CyberPeople

Critical 0-day Vulnerabilities in Citrix NetScaler ADC and Gateway: What We Know

Citrix NetScaler: Critical 0-day RCE Vulnerabilities Actively Exploited

Two critical 0-day RCE vulnerabilities in Citrix NetScaler (CVE-2026-88771, CVE-2026-88772) are actively exploited. Which versions are vulnerable and how to check your system.

What happened

On September 27, 2026, Citrix published security bulletin CTX697096, disclosing eight vulnerabilities in Citrix NetScaler ADC and Citrix NetScaler Gateway. Two of them proved critical: CVE-2026-88771 and CVE-2026-88772 are 0-day remote-code-execution (RCE) vulnerabilities that hackers had been actively exploiting even before the vendor officially disclosed the problem.

NetScaler ADC is an application-delivery and network-traffic security platform, while NetScaler Gateway is a secure remote-access and VPN solution. It is through such devices that employees connect to internal corporate networks, so compromising the gateway effectively opens a direct path into the organization's network. Such gateways are widely used by banks, government agencies, telecom operators, and large companies — exactly the organizations for which losing control of a remote-access point means a serious incident.

The situation is worsened by the fact that attacks began long before patches were published. According to researcher Kevin Beaumont, European government sources had been warning organizations about active attacks all week, and the exploitation ran through all of September. Signs point to a well-resourced, likely state-linked group whose goal is espionage, not ordinary extortion.

The two critical 0-days: technical breakdown

Both critical vulnerabilities carry the maximum CVSSv4 score of 9.5.

CVE-2026-88771 is a remote-code-execution vulnerability caused by improper input validation (CWE-20). It allows an unauthenticated attacker to execute arbitrary commands on the device. Worst of all, the vulnerability triggers on devices in default configuration, with no additional features enabled. The vendor notes the exploitation complexity is low, meaning a reliable attack is possible against any vulnerable device regardless of settings. This makes CVE-2026-88771 especially dangerous given NetScaler's wide deployment.

CVE-2026-88772 is a memory-corruption vulnerability (CWE-119) that can lead to remote code execution or denial of service. Exploitation requires the DTLS feature to be enabled — and it is enabled by default on virtual VPN servers. Attack complexity here is rated high, so reliable exploitation is harder than with CVE-2026-88771.

Importantly, both vulnerabilities can be exploited independently. As the Dutch National Cyber Security Centre (NCSC-NL) stresses, CVE-2026-88771 gives the attacker full control over the gateway and direct access to the internal corporate network behind it.

For readers unfamiliar with vulnerability classifications: "improper input validation" (CWE-20) means the device doesn't properly check what an attacker sends it and executes the commands passed; "memory corruption" (CWE-119) means the program writes data outside its allocated memory region, allowing its logic to be hijacked. Both types are classics in network-device attacks, and both, in NetScaler's case, lead to full takeover.

Network gateway security

The other six vulnerabilities in the bulletin

Besides the two critical 0-days, Citrix fixed six more vulnerabilities of varying severity:

  • CVE-2026-88773 (CVSS 9.3) — HTTP request smuggling, triggered when an HTTP configuration is enabled on the device.
  • CVE-2026-88774 (CVSS 7.0) — policy bypass through improper use of HTTP URL-based expressions.
  • CVE-2026-88775, CVE-2026-88776, CVE-2026-88777 (CVSS 8.8) — memory corruption leading to unpredictable behavior or denial of service, depending on configuration (Gateway/AAA, Oracle-type load balancer, LB/CS or CGNAT/NAT64).
  • CVE-2026-88778 (CVSS 8.8) — predictability of TCP initial sequence numbers (ISN).

Although confirmed active exploitation was recorded only for the first two, all eight should be closed in one update — it is available in a single set of fixed builds.

Who is behind the attacks and their scale

The US Cybersecurity and Infrastructure Security Agency (CISA) added both 0-days to its Known Exploited Vulnerabilities (KEV) catalog on September 27, confirming attacks are occurring worldwide. US federal civilian agencies were ordered to remediate by September 30 and run forensic checks for signs of compromise. National and sectoral CERTs worldwide, including CERT-EU and HKCert, followed with warnings.

Researcher Kevin Beaumont characterized the attacks as likely state-linked and well-resourced, with espionage goals rather than ordinary extortion. According to Tenable, roughly two-thirds of threat activity targeting Citrix NetScaler over the past seven years has been tied to APT groups, and a third to ransomware groups and their affiliates. In other words, NetScaler consistently attracts the most serious players.

The first alarm signals appeared as early as September 26: watchTowr publicly warned about vulnerabilities being exploited "in the wild," and NetScaler administrators began receiving instructions from vendors and security teams to shut devices down — after a private warning from the Dutch NCSC-NL. The next day Citrix published the bulletin and patches.

Why compromising a VPN gateway is dangerous

A VPN gateway and load balancer are the doors into an organization's network, which is exactly why they are so valuable to attackers. After gaining remote code execution on such a device, an attacker typically follows a classic playbook:

  1. Persistence. Install a webshell or other backdoor to retain access even after a reboot or partial response.
  2. Reconnaissance. Study the device configuration, harvest credentials, certificates, and information about the internal network.
  3. Lateral movement. Use the compromised gateway as a beachhead to move inward — to servers, databases, and workstations.
  4. Collection and exfiltration. Extract confidential information or prepare the ground for further actions, such as a ransomware attack.

In the current NetScaler attacks, researchers recorded exactly this behavior: device-unique webshells and active trail-destruction via anti-forensics commands. This means a quick visual check is unlikely to reveal a compromise — methodical forensic analysis is required.

Special attention is warranted because a remote-access gateway often has access to internal resources that are never exposed externally. So a compromised NetScaler is not just a "hacked device" but a potential entry point to the entire internal perimeter.

VPN gateway compromise

Which versions are vulnerable and how to update

The vulnerability affects customer-managed (self-managed) deployments of NetScaler ADC and NetScaler Gateway. Hybrid Secure Private Access deployments using NetScaler are also affected.

Vulnerable versions:

  • NetScaler ADC and Gateway 14.1 — before build 14.1-73.37;
  • NetScaler ADC and Gateway 13.1 — before build 13.1-64.23;
  • NetScaler ADC 14.1-FIPS — before 14.1-73.37 FIPS;
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP — before 13.1-37.279.

Minimum fixed builds:

  • 14.1-73.37 and later;
  • 13.1-64.23 and later in the 13.1 branch;
  • 14.1-73.37 FIPS and later;
  • 13.1-37.279 and later for FIPS/NDcPP.

There is no workaround — the only protection is updating to a fixed build. Experts, including Rapid7, advise emergency updates outside the normal patching cycle. Note: devices updated for the previous vulnerability CVE-2026-19490 remain vulnerable unless updated to the fixed builds from this bulletin.

How to check whether you were already breached

Since the attacks went on for weeks, updating alone is not enough — you must check whether the device was already compromised. Hackers installed webshells (unique per device) on breached devices and ran anti-forensics commands.

What to do:

  • Save memory dumps and logs for at least the last month — NCSC-NL advises doing this before applying updates.
  • Check SIEM logs for base64 strings immediately after the User-Agent field (no space) and entries with the string "pitboss" together with "IFS" (pattern pitboss*IFS or pitboss*b64decode).
  • Note: Citrix's standard verification script via NetScaler Console only works if the logs on the device haven't rotated since the attack — and over several weeks they most likely have.
  • Citrix itself warns that its indicators of compromise may fail to detect real breaches and advises engaging experienced forensic specialists.

Additionally, check whether your employees' credentials have appeared in public breaches — use our free data-breach check tool.

Even if no direct signs of compromise are found, keep watching the device for several more weeks after updating: compromised gateways can contain hidden re-access mechanisms that activate later. NCSC-NL separately advises monitoring suspicious traffic and anomalous activity even after updating.

Server patch and update

How to protect yourself: practical tips

Besides the emergency update, implement systemic measures that reduce the risk of similar attacks in the future:

  1. Inventory and visibility. Make sure all internet-facing network devices (VPN gateways, load balancers, ADC) are accounted for and monitored. Unknown "forgotten" devices are the attacker's first target.
  2. Restrict access. Close administrative interfaces from the internet, use IP allowlists and multi-factor authentication for management access.
  3. Network segmentation. A gateway compromise should not give direct access to the whole internal network — separate critical systems.
  4. Monitoring and logs. Collect logs from network devices into SIEM and set alerts for anomalous activity.
  5. Backups and an incident-response plan. Have an incident plan and regularly test backups.
  6. Out-of-band patching. For critical edge devices (VPN gateways, ADC, firewalls), keep a separate accelerated update process that doesn't wait for the monthly change window. 0-days on such devices are exactly the case where speed matters more than the usual routine.
  7. Staff training. Many incidents start with the human factor. Regular cyber-hygiene training for administrators and ordinary users reduces the chance an attack gets its initial foothold.

This is not the first time Citrix NetScaler vulnerabilities have been actively exploited right after disclosure: earlier in September, CVE-2026-19490 entered the KEV catalog. Such devices remain an attractive target, so patching must be fast and continuous. To deepen your team's foundational cybersecurity knowledge, see our piece on learning cybersecurity from scratch.

Conclusion

Two critical 0-day RCE vulnerabilities in Citrix NetScaler ADC and Gateway, exploited for weeks before patches were published, are a serious signal for anyone managing corporate VPN gateways and load balancers. The main thing now is to update to the fixed builds (14.1-73.37+, 13.1-64.23+ and the corresponding FIPS/NDcPP) and simultaneously check devices for signs of compromise — because updating alone doesn't remove an already-installed webshell.

If you're responsible for infrastructure, don't postpone the update — there is no workaround, and the attacks are already underway.

Stay ahead of threats

Weekly cybersecurity intelligence in your inbox. No spam.

CyberPeople contributor