NetScaler CVE-2026-88771: public exploit turns targeted attacks into mass scanning — patch and hunt now
EditorialBy TrustList Editorial
A public proof-of-concept for NetScaler ADC and Gateway flaw CVE-2026-88771 has turned targeted zero-day attacks into internet-wide exploitation. CISA’s deadline was 30 September. Patch, then hunt for web shells.
- Cybersecurity
- Cybersecurity Software
- Vulnerability Management
- Network Security
- +2 more
About NetScaler CVE-2026-88771: public exploit turns targeted attacks into mass scanning — patch and hunt now
NetScaler CVE-2026-88771: public exploit turns targeted attacks into mass scanning — patch and hunt now
30 September 2026 — When we reported the two NetScaler zero-days on 28 September, the attacks were targeted. That has changed. A root-cause analysis and a working proof-of-concept exploit for CVE-2026-88771 are now public. Researchers say attackers began scanning the whole internet for unpatched appliances within minutes of their release.
What changed since 28 September
- CVE-2026-88771 is an unauthenticated remote code execution flaw that affects all NetScaler ADC and Gateway deployments. Help Net Security reports it can be exploited remotely on unpatched devices in the default configuration. CVE-2026-88772, a memory overflow flaw, can lead to code execution or denial of service when DTLS is enabled.
- Lupovis told Help Net Security that its sensors saw live exploitation attempts within minutes of the proof-of-concept going public. The attempts were opportunistic scans for any exposed, unpatched appliance.
- Mandiant (Google Threat Intelligence Group), quoted by BleepingComputer, says exploitation began in early September at the latest. It hit organisations in North America and Europe in government, financial services, education, legal and professional services. The attackers gained root, installed PHP web shells disguised as image, CSS or package files, stole credentials and moved into internal networks.
- GreyNoise saw a failed exploitation attempt on 24 September, three days before Citrix disclosed the flaws.
- Censys counts about 42,000 internet-facing NetScaler ADC or Gateway hosts. It cannot tell which are vulnerable.
CISA added both CVEs to its Known Exploited Vulnerabilities catalog on 27 September with a remediation deadline of 30 September 2026 for US federal agencies.
Fixed builds
Citrix's bulletin CTX697096 lists 14.1-73.37 and later, 13.1-64.23 and later, 14.1-73.37 FIPS, and 13.1-37.279 for 13.1-FIPS and 13.1-NDcPP. It covers customer-managed appliances; Citrix is upgrading its cloud services itself. Citrix also published a detection script, but warns it "might fail to identify actual compromises".
What to do
- Patch every customer-managed NetScaler ADC and Gateway now, including instances behind Secure Private Access hybrid deployments.
- Assume compromise if an appliance was exposed and unpatched. Patching does not remove a web shell that is already there.
- Hunt with the indicators researchers have published:
- POST requests to
/nf/auth/doAuthentication.dowhose body containspitboss PPE unexpectedly died NSPPE(Lupovis); - outbound DNS lookups ending in
instances.httpworkbench.com(Lupovis); - a file named
.ctxs.receiverunder/var/netscaler/logon/LogonPoint/custom/, new Alias or AliasMatch lines in/etc/httpd.conf, and changed permissions on/bin/sh(GreyNoise); - web-server configuration that makes non-executable extensions such as .deb, .sig or .ico under
/vpn/media/run as PHP (Mandiant).
- POST requests to
- If you find anything, rebuild the appliance from a clean image. Rotate every credential, session and certificate that passed through it. Then check the internal network for lateral movement.
If a managed service provider runs your remote access, ask it in writing which build each appliance runs and whether it has done the hunt.
Sources
- Help Net Security: NetScaler zero-day exploitation escalates into mass attacks (CVE-2026-88771) — 29 September 2026
- BleepingComputer: Hackers exploit Citrix NetScaler zero-day to deploy web shells — 29 September 2026
- Citrix: NetScaler ADC and NetScaler Gateway Security Bulletin (CTX697096) — 27 September 2026
- CISA: Known Exploited Vulnerabilities Catalog (CVE-2026-88771 and CVE-2026-88772 added 27 September, due 30 September) — 27 September 2026
Categories & features
- Cybersecurity
- Cybersecurity Software
- Vulnerability Management
- Network Security
- VPN
- Remote Access
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More CybersecurityThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.