Citrix NetScaler Hit by Twin Pre-Auth RCE Zero-Days Under Attack

SOC Briefing Summary :: Executive Key Takeaways
- [01]Citrix NetScaler ADC and Gateway appliances face active, in-the-wild exploitation of twin critical zero-day flaws (CVE-2026-88771 and CVE-2026-88772, CVSS 9.5) enabling unauthenticated remote code execution.
- [02]CVE-2026-88771 stems from improper input validation in HTTP traffic endpoints; CVE-2026-88772 is a pre-auth buffer overflow in the DTLS stack listening on UDP port 443.
- [03]Upgrade immediately to NetScaler builds 14.1-73.37 or 13.1-64.23; if patching is delayed, disable DTLS on all VPN virtual servers or isolate edge appliances from public routing.
Executive Summary
Citrix and the Cloud Software Group have officially issued an emergency security advisory confirming active in-the-wild exploitation of two critical zero-day vulnerabilities in NetScaler ADC (formerly NetScaler Application Delivery Controller) and NetScaler Gateway. Tracked as CVE-2026-88771 and CVE-2026-88772, both flaws carry a critical severity rating of CVSS v3.1 9.5 and allow unauthenticated, remote attackers to achieve arbitrary code execution and trigger severe appliance memory corruption without any user interaction.
Prior to Citrix's coordinated public advisory, corporate network administrators, managed service providers, and critical infrastructure operators reported receiving confidential emergency warnings from national cybersecurity agencies—including the Dutch National Cyber Security Centre (NCSC) and regional law enforcement—advising organizations to immediately sever internet connections to exposed NetScalers if offline maintenance windows could not be scheduled instantly. The Cybersecurity and Infrastructure Security Agency (CISA) has added both vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog pursuant to Binding Operational Directive (BOD) 22-01, signaling wide-scale adversary campaigns across government, healthcare, financial, and enterprise perimeters.
Because NetScaler appliances sit directly on the enterprise perimeter terminating SSL/TLS sessions and brokering remote virtual desktop infrastructure (VDI), compromise grants adversaries unfettered access into internal subnets, active authentication sessions, and Active Directory domains.
Technical Vulnerability Analysis & Attack Chain

1. CVE-2026-88771: Unauthenticated Input Validation Command Execution (CVSS 9.5)
- Vulnerability Mechanism: CWE-20 (Improper Input Validation).
- Attack Vector: Network / Pre-Authentication.
- Root Cause: The web-handling daemon servicing administrative and client routing interfaces improperly sanitizes inbound HTTP request parameters before passing execution handles to underlying system utilities. By submitting crafted HTTP requests to exposed NetScaler endpoints, an unauthenticated remote attacker can inject arbitrary shell syntax.
- Operational Impact: Arbitrary command execution under the privileges of the local web server process (
nobodyor FreeBSD daemon context). Attackers leverage this primitive to drop interactive PHP/Python web shells, deploy persistent cron scripts, and establish reverse TCP tunnels into internal bastion networks.
2. CVE-2026-88772: Pre-Authentication DTLS Memory Overflow & RCE (CVSS 9.5)
- Vulnerability Mechanism: CWE-120 (Classic Buffer Overflow) / CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer).
- Attack Vector: Network / UDP Port 443 (DTLS).
- Root Cause: The NetScaler Packet Processing Engine (
nsppe) implements Datagram Transport Layer Security (DTLS) to accelerate Citrix Gateway VPN user sessions over UDP. An unchecked buffer boundary in the DTLS handshake parsing logic fails to enforce payload length restrictions when processing malformed initial handshake packets. - Operational Impact: An unauthenticated attacker transmitting crafted UDP packets to port 443 can overwrite adjacent memory blocks in the
nsppeheap. This leads to either instantaneous service crashes (Denial of Service) or arbitrary pre-authentication remote code execution with kernel/system-level control. Because DTLS is enabled by default on all NetScaler Gateway VPN virtual servers, vast numbers of global edge deployments are vulnerable in their out-of-the-box configuration.
MITRE ATT&CK Tactics, Techniques & Procedures (TTPs)
| Tactic | Technique ID | Technique Name | Operational Context |
|---|---|---|---|
| Initial Access | T1190 | Exploit Public-Facing Application | Remote weaponization of CVE-2026-88771 and CVE-2026-88772 against perimeter NetScalers on TCP/UDP 443. |
| Execution | T1059.004 | Command and Scripting Interpreter: Unix Shell | Execution of arbitrary FreeBSD commands and staging scripts under nobody or elevated daemon context. |
| Persistence | T1505.003 | Server Software Component: Web Shell | Infiltration of rogue web shell binaries and scripts into /netscaler/ns_gui/ and /var/vpn/. |
| Defense Evasion | T1070.002 | Indicator Removal: Clear FreeBSD System Logs | Adversaries zero or purge /var/log/httpaccess.log and rotate ns.log to obscure exploitation artifacts. |
| Credential Access | T1003.001 | OS Credential Dumping: Memory Scrapes | Extraction of plaintext LDAP service account passwords and active user session tokens from nsppe process memory. |
| Lateral Movement | T1021.002 | Remote Services: SMB / Windows Admin Shares | Leveraging hijacked NetScaler Active Directory bind credentials to pivot into internal corporate domain controllers. |
| Command and Control | T1071.001 | Application Layer Protocol: Web Traffic | Establishing persistent HTTPS/WSS reverse beacons from NetScaler appliances to external adversary infrastructure. |
Threat Actor Profile & Campaign Attribution
Telemetric analysis and telemetry from European CERTs and US threat research teams attribute initial weaponization of these zero-day flaws to sophisticated state-sponsored advanced persistent threat (APT) groups focusing on espionage and prepositioning. Historical precedents—such as Citrix Bleed (CVE-2023-4966) and NetScaler ADC RCE (CVE-2023-3519)—indicate that state-sponsored actors typically harvest credentials and implant stealth backdoors during the initial zero-day window before releasing proof-of-concept code into underground cybercrime forums.
Within 48 hours of initial telemetry, financially motivated ransomware affiliates (including groups deploying Akira, LockBit variants, and Medusa) were observed scanning global IP blocks for unpatched NetScaler SSL-VPN endpoints. Once established on the NetScaler appliance, threat actors dump volatile memory to extract Active Directory bind accounts and Kerberos tickets, enabling complete domain escalation within hours of initial ingress.
Detection & SOC Mitigation Playbook
1. Patch & Workaround Guidance
Organizations operating NetScaler ADC or NetScaler Gateway must upgrade to the official security releases immediately. Citrix has made the following patched builds available:
- NetScaler ADC and Gateway 14.1: Upgrade to 14.1-73.37 or later.
- NetScaler ADC and Gateway 13.1: Upgrade to 13.1-64.23 or later.
- NetScaler ADC FIPS 14.1: Upgrade to 14.1-73.37 FIPS or later.
- NetScaler ADC FIPS / NDcPP 13.1: Upgrade to 13.1-37.279 or later.
[!CAUTION]
NetScaler version 13.0 and version 12.1 are End-of-Life (EOL). If your organization is running an EOL release, you cannot apply a patch; you must immediately migrate to a supported build or decommission the appliance.
Temporary Compensating Workaround for CVE-2026-88772
While there is no configuration workaround for CVE-2026-88771, organizations unable to execute an emergency reboot/patch cycle today can mitigate the DTLS memory overflow (CVE-2026-88772) by disabling DTLS on all active VPN virtual servers via CLI:
# Enumerate all configured VPN virtual servers
show vpn vserver
# Disable DTLS on each identified VPN virtual server
set vpn vserver <vserver_name> -dtls OFF
# Save running configuration to permanent storage
save ns configNote: Disabling DTLS forces client traffic onto standard TCP TLS (port 443), which may cause minor latency increases for high-throughput VoIP/video streams but closes the UDP remote exploitation vector completely.
2. Network & Perimeter Defenses
- Management Interface Isolation: Ensure the NetScaler Management IP (NSIP) and Subnet IP (SNIP) interfaces are strictly restricted to dedicated, air-gapped Out-of-Band (OOB) administrative VLANs with multi-factor authentication (MFA). Never expose NSIP/SNIP ports (TCP 80, 443, 22) to the public internet.
- Perimeter Firewall Ingress Filtering: Temporarily drop unsolicited inbound UDP traffic to port 443 at upstream perimeter firewalls if DTLS is not strictly required by remote workforce profiles.
- WAF Signature Enforcement: Deploy emergency layer-7 Web Application Firewall (WAF) regex inspection rules targeting unusual shell metacharacters (
;,|,$(,`) within incoming NetScaler HTTP query parameters.
3. Endpoint Detection & Hunting Query
Security teams should execute active threat hunting queries across firewall, load balancer, and endpoint telemetry to detect anomalous command invocations and file modifications on NetScaler appliances.
Sigma Detection Rule (Appliance Shell Spawns)
title: Citrix NetScaler Suspicious Shell Execution Post-Exploitation
id: c1e289f4-a4b3-4f91-8842-88771citrix
status: critical
description: Detects suspicious process spawning from NetScaler web services (nsppe/nobody) indicative of CVE-2026-88771 command injection.
references:
- https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096
author: CyberNewsAI Threat Intelligence
date: 2026-09-27
tags:
- attack.initial_access
- attack.t1190
- attack.execution
- attack.t1059.004
logsource:
category: process_creation
product: linux
detection:
selection_parent:
ParentImage|endswith:
- '/nsppe'
- '/httpd'
- '/apache'
selection_child:
Image|endswith:
- '/bin/sh'
- '/bin/bash'
- '/usr/bin/python'
- '/usr/bin/perl'
- '/usr/bin/curl'
- '/usr/bin/wget'
selection_cmdline:
CommandLine|contains:
- '/netscaler/ns_gui/'
- '/var/vpn/'
- '/var/tmp/'
- 'nobody'
condition: selection_parent and selection_child or selection_cmdline
falsepositives:
- Legitimate Citrix administrator maintenance scripts executed via validated SSH sessions.
level: criticalMicrosoft Sentinel / Defender KQL Hunting Query
// Hunt for abnormal outbound connections originating from Citrix NetScaler IP addresses
let NetScalerIPs = dynamic(['198.51.100.10', '203.0.113.50']); // Replace with your enterprise NetScaler external/internal IPs
CommonSecurityLog
| where TimeGenerated >= ago(7d)
| where SourceIP in (NetScalerIPs) or DestinationIP in (NetScalerIPs)
| where DeviceVendor =~ "Citrix" or DeviceProduct =~ "NetScaler"
| where Activity has_any ("POST /vpn/", "ns_gui", "dtls", "login")
| extend RequestURI = tostring(parse_url(RequestURL).Path)
| where RequestURI has_any (".php", ".sh", "eval", "base64", "cmd")
| project TimeGenerated, SourceIP, DestinationIP, DestinationPort, Protocol, RequestURI, Activity, DeviceAction
| order by TimeGenerated descStaging Paths & File Artifacts
/netscaler/ns_gui/vpn/*.php(Unauthorized web shells)/var/vpn/themes/*.sh(Backdoor persistence scripts)/var/tmp/.citrix_cache(Staged credential dumps)/var/crash/core.nsppe.*(Memory dump crash artifacts indicating CVE-2026-88772 buffer overflow exploitation)
Malicious IP Addresses & Scanning Nodes
194.38.20.144(Scanning & DTLS buffer overflow probes)185.196.8.212(Command injection payload delivery)45.154.255.89(Reverse shell listener / C2 bridge)91.240.118.172(Automated vulnerability probing)
Observed Web Shell Hashes (SHA-256)
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855(Generic PHP Webshell Stager)7d1a29f8c4495b3b9f1d07c2a138bb390e6c5180f1e84742a0e4c632867ef088(Obfuscated Python Reverse Tunnel)
194.38.20.144185.196.8.21245.154.255.8991.240.118.172/netscaler/ns_gui/vpn//var/crash/core.nsppe.*7d1a29f8c4495b3b9f1d07c2a138bb390e6c5180f1e84742a0e4c632867ef088Declassified Field Apparel for This Incident

Citrix Emergency Mitigation: "Pull The Plug" Heavyweight Tee - Light
“Your NetScaler can't get exploited if it's completely unplugged.”

Citrix Emergency Mitigation: "Pull The Plug" Heavyweight Tee - Dark
“Your NetScaler can't get exploited if it's completely unplugged.”
// VERIFIED_SOURCES_&_REFERENCES
Watch Full Video Briefings on YouTube
Subscribe to CyberNewsAI on YouTube for animated threat vectors, CISO breakdowns, and security briefings.
Related Threat Intelligence
View Archive
LunexStealer Abuses AMD Driver BYOVD to Blind EDR and Steal Credentials
LunexStealer deploys AMD PDFWKRNL.sys via BYOVD to zero kernel callbacks, blinding EDR before stealing browser credentials and crypto wallets across 28 panels.

GitHub Actions Re-Enabled With Active Mini Shai-Hulud Payload
Two compromised GitHub Actions re-enabled with active Mini Shai-Hulud malware exposed 15,000 repos to credential theft via uncleaned mutable release tags.

CISA KEV Alert: WSO2, SharePoint & Adobe Commerce Exploited
CISA adds critical WSO2 JWT auth bypass, Adobe Commerce zero-click flaw, and SharePoint code injection vulnerabilities to its Known Exploited catalog.