Back to threat alerts

Citrix NetScaler Zero-Day Vulnerabilities (CVE-2026-88771 & CVE-2026-88772)

Citrix’s September 2026 security bulletin (CTX697096) resolves eight distinct vulnerabilities impacting NetScaler ADC and Gateway appliances, with severity scores ranging from CVSS 7.0 to 9.5. The bulletin is headlined by two actively exploited, maximum-severity zero-days. Because these edge devices manage remote access and hold highly sensitive cryptographic material in active memory, threat actors are leveraging these flaws to bypass authentication, harvest session tokens, and establish deep persistence within corporate networks.

Threat alert
September 28, 2026

NetScaler appliances are fundamentally designed to terminate cryptographic tunnels, balance application loads, and authenticate remote users via VPN or ICA proxy configurations. Consequently, these devices hold highly sensitive cryptographic material in active memory, including Active Directory LDAP binding credentials, SAML signing keys, user session tokens, and SSL private keys.  

When a threat actor achieves arbitrary code execution on a NetScaler appliance, they effectively bypass the entire external security perimeter. The underlying operating system is a heavily customised FreeBSD derivative. A compromise of the web management daemons or the Packet Processing Engine (PPE) grants an attacker root-equivalent access to the file system and memory space, allowing them to harvest session tokens and seamlessly bypass Multi-Factor Authentication (MFA).

The Core Vulnerabilities

CVE-2026-88771 (CVSS 9.5): Unauthenticated Remote Code Execution This flaw stems from improper input validation (CWE-20) within the HTTP/HTTPS request parsing logic of NetScaler management daemons. It requires no preconditions, authentication, or user interaction. An attacker can simply send a specially crafted web request to pass unsanitised commands directly to the underlying FreeBSD shell. Because it affects all default deployments, this vulnerability is highly susceptible to automated, internet-wide scanning and exploitation.

CVE-2026-88772 (CVSS 9.5): DTLS Memory Buffer Overflow Targeting the cryptographic data-plane, this vulnerability exploits how the NetScaler Packet Processing Engine (PPE) allocates memory for fragmented User Datagram Protocol (UDP) payloads over Datagram Transport Layer Security (DTLS). By sending malformed packets, an attacker can overflow the memory buffer, leading to Remote Code Execution (RCE) or a catastrophic Denial of Service (DoS) if the PPE crashes. DTLS is enabled by default on all VPN virtual servers, making this a widespread risk.

Additional High-Risk Flaws The bulletin also addresses CVE-2026-88773 (CVSS 9.3), a critical HTTP request smuggling vulnerability that allows attackers to bypass Web Application Firewalls (WAF) or hijack sessions, and CVE-2026-88778 (CVSS 8.8), a TCP sequence prediction flaw that permits the injection of malicious packets into unencrypted streams.

Threat Hunting and Forensic Telemetry Analysis

Because automated IoC scanners rely entirely on known signatures, advanced threat actors frequently mutate their tooling to evade static detection. Organisations must assume a breach and conduct manual forensic analysis before altering the state of the machine with patches.

‍

Manual File System Interrogation Responders should utilise native Unix shell utilities to hunt for bespoke persistence mechanisms across the NetScaler file system:

  • Search for recently modified files across critical web directories (e.g., /var/netscaler/gui and /var/vpn).
  • Scan for concealed PHP execution tags (<?php) hidden within disguised file extensions like image or text files.
  • Locate unexpected script extensions (.sh, .py, .pl, .cgi) occupying world-writable GUI directories.
  • Audit the crontab (crontab -l, cat /etc/crontab) for unauthorised scheduling established by the web daemon, and inspect SSH configurations for rogue public keys.
    ‍

Log Analysis for Session Hijacking To detect lateral movement and session hijacking, analysts must scrutinise TCPCONNSTAT events within the native /var/log/ns.log file structure. This log records the parameters of SSLVPN connections. Look for a stark mismatch between the Client_ip (the originating IP where the session was established) and the Source (the IP address of the active connection). While some mobility is normal, abrupt changes involving disparate Autonomous System Numbers (ASNs) or foreign geolocations are highly indicative of compromised, exfiltrated session tokens being replayed.

SIEM Telemetry Enhancements Default NetScaler logging is often insufficient to capture the granular authentication responses required to detect advanced exploitation. Administrators must explicitly configure the appliance via the CLI to forward debug-level telemetry and session logging to their Security Information and Event Management (SIEM) platform. This central aggregation is vital for baselining normal geographic access patterns and rapidly alerting on deviations.

Affected Versions and Patch Management

The vulnerabilities affect both standard commercial branches and the hardened FIPS/NDcPP variants. Immediate remediation requires applying updated firmware builds across all vulnerable appliances.

Product Family Vulnerable Versions Fixed Release (Minimum Required)
NetScaler ADC & Gateway 14.1 Prior to 14.1-73.37 14.1-73.37 and later releases
NetScaler ADC & Gateway 13.1 Prior to 13.1-64.23 13.1-64.23 and later releases
NetScaler ADC 14.1-FIPS Prior to 14.1-73.37 FIPS 14.1-73.37 FIPS and later releases
NetScaler ADC 13.1-FIPS & NDcPP Prior to 13.1-37.279 13.1-37.279 and later releases

Note: End-of-Life (EOL) product branches, specifically NetScaler versions 12.1 and 13.0, are unequivocally vulnerable and will not receive security patches. Organisations operating EOL appliances must execute a disruptive branch upgrade to 13.1 or 14.1 immediately.

‍

Strategic Recommendations and Mitigations

Patching the appliance is only the first step in containment. If an appliance was compromised prior to the update, the threat actor likely exfiltrated active session tokens or configuration secrets. Security teams must assume a breach and execute the following remediation strategy:

  • Execute Forensic Triage Before Patching: Do not apply firmware updates blindly. Capture a complete hypervisor snapshot, extract technical support bundles, and preserve all core dumps. Applying a patch immediately can overwrite volatile memory and destroy crucial forensic evidence. Use the NetScaler Console to run Indicators of Compromise (IoC) scans.
  • Apply Firmware Updates (Mind the 13.1 Reboot Loop): Upgrade to the fixed firmware builds immediately (e.g., 14.1-73.37 or 13.1-64.23).
    • ‍Warning: Administrators applying the 13.1-64.23 patch must first check the ns.conf file using the show ns variable command. If variables are present, applying 64.23 will cause an infinite reboot loop; administrators must deploy the specifically compiled 13.1-64.24 build instead. Note: End-of-Life versions 12.1 and 13.0 remain vulnerable and must be upgraded to a supported branch.
  • Enforce Global Session Invalidation: Immediately after rebooting the patched appliance, forcefully terminate all active VPN and ICA sessions using the CLI commands kill icaconnection -all and kill vpn -all. This renders any stolen session tokens entirely useless.
  • Execute Comprehensive Credential Rotation: Rotate all service accounts, LDAP binding credentials, RADIUS shared secrets, and administrative passwords stored in the ns.conf file. Additionally, reset the passwords of any users who authenticated during the active exploitation window.
  • Revoke Cryptographic Assets: Because the NetScaler acts as the TLS termination point, its SSL/TLS private keys must be considered compromised. Revoke the existing certificates and reissue new ones via your Certificate Authority (CA).
  • Isolate Management Interfaces: Rigorously segregate the NetScaler Management Interface (NSIP) from the public internet. Restrict administrative access to dedicated Out-of-Band (OOB) networks protected by Multi-Factor Authentication (MFA).
  • Harden TCP Parameters: To fully mitigate CVE-2026-88778, administrators must manually enable the Enhanced ISN Generation parameter via the CLI, as simply applying the firmware patch will not remediate this specific cryptographic weakness.