Citrix patched two exploited NetScaler zero-days, CVE-2026-88771 and CVE-2026-88772, but a public PoC brought mass exploitation and backdoors that outlive the patch. Fixed builds, hunting checks and what to rotate.

Two zero-days in Citrix NetScaler ADC and NetScaler Gateway went from quiet espionage to mass exploitation in under a week. Citrix fixed them on September 27, 2026 in security bulletin CTX697096, which also fixes six other flaws. Two days later watchTowr published a proof of concept, and GreyNoise saw exploitation attempts start "within minutes", TechTimes reports.
That same week brought the finding that changes how admins have to respond. A Mandiant and Google Threat Intelligence Group report, published September 29-30, says attackers have exploited one of the flaws since at least early September. They planted backdoors that a firmware update does not remove. Patching closes the door. It does not evict anyone already inside.
NetScaler Gateway is the remote-access front door for a large share of enterprise and government networks. This is its third major incident in four years, after CitrixBleed (CVE-2023-4966) in 2023 and CitrixBleed 2 (CVE-2025-5777) in 2025, and both of those were later used by ransomware crews. So far, CISA lists ransomware use of the two new CVEs as "Unknown".

Photo: Bz3rk, CC BY-SA 3.0, via Wikimedia Commons
For anyone running one, the before and after is stark. On September 26, installing the fix was the whole job. As of October 1, 2026, any NetScaler that faced the internet in September has to be treated as possibly compromised. That means patching, then hunting, then rotating every secret the appliance held. Mandiant CTO Charles Carmakal told SecurityWeek he expects "broad and opportunistic exploitation...by a variety of threat actors in the near term".
The exposed population is large, though the counts depend on who did the counting. Palo Alto Networks' Cortex Xpanse found more than 50,277 internet-exposed, potentially vulnerable instances. Shadowserver, counting by IP address, found more than 23,000: about 22,000 ADC and 1,500 Gateway. A scan by researcher Kevin Beaumont on September 29 found fewer than 10% of exposed hosts patched. CISA added both CVEs to its Known Exploited Vulnerabilities catalog on September 27 and gave federal agencies three days to act, until September 30, under BOD 26-04.
Both flaws score 9.5 on CVSS v4, but they work differently, and each needs its own stopgap until the patch is in.

Photo: Jemimus, CC BY 2.0, via Wikimedia Commons
| CVE-2026-88771 | CVE-2026-88772 | |
|---|---|---|
| Type | Improper input validation (CWE-20), pre-auth command injection via log poisoning | Memory overflow (CWE-119) in DTLS handling |
| Requires | Nothing beyond the default configuration | DTLS enabled, the default on VPN virtual servers |
| Attack complexity | Low | High |
| Result | Arbitrary commands, no login needed | Root shellcode on the appliance, or a crash |
Mandiant tied the DTLS bug to the weeks-long campaign. An attacker sends malformed, fragmented DTLS record headers over UDP/443. These corrupt heap memory in the NetScaler Packet Processing Engine (NSPPE) and run shellcode as root on the appliance's FreeBSD base. The engine crashes in the process, and the crash leaves log entries worth searching for: "Handshake failure-Internal Error" with ClientVersion DTLSv1.0, and pitboss messages about "NOT restarting NSPPE".
The public PoC made the command-injection bug easy to use. Rapid7 saw attempts from September 20 and a web shell deployed on September 24, and it confirmed two organizations compromised through this flaw. In one attack, the payload copied /flash/nsconfig to a web-reachable folder. That exposed ns.conf with its encrypted admin passwords, the TLS certificates and private keys, and the SSH host keys.
The sources don't agree on when exploitation started. Mandiant says early September at the latest for CVE-2026-88772, Rapid7's earliest attempts date to September 20, and GreyNoise's to September 24. watchTowr founder Benjamin Harris noted that the patch was "dated September 24", which suggests Citrix knew about the attacks days before it disclosed them. Beaumont called the original campaign "likely nation-state aligned and espionage-focused". No threat actor has been named.
Mandiant named two new tools. WHIPSHOT is a PHP web shell that hides Base64-encoded commands in HTTP headers (X-UX, NSC_LDAP and NSC_CLIENTTYPE). It answers with HTTP 404 while carrying the tunneled data in the response body, so a quick log review sees only failed requests. SLAPSHOT is a Python TCP tunneler bound to 127.0.0.1 that leaves /tmp/.uxdport and /tmp/.uxdlock behind. Together they turn the appliance into a bridge into the internal network.

Image: Google Threat Intelligence Group
The persistence lives in configuration files, not firmware, which is why patching doesn't remove it. Attackers rewrote /etc/httpd.conf so that .deb files in the VPN scripts folder, or .sig files served through /vpn/media/*.ico URLs, run as PHP. They also ran chmod u+s /bin/sh, which gives the web server root. A firmware update replaces the vulnerable code and leaves all of that in place. Mandiant's indicators include 143.198.7.94 (scanning and staging) and 157.254.167.12 (exploitation). The victims Mandiant has seen are in North America and Europe, in government, financial services, technology, education, and legal and professional services. SecurityWeek puts the count at dozens to more than 100 organizations.
Start with the upgrade. NetScaler ADC and Gateway need 14.1-73.37 or 13.1-64.23 or later. The 14.1 FIPS build needs 14.1-73.37 FIPS, and 13.1-FIPS and 13.1-NDcPP need 13.1-37.279. Versions 12.1 and 13.0 are end-of-life and get no fix, so an appliance on either needs a new major version, not a patch. The bulletin covers customer-managed appliances only: Cloud Software Group, Citrix's parent company, is upgrading Citrix's cloud services and cloud-managed Adaptive Authentication itself.

Screenshot: Tenable
Then assume September went badly. Snapshot the appliance before you reboot it so the evidence survives, and check the three places the backdoors live:
grep -En -i "application/x-httpd-php|php_flag|AliasMatch" /etc/httpd.conf for the PHP handler rewritels -l /bin/sh for a setuid bitls -la /tmp/.uxdport* /tmp/.uxdlock for SLAPSHOTWhatever those checks find, revoke admin, Gateway, VPN and ICA/HDX sessions. Then rotate everything the appliance held: admin and local accounts, SSH keys, TLS certificates and private keys, LDAP bind accounts, RADIUS shared secrets, TACACS and SNMP credentials, and NITRO API credentials. Given that ns.conf was stolen in at least one case, the private keys deserve special attention: reissuing certificates takes far longer than a firmware update. If you can live without DTLS, disable it or block inbound UDP/443, and keep the NSIP management interface off the internet. watchTowr also recommends turning on Enhanced ISN Generation for CVE-2026-88778, a TCP sequence-prediction bug fixed in the same bulletin.
The next wave is likely to be opportunistic: a public PoC is out, and fewer than one in ten exposed hosts were patched as of the last scan. Expect access brokers and, if CitrixBleed is any guide, ransomware crews. More than 100 organizations already have unique web shells documented. According to Tenable, roughly two-thirds of threat activity against NetScaler over the past seven years involved APT groups, and CISA's catalog now lists 13 NetScaler-related flaws. Lupovis CEO Xavier Bellekens summed it up: "If you run NetScaler and you haven't patched, assume you are already being probed." If you patched after early September, assume more than that.
