What is Citrix NetScaler?
NetScaler ADC (formerly Citrix ADC) is an application delivery controller: a network appliance that sits at the edge of an enterprise network doing load balancing, SSL termination, web application firewalling, and traffic shaping. NetScaler Gateway is the remote-access mode of the same platform, providing VPN and single sign-on for employees reaching internal applications. Both roles put the appliance directly on the internet, in front of everything else, holding TLS private keys, Active Directory service credentials, and live user sessions. That combination is why NetScaler has been a repeat target: compromising one appliance can hand an attacker an authenticated foothold inside the network without touching a single endpoint.
Overview
CVE-2026-88771 is an unauthenticated command injection in NetScaler ADC and NetScaler Gateway. An attacker who can reach the appliance's web interface can cause arbitrary shell commands to run as root, with no credentials, no user interaction, and no non-default feature enabled. Citrix rates it 9.5 Critical under CVSS 4.0; NVD scores it 9.8 under CVSS 3.1.
Citrix disclosed the flaw on 2026-09-27 in bulletin CTX697096, which covers eight NetScaler vulnerabilities (CVE-2026-88771 through CVE-2026-88778). Two of the eight, this one and CVE-2026-88772, were already being exploited as zero-days. The disclosure was unusually chaotic: administrators were being told by national CERTs and suppliers to shut appliances down before any vendor advisory existed. NCSC-NL, the Dutch national cyber security centre, issued a private pre-notification on 2026-09-26 after receiving information from a partner CERT indicating exploitation at multiple Citrix customers worldwide. Citrix filed a notification under the EU Cyber Resilience Act.
What makes this one worse than a typical NetScaler bug is the absence of preconditions. CVE-2026-88772 requires DTLS; the other six in the bulletin depend on specific configurations. CVE-2026-88771 affects every deployment on an affected build in its default configuration. Researcher Kevin Beaumont noted that European government sources had been warning organizations all week and that the attacks had been unfolding through the whole month, meaning exploitation predates the patch by weeks.
Affected Versions
| Product | Vulnerable | Fixed |
|---|---|---|
| NetScaler ADC and NetScaler Gateway 14.1 | before 14.1-73.37 | 14.1-73.37 and later |
| NetScaler ADC and NetScaler Gateway 13.1 | before 13.1-64.23 | 13.1-64.23 and later |
| NetScaler ADC 14.1 FIPS | before 14.1-73.37 FIPS | 14.1-73.37 FIPS and later |
| NetScaler ADC 13.1 FIPS / NDcPP | before 13.1-37.279 | 13.1-37.279 and later |
Branches that have reached end of life receive no fix and must be migrated to a supported build.
Technical Details
The root cause is CWE-20, improper input validation, in a Perl helper script on the appliance (ns_monuploadd_err.pl) that parses log files. The script extracted fields from log lines using a shell pipeline of grep, sed, and awk invoked through backtick interpolation, without strict pattern matching on what it pulled out. Anything that lands in those logs is therefore treated as shell syntax.
Exploitation is two-stage and does not require authentication. First an attacker sends an unauthenticated request to a logging endpoint, for example a POST to /nf/auth/doAuthentication.do with shell metacharacters (semicolons, backticks, redirects) embedded in the login parameter. The request fails authentication, which is the point: the failure is written to the log. Second, when the monitoring daemon next processes that log, the injected metacharacters are executed as root. The delay can be up to 24 hours, though the daemon can be forced to run sooner. Failed logins are not the only sink: request parameters, rate-limit block records, and User-Agent headers also reach the affected logs, giving an attacker several routes to poison them.
The fix in 14.1-73.37 replaces the shell-based parsing with strict regular expression validation. watchTowr reconstructed the vulnerability by diffing the vulnerable 14.1-73.30 build against the patched one.
Discovery
Citrix has not publicly credited an outside researcher. Per the NCSC-NL pre-notification, Citrix identified the vulnerabilities while investigating customer security incidents, making this a discovery driven by incident response rather than proactive research. Information reached NCSC-NL through a European partner CERT, which had confirmed exploitation at multiple Citrix customers worldwide, and NCSC-NL warned Dutch organizations on 2026-09-26, roughly a day before Citrix published. watchTowr, whose CEO Benjamin Harris and threat intelligence specialist Yordan Ganchev publicly confirmed exploitation ahead of the advisory, published the first technical reconstruction after patches shipped.
Exploitation Context
Citrix confirmed exploitation against unmitigated deployments and acknowledged that webshells were planted on compromised appliances. CISA stated that threat actors are exploiting these vulnerabilities globally. Exposure is large: Shadowserver counted more than 20,000 exposed NetScaler instances as of 2026-09-28, and Palo Alto Networks Cortex Xpanse counted over 50,277 exposed instances on 2026-09-27. Confirmed compromises, by contrast, were described by researchers as real but not yet widespread, which is consistent with targeted use rather than mass scanning.
No named threat actor has been attributed. Beaumont assessed the operators as probably nation-state aligned and well resourced, espionage rather than opportunistic. Tenable noted that historically around two-thirds of NetScaler-targeting activity has involved APT groups. CVE-2026-88771 and CVE-2026-88772 are independent vulnerability classes and there is no public evidence they are chained; either alone yields code execution.
Remediation
- Upgrade to 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, or 13.1-37.279 as applicable. There is no workaround. Patching is the only fix.
- Investigate before you patch. Citrix and CISA both warn that updating can destroy forensic evidence. Capture logs, configuration, and disk state first if compromise is plausible.
- Run the IOC check. NetScaler Console 14.1-73.36 or later with telemetry enabled exposes an IOC scan on the Security Advisory page. Citrix cautions that the IOCs do not cover every technique, so a clean result is not proof the appliance is uncompromised.
- Assume the appliance is compromised if it was internet-facing and unpatched during September 2026. Follow Citrix CTX694799: rotate all credentials the appliance held or could see, replace TLS certificates and keys, terminate all active sessions, and reset local accounts.
- Review logs for unexpected outbound connections from the appliance, unexplained gaps in logging, new or modified files in web-accessible paths, and administrative sessions you cannot account for.
- Restrict management interface exposure to a dedicated management network. The data plane must stay reachable, but NSIP and management access should never be internet-facing.
- Federal civilian agencies were required to remediate by 2026-09-30 under BOD 26-04, a three-day window that reflects the severity of active exploitation, and to perform the forensic triage the directive specifies.
Key Details
| Property | Value |
|---|---|
| CVE ID | CVE-2026-88771 |
| Vendor / Product | Citrix — NetScaler |
| NVD Published | 2026-09-27 |
| NVD Last Modified | 2026-09-28 |
| CVSS 3.1 Score | 9.8 |
| CVSS 3.1 Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Severity | CRITICAL |
| CWE | CWE-20 find similar ↗ |
| CISA KEV Added | 2026-09-27 |
| CISA KEV Deadline | 2026-09-30 |
| Known Ransomware Use | No |
CVSS 3.1 Breakdown
Required Action
Timeline
| Date | Event |
|---|---|
| 2026-09-26 | NCSC-NL privately warns customers; watchTowr publicly reports in-the-wild exploitation of an unnamed NetScaler zero-day |
| 2026-09-27 | Citrix publishes security bulletin CTX697096 with fixed builds; CVE record published |
| 2026-09-27 | CISA issues alert and adds CVE-2026-88771 to the Known Exploited Vulnerabilities catalog |
| 2026-09-30 | CISA BOD 26-04 remediation deadline |
References
| Resource | Type |
|---|---|
| NVD - CVE-2026-88771 | Vulnerability Database |
| CISA KEV Catalog Entry | US Government |
| Citrix Security Bulletin CTX697096 - CVE-2026-88771 through CVE-2026-88778 | Vendor Advisory |
| Citrix CTX694799 - Steps to Take if NetScaler ADC is Suspected of Compromise | Vendor Advisory |
| CISA Alert - Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway | US Government |
| watchTowr Labs - Citrix NetScaler PreAuth Command Injection CVE-2026-88771 | Security Research |
| Rapid7 - Zero-Day Exploitation of Citrix NetScaler ADC and Gateway | Security Research |
| Unit 42 Threat Brief - NetScaler Zero Days Exploited in the Wild | Security Research |
| Help Net Security - Citrix NetScaler RCE Zero-Days Exploited Globally for Weeks | News |
| Cybersecurity Dive - Citrix Urges Immediate Upgrades Amid Widespread Exploitation | News |