MongooseWeb

File

Edit

View

History

Bookmarks

Profiles

Tabs

Window

Help

Mon 15 Oct

13:37

NetScaler is the front door. Two zero-days just walked through it.

On 27 September 2026, Citrix published security bulletin CTX697096 covering eight vulnerabilities in customer-managed NetScaler ADC and NetScaler Gateway. Two of them, CVE-2026-88771 and CVE-2026-88772, were already being exploited as zero-days. Both score 9.5. CISA added both to the Known Exploited Vulnerabilities catalogue the same day. On 1 October, the UK National Cyber Security Centre told UK organisations to treat this as an incident, not a routine patch cycle.

If your remote access, ICA proxy or application delivery sits on a NetScaler, this is not an edge-device hygiene issue. It is a possible foothold on the box that terminates your VPN and sits in front of internal applications.

What was exploited

CVE-2026-88771 is an improper input validation flaw. An unauthenticated attacker can execute arbitrary commands. Citrix states it affects all NetScaler ADC and Gateway deployments, including the default configuration. No optional feature has to be switched on.

CVE-2026-88772 is a memory overflow that can lead to remote code execution or denial of service. It requires DTLS. DTLS is enabled by default on VPN virtual servers, which is how most Gateway deployments are built.

Citrix’s own wording: “Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed.” The bulletin applies to customer-managed appliances. Secure Private Access Hybrid deployments that use NetScaler instances are in scope too.

Supported builds that need upgrading:

  • 14.1 before 14.1-73.37
  • 13.1 before 13.1-64.23
  • 14.1-FIPS before 14.1-73.37
  • 13.1-FIPS and 13.1-NDcPP before 13.1-37.279

End-of-life 12.1 and 13.0 have no fix. If you are still on those, you are running an internet-facing appliance the vendor will not patch.

The same bulletin also fixes HTTP request smuggling (CVE-2026-88773, CVSS 9.3, scored 10.0 by NVD), policy bypass, denial of service and predictable TCP sequence numbers (CVE-2026-88774 through CVE-2026-88778). Those six are not confirmed as exploited. Patch the product, not the two lines in the KEV list. A smuggling bug on the device that fronts your applications is the same class of problem as an authorisation flaw: the control you trust is the control being bypassed.

This was not a weekend surprise

Public disclosure landed on 27 September. The campaign did not.

Mandiant and Google Threat Intelligence assess exploitation of the zero-days as ongoing since at least early September, weeks before a CVE existed. Targets include government, financial services, education, legal and professional services in North America and Europe. Mandiant’s CTO has said dozens of organisations were hit, including by suspected state-sponsored actors. Researcher Kevin Beaumont has reported awareness of more than 100 victim organisations. Early activity looks like espionage. After the bulletin and a public proof of concept, scanning and opportunistic exploitation widened.

That is the pattern with NetScaler. CitrixBleed (CVE-2023-4966) in 2023 leaked session tokens and fed ransomware intrusions at large enterprises. CitrixBleed 2 (CVE-2025-5777), disclosed in June 2025, did the same class of damage: pre-authentication memory disclosure on Gateway and AAA virtual servers, session hijack that made MFA irrelevant, then a repeatable path into ransomware. Huntress documented that chain into DragonForce deployments through the first half of 2026. The September 2026 flaws are worse in one respect. They are unauthenticated remote code execution on the appliance itself, not only a token leak.

What compromise looks like

Attackers have been gaining root on the appliance, rewriting the web server configuration, and planting webshells that run with root privileges. Public reporting describes a hidden PHP webshell under the logon custom directory (including a file named .ctxs.receiver), Apache aliases that disguise it as a stylesheet, and cron jobs used to strip forensic artefacts. GreyNoise observed attempts to set the setuid and setgid bits on /bin/sh. Mandiant reported a PHP webshell it calls WHIPSHOT and a Python tunnel it calls SLAPSHOT, used together to reach the internal network, reconnoitre, move laterally and steal credentials.

A patched NetScaler with a webshell still on it is not patched. Session tokens, Gateway cookies and nsroot material on a compromised appliance should be treated as stolen. Killing sessions after the upgrade is part of the fix, not an optional extra. Citrix’s own bulletin and blog include indicators of compromise. Read them before you declare the change window a success.

Why a vulnerability scan will not save you

Most external scans will tell you a NetScaler is present and, if you are lucky, that the build is behind. They will not tell you whether DTLS is on, whether a webshell was dropped in September, or whether the appliance has already been used as a tunnel into Active Directory. Authenticated application testing does not cover the ADC. A gateway pentest that stops at “login page works, MFA is on” misses the device underneath the login page.

The business impact is specific:

  • Remote workers and contractors authenticate through this box. A stolen session is a valid user.
  • The appliance often has line of sight to internal applications, file services and identity infrastructure.
  • Logs on NetScaler are thin, rotated quickly, and in this campaign have been tampered with. If you only keep what the appliance keeps, you may already have lost the evidence.

What to do this week

  1. Inventory every customer-managed ADC and Gateway, including FIPS, NDcPP and hybrid Secure Private Access instances. Shadow appliances in branch offices and old VPN gateways are where these linger.
  2. Upgrade to 14.1-73.37, 13.1-64.23, or the matching FIPS and NDcPP builds. If you cannot patch today, remove the appliance from the internet until you can.
  3. After the upgrade, terminate active sessions and rotate credentials that the appliance could have exposed, including local nsroot and any secrets stored on it.
  4. Hunt before you close the ticket. Look for unexpected files under /var/netscaler/logon/, modified httpd aliases, setuid on /bin/sh, new cron entries, and outbound tunnels from the appliance. Compare against Citrix’s published indicators.
  5. If the build was vulnerable at any point in September, assume compromise until the hunt says otherwise. Patching does not evict an attacker who has already had root.

The organisations that get this right are not the ones with the fastest change window. They are the ones that treat the edge device as a host, keep its logs somewhere the attacker cannot wipe, and test the thing that actually faces the internet.

Mongoose Cyber Security tests the path from an exposed NetScaler through to internal systems, including the cases a scanner marks as informational. If you want that scoped against the appliances you actually run, reach out now.

Cobras strike without warning. The mongoose strikes with intent.
‍
Don’t sit back and wait for the bite, it’s time to take the fight to the cobra.

Ready to flip the script? Let’s begin the hunt.

Request a confidential Consultation