NC4-ALR-2026-000007 : Citrix NetScaler ADC and NetScaler Gateway Vulnerabilities (CVE-2026-88771 and CVE-2026-88772)
Introduction
The National Cyber Coordination and Command Centre (NC4) is monitoring active exploitation of two critical vulnerabilities affecting customer-managed Citrix NetScaler ADC and NetScaler Gateway appliances, tracked as CVE-2026-88771 and CVE-2026-88772.
Both vulnerabilities were disclosed on 27 September 2026, with Citrix confirming that exploitation has been observed against unmitigated NetScaler deployments. Organizations should apply the relevant security updates and assess previously exposed appliances for potential compromise. Citrix has made generic Indicators of Compromise (IOCs) available through the NetScaler Console Security Advisory workflow. Where compromise is suspected, organizations should preserve forensic evidence before remediation and follow Citrix's incident response guidance.
NC4 assesses with moderate confidence that these vulnerabilities present an immediate risk to organizations operating affected internet-facing NetScaler appliances. This assessment is based on vendor-confirmed exploitation and available reports of active zero-day exploitation of CVE-2026-88772. The full scale of exploitation and the extent of impact to Malaysian organizations have not yet been fully established.
Impact
Successful exploitation of CVE-2026-88771 or CVE-2026-88772 may allow an unauthenticated remote attacker to execute code or commands on an affected NetScaler appliance. CVE-2026-88772 may additionally cause denial-of-service conditions.
Depending on the appliance configuration and subsequent attacker activity, successful exploitation may enable an attacker to:
- execute arbitrary commands on the affected appliance,
- modify appliance files or configuration,
- establish persistent access,
- access credentials, certificates, authentication material or other secrets available to the appliance,
- disrupt VPN, gateway or application delivery services,
- use the compromised appliance to access or target connected systems, or
- conduct further malicious activity within the affected environment.
Following CVE-2026-88772 exploitation, post-exploitation activity was reported involving web shells and tunnelling tool. The observed activity supported persistent access, internal reconnaissance and credential theft.
Brief Description
Threat Assessment
CVE-2026-88771 is an improper input validation vulnerability that allows unauthenticated remote command execution. It affects vulnerable NetScaler ADC and NetScaler Gateway deployments without requiring additional configuration.
CVE-2026-88772 is a memory overflow vulnerability that may lead to remote code execution or denial of service. Exploitation requires DTLS to be enabled, which is the default configuration for NetScaler Gateway VPN virtual servers.
Citrix has confirmed exploitation of both vulnerabilities against unmitigated systems. CVE-2026-88771 presents broader exposure as it does not require an additional configuration precondition.
Affected Product
|
Product |
Affected Versions |
Vulnerability Exposure |
Fixed Version |
|---|---|---|---|
|
NetScaler ADC and NetScaler Gateway 14.1 |
Before 14.1-73.37 |
CVE-2026-88771; CVE-2026-88772 where DTLS is enabled |
14.1-73.37 or later |
|
NetScaler ADC and NetScaler Gateway 13.1 |
Before 13.1-64.23 |
CVE-2026-88771; CVE-2026-88772 where DTLS is enabled |
13.1-64.23 or later |
|
NetScaler ADC 14.1-FIPS |
Before 14.1-73.37 FIPS |
CVE-2026-88771; CVE-2026-88772 where DTLS is enabled |
14.1-73.37 FIPS or later |
|
NetScaler ADC 13.1-FIPS and 13.1-NDcPP |
Before 13.1-37.279 |
CVE-2026-88771; CVE-2026-88772 where DTLS is enabled |
13.1-37.279 or later |
Secure Private Access Hybrid deployments using NetScaler instances are also affected and should be upgraded to the appropriate fixed NetScaler build. The Citrix security bulletin applies to customer-managed NetScaler ADC and NetScaler Gateway deployments. Citrix-managed cloud services are updated separately by Citrix.
Organizations operating End-of-Life or unsupported NetScaler releases should migrate to a supported release containing the applicable security fixes.
Vulnerability Preconditions
CVE-2026-88771 affects vulnerable NetScaler ADC and NetScaler Gateway deployments without requiring additional configuration, while exposure to CVE-2026-88772 depends on whether DTLS is enabled.
Organizations are advised to refer to the official Citrix security bulletin to determine whether the relevant preconditions for these vulnerabilities are met.
Recommendation
Immediate Actions
NC4 recommends that organizations:
- identify all customer-managed NetScaler ADC and NetScaler Gateway appliances, particularly internet-facing systems,
- determine the software version and build installed,
- upgrade affected appliances to the appropriate fixed release:
- NetScaler ADC and NetScaler Gateway 14.1-73.37 or later
- NetScaler ADC and NetScaler Gateway 13.1-64.23 or later
- NetScaler ADC 14.1-73.37 FIPS or later, or
- NetScaler ADC 13.1-37.279 FIPS/NDcPP or later,
- verify that the update was successfully applied,
- assess previously exposed appliances for potential compromise, and
- preserve relevant logs and follow incident response procedures where compromise is suspected.
Citrix has confirmed exploitation of both vulnerabilities and recommends applying the fixed releases as soon as possible.
Important Note for NetScaler 13.1
Citrix has identified a non-security issue affecting NetScaler 13.1-64.23 where certain configurations may enter a cyclic reboot during the upgrade process.
Administrators can check the configuration using:
show ns variable
If the command returns configured variables, Citrix recommends planning the upgrade to 13.1-64.24 to avoid the operational issue.
Temporary Exposure Reduction
Citrix has not documented a configuration-based workaround that removes exposure to CVE-2026-88771. As the vulnerability affects all vulnerable NetScaler deployments, upgrading to a fixed release should be treated as the primary remediation.
For CVE-2026-88772, organizations that cannot immediately update may consider explicitly disabling DTLS on affected virtual servers where operational requirements permit. This removes the stated DTLS precondition for CVE-2026-88772.
However, disabling DTLS does not mitigate CVE-2026-88771 and must not be treated as an alternative to installing the security update.
Compromise Assessment
Organizations with appliances that were exposed to the internet while vulnerable should assess for possible compromise.
Citrix provides generic Indicators of Compromise through the NetScaler Console Security Advisory workflow. The capability is available through NetScaler Console Service and NetScaler Console on premises with Cloud Connect, with the applicable functionality starting from version 14.1-73.36. Organizations unable to use this capability should contact Citrix Support for assistance.
A "No Compromise Detected" result should not be treated as conclusive evidence that the appliance was not compromised, as available IOCs may not detect all attacker activity.
Where compromise is suspected, organizations should:
- preserve evidence before undertaking destructive remediation where operationally possible,
- record the appliance system time, time zone and NTP configuration,
- preserve local, NetScaler Console and remote syslog data,
- collect an appropriate technical support bundle,
- isolate the affected appliance from external and internal networks,
- revoke credentials, certificates and secrets accessible through the appliance,
- investigate systems that communicated with the compromised NetScaler,
- rebuild or replace compromised instances from a trusted state,
- rotate credentials and cryptographic material following recovery, and
- closely monitor the recovered environment.
Additional Security Measures
Citrix specifically recommends external log forwarding to support centralized monitoring, threat detection and forensic investigation, and notes that NetScaler Console File Integrity Monitoring can assist in identifying unexpected file-level changes.
Organizations should also:
- ensure NetScaler management interfaces are not exposed directly to the public internet,
- restrict management access to authorized administrative networks,
- forward NetScaler logs to an external SIEM or log management platform,
- enable appropriate file integrity monitoring,
- monitor configuration and administrative changes,
- maintain current configuration and system backups,
- protect credentials, certificates and authentication secrets accessible to the appliance, and
- retain sufficient logs to support forensic investigation and incident response.
Detection and Monitoring
Public technical information on the complete exploit chain remains limited. However, security vendors have published several exploitation and post-exploitation artefacts associated with observed CVE-2026-88772 activity. Organizations should use these indicators together with behavioral monitoring and retrospective analysis rather than rely solely on static IOCs.
The following activity may warrant further investigation:
|
Category |
Activity to Review |
|---|---|
|
DTLS / SSL Activity |
|
|
NSPPE Activity |
|
|
Availability Events |
Unexpected HA failovers or appliance restarts occurring close in time to DTLS handshake failures or NSPPE crashes. |
|
Web Server Configuration |
|
|
Web shell / File Activity |
Plain-text or PHP files disguised as .deb, .sig or .ico (for example nsginstaller*.deb and nsgclient*.sig) in /var/netscaler/gui/vpn/scripts/linux/, /netscaler/ns_gui/vpn/scripts/linux/, /var/netscaler/gui/vpns/scripts/vista/, /var/netscaler/gui/vpns/scripts/mac/, /netscaler/ns_gui/vpn/media/ and /var/vpn/theme/. |
|
Web shell HTTP Activity |
|
|
Log Tampering / Anti-Forensic Activity |
|
|
Privilege Changes |
Unexpected SUID permissions on /bin/sh (-rwsr-xr-x, root-owned). |
|
Administrative Activity |
|
|
Process Activity |
|
|
Tunnelling Tool Artefacts |
|
|
Network Activity |
|
|
Downstream Authentication / Credential Activity |
Anomalous privileged or RDP logons, credential dumping, or unusual PAM activity on systems accessible from the NetScaler. |
|
Internal Environment |
|
Reporting
Organizations identifying attempted exploitation or confirmed compromise should report the incident through the appropriate national reporting channel.
NCII entities should continue to comply with applicable reporting obligations under the Cyber Security Act 2024 (Act 854) and associated regulations. Other organizations are encouraged to submit cybersecurity incident reports through NACSA's designated reporting channels.
Disclaimer
This advisory reflects information available to NC4 as of 30 September 2026. Exploitation activity remains under investigation, and technical details, indicators of compromise, exploitation methods and threat actor attribution may change as Citrix and cybersecurity authorities publish additional information.
Organizations should continue to monitor official Citrix and cybersecurity advisories for updates.
References
1. Citrix - Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778 (CTX697096)
https://support.citrix.com/external/article/CTX697096
2. Citrix - NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778 - Security Updates
https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/
3. Citrix - Steps to Take if NetScaler ADC is Suspected to be Compromised (CTX694799)
https://support.citrix.com/external/article/CTX694799/steps-to-take-if-netscaler-adc-is-suspec.html
4. Google Threat Intelligence Group / Mandiant - Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances, 29 September 2026
https://cloud.google.com/blog/topics/threat-intelligence/defending-against-active-exploitation-of-citrix-netscaler-adc-and-gateway-appliances
5. CERT-EU - Security Advisory 2026-014: Critical Vulnerabilities in Citrix NetScaler ADC and Gateway
https://cert.europa.eu/publications/security-advisories/2026-014/
6. CISA - CISA Adds Two Known Exploited Vulnerabilities to Catalog, 27 September 2026
https://www.cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway