Skip to content
TrustList
News

NetScaler CVE-2026-88771: public exploit turns targeted attacks into mass scanning — patch and hunt now

Editorial

By TrustList Editorial

A public proof-of-concept for NetScaler ADC and Gateway flaw CVE-2026-88771 has turned targeted zero-day attacks into internet-wide exploitation. CISA’s deadline was 30 September. Patch, then hunt for web shells.

About NetScaler CVE-2026-88771: public exploit turns targeted attacks into mass scanning — patch and hunt now

NetScaler CVE-2026-88771: public exploit turns targeted attacks into mass scanning — patch and hunt now

30 September 2026 — When we reported the two NetScaler zero-days on 28 September, the attacks were targeted. That has changed. A root-cause analysis and a working proof-of-concept exploit for CVE-2026-88771 are now public. Researchers say attackers began scanning the whole internet for unpatched appliances within minutes of their release.

What changed since 28 September

  • CVE-2026-88771 is an unauthenticated remote code execution flaw that affects all NetScaler ADC and Gateway deployments. Help Net Security reports it can be exploited remotely on unpatched devices in the default configuration. CVE-2026-88772, a memory overflow flaw, can lead to code execution or denial of service when DTLS is enabled.
  • Lupovis told Help Net Security that its sensors saw live exploitation attempts within minutes of the proof-of-concept going public. The attempts were opportunistic scans for any exposed, unpatched appliance.
  • Mandiant (Google Threat Intelligence Group), quoted by BleepingComputer, says exploitation began in early September at the latest. It hit organisations in North America and Europe in government, financial services, education, legal and professional services. The attackers gained root, installed PHP web shells disguised as image, CSS or package files, stole credentials and moved into internal networks.
  • GreyNoise saw a failed exploitation attempt on 24 September, three days before Citrix disclosed the flaws.
  • Censys counts about 42,000 internet-facing NetScaler ADC or Gateway hosts. It cannot tell which are vulnerable.

CISA added both CVEs to its Known Exploited Vulnerabilities catalog on 27 September with a remediation deadline of 30 September 2026 for US federal agencies.

Fixed builds

Citrix's bulletin CTX697096 lists 14.1-73.37 and later, 13.1-64.23 and later, 14.1-73.37 FIPS, and 13.1-37.279 for 13.1-FIPS and 13.1-NDcPP. It covers customer-managed appliances; Citrix is upgrading its cloud services itself. Citrix also published a detection script, but warns it "might fail to identify actual compromises".

What to do

  1. Patch every customer-managed NetScaler ADC and Gateway now, including instances behind Secure Private Access hybrid deployments.
  2. Assume compromise if an appliance was exposed and unpatched. Patching does not remove a web shell that is already there.
  3. Hunt with the indicators researchers have published:
    • POST requests to /nf/auth/doAuthentication.do whose body contains pitboss PPE unexpectedly died NSPPE (Lupovis);
    • outbound DNS lookups ending in instances.httpworkbench.com (Lupovis);
    • a file named .ctxs.receiver under /var/netscaler/logon/LogonPoint/custom/, new Alias or AliasMatch lines in /etc/httpd.conf, and changed permissions on /bin/sh (GreyNoise);
    • web-server configuration that makes non-executable extensions such as .deb, .sig or .ico under /vpn/media/ run as PHP (Mandiant).
  4. If you find anything, rebuild the appliance from a clean image. Rotate every credential, session and certificate that passed through it. Then check the internal network for lateral movement.

If a managed service provider runs your remote access, ask it in writing which build each appliance runs and whether it has done the hunt.

Sources

Categories & features

  • Cybersecurity
  • Cybersecurity Software
  • Vulnerability Management
  • Network Security
  • VPN
  • Remote Access