A NetScaler can now be fully patched and still compromised. Attackers who used CVE-2026-88771 and CVE-2026-88772 before any fix existed left behind web shells (scripts that take commands over HTTP), and the upgrade is not designed to remove them. Unit 42 warns that updates "will not remove access for attackers that have already established persistence".
On Sunday 27 September 2026 Citrix issued security bulletin CTX697096 for eight vulnerabilities in NetScaler ADC and NetScaler Gateway. Two carry a CVSS v4 score of 9.5 and were being exploited as zero-days before the fixed builds came out. CISA put both in its KEV catalogue of known exploited vulnerabilities the same day and gave federal agencies until 30 September to remediate them, according to Computer Weekly.
What do CVE-2026-88771 and CVE-2026-88772 allow?
They are separate bugs that lead to one outcome: code execution on the appliance without credentials. Rapid7 describes CVE-2026-88771 as improper input validation that is reachable in a default configuration, and CVE-2026-88772 as a memory overflow that requires DTLS, the protocol securing the VPN's UDP traffic. SecurityWeek notes that DTLS is on by default for VPN virtual servers, which suggests many internet-facing Gateways meet that condition.
Google Threat Intelligence Group (GTIG) explains in its analysis how the second bug works. Malformed DTLS headers sent during the pre-authentication handshake corrupt the process's memory, leaving the attacker running code as root on the appliance's underlying FreeBSD. No user interaction is needed.
Affected releases are 14.1 before 14.1-73.37 and 13.1 before 13.1-64.23, along with FIPS and NDcPP builds before 13.1-37.279. The bulletin applies to customer-managed appliances. Citrix upgrades its own cloud services separately.
Exploitation began more than three weeks before the bulletin
When it began depends on whose telemetry you read. Taken together, the published sightings show reconnaissance from late August and confirmed exploitation from 3 September, more than three weeks before the bulletin.
- 21 and 22 August: Unit 42 sees version fingerprinting against NetScaler devices from several IP addresses.
- 3 September: the earliest activity GTIG treats as confirmed, according to Cybersecurity Dive.
- 4 to 24 September: a DTLS exploitation campaign drops web shells from infrastructure that changes daily, according to Unit 42.
- 20 September: first exploitation attempts in Rapid7's telemetry, followed by a web shell deployment on the 24th.
- 21 September: Unit 42 observes CVE-2026-88771 used against targets in the United States.
- 24 September: GreyNoise logs its first attempt, as BleepingComputer notes.
- 26 September: watchTowr posts on X about rumours of an unpatched flaw, and several administrators say they have taken appliances offline.
- 27 September: Citrix bulletin, fixed builds and KEV listing.
That same weekend, before the bulletin appeared, the Dutch National Cyber Security Centre (NCSC-NL) sent a TLP:AMBER pre-notification after hearing from a European CERT, while suppliers and response teams phoned customers and asked them to shut their NetScalers down without being able to say why. SecurityWeek and BleepingComputer both describe those calls. Whoever picked up the phone had to decide whether to cut their own remote access with nothing more to go on.
Why does the patch leave the backdoor in place?
An upgrade fixes the vulnerable code but is not a clean-up. It does not guarantee that the altered Apache configuration, the added files or the changed permissions are gone.
GTIG's analysis shows the initial payload editing /etc/httpd.conf, the configuration of the Apache server behind the portal, so that it runs files as PHP when they carry extensions that seldom get a second look: .deb, .sig, or paths dressed up as stylesheets. The web shell sits in the directories where the appliance keeps its VPN client installers and is served like any other download.
The same report names two malware families. WHIPSHOT is a PHP web shell that receives commands hidden in HTTP headers and answers with a 404 error whose body holds the real output. SLAPSHOT is a Python tunneller that relays TCP traffic into the internal network and shuts itself down after ten minutes with no sessions.
For persistence, the attacker sets the setuid bit on /bin/sh, a permission that makes the shell run with the privileges of root, its owner, whoever calls it. Then the tracks are covered: the implant strips from the logs and from /etc/crontab every line that mentions the path of its files.
Charles Carmakal, chief technology officer at Mandiant Consulting, raises a separate problem in a statement quoted by Cybersecurity Dive: stolen credentials still work after the upgrade.
How many appliances are exposed, and which need reviewing?
Unit 42 counted 50,277 NetScaler instances visible from the internet as of 27 September. The Shadowserver Foundation puts the number exposed and potentially vulnerable above 20,000, according to Cybersecurity Dive. The first counts every instance that can be seen and the second those that look vulnerable, so the two should not be added together.
As for victims, the same publication cites Arctic Wolf's count of at least 78 organisations seeing exploitation activity across the United States, Canada and Europe. GTIG and Mandiant speak of dozens, spread over government, financial services, technology, education, and legal and professional services. No one has been named: researchers suspect a state-linked actor and have tied the activity to no known group.
Our recommendation is to treat any NetScaler that has been exposed to the internet on an affected build since late August as possibly compromised until a review rules it out. Upgrading on the Sunday itself lowers the risk but does not remove it, because the targeted campaign predates the bulletin.
The Hacker News points out that the 13.1 branch reached end of maintenance on 15 September, yet Citrix still shipped a fix for it. Anyone on 13.1 has a patch today, and now has a further reason to plan the move to 14.1.
How do you check whether a NetScaler is compromised?
The UK's NCSC asks organisations to isolate affected systems and preserve forensic evidence before patching, according to Computer Weekly. An upgrade or a reboot can destroy volatile evidence (running processes, files in /tmp, logs), so take a copy of the configuration and the logs first and, on a virtual appliance, a disk snapshot.
GTIG has published detection commands and YARA rules, and Rapid7 and BleepingComputer contribute indicators of compromise of their own. The same signs come up across the reports:
AddHandler,AliasMatchorphp_flagdirectives in/etc/httpd.confthat map extensions other than.phpto the PHP engine..debor.sigfiles that turn out to be text, and.phpfiles that are not part of the install, in/var/netscaler/gui/vpn/scripts/linux/and its sibling directories. A real installer package is binary.- The
/bin/shshell with the setuid bit, shown as-rwsr-xr-xin a permissions listing. - The files
/tmp/.uxdportand/tmp/.uxdlock, or Python processes that reference them. - 404 responses several kilobytes long to requests under
/vpn/media/or/vpn/scripts/in the access logs. - DTLSv1.0 handshake failures with the reason "Handshake failure-Internal Error", and NSPPE process crashes the system does not restart.
- A hidden file named
.ctxs.receiverin/var/netscaler/logon/LogonPoint/custom/.
The attacker deletes log lines and logs rotate, so a clean result taken from the appliance itself is worth little without an external copy to compare against. That is one argument for shipping perimeter logs to a SIEM, and it is also why network edge devices are a blind spot for EDR: they take no agent and have to be watched from outside.
The review has to go beyond the NetScaler. Carmakal has said the intrusions led to lateral movement into other systems at some victims. The advice relayed by Cybersecurity Dive is to audit StoreFront servers and Delivery Controllers and to go through Windows event logs for unusual logons and Remote Desktop use. Once any of the implant signs turns up (directives, files or setuid), this is no longer maintenance but incident response, and it calls for digital forensics.
Patching, interim mitigation and credential rotation
The fix is an upgrade to 14.1-73.37 or 13.1-64.23, or the matching FIPS and NDcPP builds. No configuration change stands in for the upgrade across both flaws.
If the upgrade has to wait, GTIG suggests disabling DTLS on internet-facing Gateway virtual servers and blocking inbound UDP/443 at the upstream firewall. That covers CVE-2026-88772 alone. CVE-2026-88771 affects the default configuration and the bulletin offers no workaround for it, The Hacker News notes, which leaves restricting access by source address or taking the appliance off the internet until it can be upgraded.
If there are signs of compromise, or it cannot be ruled out, treat everything the appliance held as exposed:
- Revoke every administrative, Gateway and VPN session.
- Change NetScaler administrator passwords and SSH keys.
- Reset the passwords of LDAP bind accounts and renew RADIUS shared secrets, TACACS credentials, SNMP community strings and NITRO API credentials.
- Replace TLS certificates and their private keys.
Rapid7 saw the attackers move early to archive /flash/nsconfig, the configuration directory that holds credentials and certificates. An upgraded appliance still using the same keys remains useful to whoever copied them.
GTIG adds two hardening measures that apply to any appliance of this kind: keep the management interface unreachable from the internet and deny outbound traffic from the NetScaler by default. Entities in scope of NIS2 face one more consequence, since a confirmed compromise of remote access may qualify as a significant incident and the early-warning clock runs from the moment the entity becomes aware of it.
What is still unknown
Since disclosure Unit 42 has described wide-scale scanning and testing, and Cybersecurity Dive now writes of mass exploitation. A selective campaign that the sources associate with espionage is giving way to opportunistic use, and other kinds of actor can be expected to follow. We traced that path in our analysis of Citrix Bleed 2 and Anubis ransomware. CISA's three-day deadline is the one its binding operational directive BOD 26-04 sets for exploited flaws on exposed systems.
Attribution remains open and the tally of affected organisations is not final. Nor has anyone claimed that the persistence mechanisms described so far are the only ones. Published indicators reflect what had been seen up to 30 September, and GTIG, Rapid7 and Unit 42 are still updating their reports.
When the review of each NetScaler is closed, there should be a written record of the build installed, the date it was examined, the checks that were run and the credentials that were changed. Senior management is likely to ask for that record when it wants to know whether the organisation was among those affected, and keeping it is part of the incident response plan.
A defensive explainer based on public information available on 2 October 2026. It contains no exploit code. The paths, directives and mitigations quoted come from the linked reports: check them against the originals and test them before use in production. Versions, dates, figures and attributions may change.
Frequently asked questions
What are CVE-2026-88771 and CVE-2026-88772?
▾
Two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway, each rated 9.5 under CVSS v4, that let an attacker run code on the appliance without credentials. The first is an input validation flaw present in the default configuration. The second is a memory overflow that needs DTLS, which is on by default on VPN virtual servers. Citrix fixed both on 27 September 2026 in bulletin CTX697096.
Which NetScaler versions contain the fix?
▾
NetScaler ADC and Gateway 14.1-73.37 and later, 13.1-64.23 and later, and the 13.1-FIPS and 13.1-NDcPP builds from 13.1-37.279. Earlier builds on those branches are affected. The 13.1 branch reached end of maintenance on 15 September, so the upgrade is a sensible moment to schedule the migration to 14.1.
I have already upgraded. Is the appliance safe?
▾
Not yet. The upgrade closes these two flaws, but the attacker's edits to the Apache configuration, the planted files and the altered permissions may still be there after a new build. Unit 42 says so explicitly, and Mandiant adds that stolen credentials still work. A compromise assessment is needed and, where intrusion cannot be excluded, credentials and certificates should be rotated.
How long have these vulnerabilities been exploited?
▾
It depends on the source. Unit 42 dates preliminary fingerprinting to 21 and 22 August 2026 and DTLS exploitation to between 4 and 24 September. Google Threat Intelligence Group treats activity from 3 September as confirmed, according to Cybersecurity Dive. Rapid7 saw first attempts in its telemetry on the 20th. Citrix's bulletin is dated the 27th, so at least one of the flaws was exploited for more than three weeks with no patch available.
What are the signs that a NetScaler has been compromised?
▾
The most widely cited are directives in /etc/httpd.conf that run .deb or .sig files as PHP, text files where binary packages should be in the VPN installer directories, the setuid bit on /bin/sh, the files /tmp/.uxdport and /tmp/.uxdlock, and 404 responses of abnormal size in the access logs. Because the attacker deletes log lines, a negative result does not prove the appliance is clean.
Is there a mitigation if I cannot patch straight away?
▾
Yes, but only a partial one. Disabling DTLS on internet-facing Gateway virtual servers and blocking inbound UDP/443 reduces exposure to CVE-2026-88772. It does nothing for CVE-2026-88771, which has no workaround in the bulletin. The remaining options there are limiting access to known source addresses or disconnecting the appliance from the internet until it is upgraded.
Which credentials should be changed after a compromise?
▾
Everything the appliance stores or uses, from its own administrator logins to the secrets it presents to the directory and the authentication servers, plus the TLS certificates and their private keys. Active administrative, Gateway and VPN sessions should be revoked too. Rapid7 observed attackers copying the configuration directory where that material is kept.