-88771, CVE-2026-88772 (nicknamed "PitScaler") |
| Component | Citrix NetScaler ADC and NetScaler Gateway (NSPPE) |
| Type | CVE-2026-88771: unauthenticated command injection. CVE-2026-88772: DTLS memory overflow |
| CVSS | 9.5 (Critical) each |
| Impact | Unauthenticated remote code execution as root; DoS |
| Affected | NetScaler ADC/Gateway 14.1 before 14.1-73.37; 13.1 before 13.1-64.23; FIPS/NDcPP builds; Secure Private Access Hybrid instances |
| Not affected | Citrix-managed cloud services and Citrix-managed Adaptive Authentication (updated by Cloud Software Group) |
| Trigger condition | CVE-2026-88771: none (all deployments, default config). CVE-2026-88772: DTLS enabled (default on VPN vServers) |
| Disclosed | September 27, 2026 (Citrix bulletin CTX697096) |
| Exploited in the wild? | Yes; both confirmed, campaign ongoing since at least early September |
| Public PoC? | Yes; released for both flaws by watchTowr |
| CISA KEV? | Yes; both added September 27 with a short federal remediation deadline |
| Custom malware | WHIPSHOT (PHP web shell), SLAPSHOT (Python TCP tunneler) |
| Interim mitigation | For CVE-2026-88772 only: disable DTLS, block inbound UDP/443. No config fix for CVE-2026-88771 |
| Full fix | Upgrade to 14.1-73.37 / 13.1-64.23 or later (or FIPS/NDcPP equivalents) |
With roughly 50,000 NetScaler appliances exposed to the internet, confirmed exploitation reaching back weeks before the patch, and custom malware already deployed in victim networks, this is not a situation to leave for the next maintenance window. Check for compromise, then patch, then assume the attacker may have moved beyond the appliance and investigate accordingly.
If you need help checking your NetScaler appliances for the published indicators of compromise, assessing whether an intruder reached your internal network, or managing credential rotation on devices that were exposed before patching, get in touch. A skeleton key to the network edge deserves a fast, deliberate response.