NC4-ALR-2026-000007 : Citrix NetScaler ADC and NetScaler Gateway Vulnerabilities (CVE-2026-88771 and CVE-2026-88772)
Introduction

The National Cyber Coordination and Command Centre (NC4) is monitoring active exploitation of two critical vulnerabilities affecting customer-managed Citrix NetScaler ADC and NetScaler Gateway appliances, tracked as CVE-2026-88771 and CVE-2026-88772.

Both vulnerabilities were disclosed on 27 September 2026, with Citrix confirming that exploitation has been observed against unmitigated NetScaler deployments. Organizations should apply the relevant security updates and assess previously exposed appliances for potential compromise. Citrix has made generic Indicators of Compromise (IOCs) available through the NetScaler Console Security Advisory workflow. Where compromise is suspected, organizations should preserve forensic evidence before remediation and follow Citrix's incident response guidance.

NC4 assesses with moderate confidence that these vulnerabilities present an immediate risk to organizations operating affected internet-facing NetScaler appliances. This assessment is based on vendor-confirmed exploitation and available reports of active zero-day exploitation of CVE-2026-88772. The full scale of exploitation and the extent of impact to Malaysian organizations have not yet been fully established.

 

Impact

Successful exploitation of CVE-2026-88771 or CVE-2026-88772 may allow an unauthenticated remote attacker to execute code or commands on an affected NetScaler appliance. CVE-2026-88772 may additionally cause denial-of-service conditions.

Depending on the appliance configuration and subsequent attacker activity, successful exploitation may enable an attacker to:

  • execute arbitrary commands on the affected appliance,
  • modify appliance files or configuration,
  • establish persistent access,
  • access credentials, certificates, authentication material or other secrets available to the appliance,
  • disrupt VPN, gateway or application delivery services,
  • use the compromised appliance to access or target connected systems, or
  • conduct further malicious activity within the affected environment.

Following CVE-2026-88772 exploitation, post-exploitation activity was reported involving web shells and tunnelling tool. The observed activity supported persistent access, internal reconnaissance and credential theft.

Brief Description

Threat Assessment

CVE-2026-88771 is an improper input validation vulnerability that allows unauthenticated remote command execution. It affects vulnerable NetScaler ADC and NetScaler Gateway deployments without requiring additional configuration.

CVE-2026-88772 is a memory overflow vulnerability that may lead to remote code execution or denial of service. Exploitation requires DTLS to be enabled, which is the default configuration for NetScaler Gateway VPN virtual servers.

Citrix has confirmed exploitation of both vulnerabilities against unmitigated systems. CVE-2026-88771 presents broader exposure as it does not require an additional configuration precondition.

Affected Product

 

Product

Affected Versions

Vulnerability Exposure

Fixed Version

NetScaler ADC and NetScaler Gateway 14.1

Before 14.1-73.37

CVE-2026-88771; CVE-2026-88772 where DTLS is enabled

14.1-73.37 or later

NetScaler ADC and NetScaler Gateway 13.1

Before 13.1-64.23

CVE-2026-88771; CVE-2026-88772 where DTLS is enabled

13.1-64.23 or later

NetScaler ADC 14.1-FIPS

Before 14.1-73.37 FIPS

CVE-2026-88771; CVE-2026-88772 where DTLS is enabled

14.1-73.37 FIPS or later

NetScaler ADC 13.1-FIPS and 13.1-NDcPP

Before 13.1-37.279

CVE-2026-88771; CVE-2026-88772 where DTLS is enabled

13.1-37.279 or later

 

 

Secure Private Access Hybrid deployments using NetScaler instances are also affected and should be upgraded to the appropriate fixed NetScaler build. The Citrix security bulletin applies to customer-managed NetScaler ADC and NetScaler Gateway deployments. Citrix-managed cloud services are updated separately by Citrix.

Organizations operating End-of-Life or unsupported NetScaler releases should migrate to a supported release containing the applicable security fixes.

 

Vulnerability Preconditions

CVE-2026-88771 affects vulnerable NetScaler ADC and NetScaler Gateway deployments without requiring additional configuration, while exposure to CVE-2026-88772 depends on whether DTLS is enabled.

Organizations are advised to refer to the official Citrix security bulletin to determine whether the relevant preconditions for these vulnerabilities are met.

Recommendation

Immediate Actions

NC4 recommends that organizations:

  • identify all customer-managed NetScaler ADC and NetScaler Gateway appliances, particularly internet-facing systems,
  • determine the software version and build installed,
  • upgrade affected appliances to the appropriate fixed release:
    • NetScaler ADC and NetScaler Gateway 14.1-73.37 or later
    • NetScaler ADC and NetScaler Gateway 13.1-64.23 or later
    • NetScaler ADC 14.1-73.37 FIPS or later, or
    • NetScaler ADC 13.1-37.279 FIPS/NDcPP or later,
  • verify that the update was successfully applied,
  • assess previously exposed appliances for potential compromise, and
  • preserve relevant logs and follow incident response procedures where compromise is suspected.

Citrix has confirmed exploitation of both vulnerabilities and recommends applying the fixed releases as soon as possible.

 

Important Note for NetScaler 13.1

Citrix has identified a non-security issue affecting NetScaler 13.1-64.23 where certain configurations may enter a cyclic reboot during the upgrade process.

Administrators can check the configuration using:

show ns variable

If the command returns configured variables, Citrix recommends planning the upgrade to 13.1-64.24 to avoid the operational issue.

 

Temporary Exposure Reduction

Citrix has not documented a configuration-based workaround that removes exposure to CVE-2026-88771. As the vulnerability affects all vulnerable NetScaler deployments, upgrading to a fixed release should be treated as the primary remediation.

For CVE-2026-88772, organizations that cannot immediately update may consider explicitly disabling DTLS on affected virtual servers where operational requirements permit. This removes the stated DTLS precondition for CVE-2026-88772.

However, disabling DTLS does not mitigate CVE-2026-88771 and must not be treated as an alternative to installing the security update.

 

Compromise Assessment

Organizations with appliances that were exposed to the internet while vulnerable should assess for possible compromise.

Citrix provides generic Indicators of Compromise through the NetScaler Console Security Advisory workflow. The capability is available through NetScaler Console Service and NetScaler Console on premises with Cloud Connect, with the applicable functionality starting from version 14.1-73.36. Organizations unable to use this capability should contact Citrix Support for assistance.

A "No Compromise Detected" result should not be treated as conclusive evidence that the appliance was not compromised, as available IOCs may not detect all attacker activity.

 

Where compromise is suspected, organizations should:

  • preserve evidence before undertaking destructive remediation where operationally possible,
  • record the appliance system time, time zone and NTP configuration,
  • preserve local, NetScaler Console and remote syslog data,
  • collect an appropriate technical support bundle,
  • isolate the affected appliance from external and internal networks,
  • revoke credentials, certificates and secrets accessible through the appliance,
  • investigate systems that communicated with the compromised NetScaler,
  • rebuild or replace compromised instances from a trusted state,
  • rotate credentials and cryptographic material following recovery, and
  • closely monitor the recovered environment.

 

Additional Security Measures

Citrix specifically recommends external log forwarding to support centralized monitoring, threat detection and forensic investigation, and notes that NetScaler Console File Integrity Monitoring can assist in identifying unexpected file-level changes.

Organizations should also:

  • ensure NetScaler management interfaces are not exposed directly to the public internet,
  • restrict management access to authorized administrative networks,
  • forward NetScaler logs to an external SIEM or log management platform,
  • enable appropriate file integrity monitoring,
  • monitor configuration and administrative changes,
  • maintain current configuration and system backups,
  • protect credentials, certificates and authentication secrets accessible to the appliance, and
  • retain sufficient logs to support forensic investigation and incident response.

 

Detection and Monitoring

Public technical information on the complete exploit chain remains limited. However, security vendors have published several exploitation and post-exploitation artefacts associated with observed CVE-2026-88772 activity. Organizations should use these indicators together with behavioral monitoring and retrospective analysis rather than rely solely on static IOCs.

The following activity may warrant further investigation:

Category

Activity to Review

DTLS / SSL Activity

  • SSL_HANDSHAKE_FAILURE events where the client version is DTLSv1.0 and the reason is "Handshake failure-Internal Error", particularly clusters on a single appliance.
  • Unexpected inbound UDP/443, especially on appliances where DTLS is disabled or not expected.

NSPPE Activity

  • NSPPE process termination or crash messages in /var/log/messages, new NSPPE core files under /var/core/, and pitboss messages indicating NSPPE was not restarted.
  • A DTLS handshake failure followed by an NSPPE crash is a strong exploitation signal.

Availability Events

Unexpected HA failovers or appliance restarts occurring close in time to DTLS handshake failures or NSPPE crashes.

Web Server Configuration

  • Unauthorised changes to /etc/httpd.conf, /nsconfig/httpd.conf and /flash/nsconfig/httpd.conf, including php_flag engine on, AddHandler/AddType application/x-httpd-php for non-PHP extensions (.deb, .sig, .html, .rpm, .tgz), and AliasMatch or RewriteRule directives mapping /vpn/media/, /vpn/theme/ or /vpn/images/ to script directories.

Web shell / File Activity

Plain-text or PHP files disguised as .deb, .sig or .ico (for example nsginstaller*.deb and nsgclient*.sig) in /var/netscaler/gui/vpn/scripts/linux/, /netscaler/ns_gui/vpn/scripts/linux/, /var/netscaler/gui/vpns/scripts/vista/, /var/netscaler/gui/vpns/scripts/mac/, /netscaler/ns_gui/vpn/media/ and /var/vpn/theme/.

Web shell HTTP Activity

  • Requests to /vpn/media/*.ico or /vpn/scripts/ returning HTTP 404 with multi-KB responses or long processing times.
  • Custom request headers such as HTTP_NSC_LDAP, HTTP_NSC_CLIENTTYPE and HTTP_X_UX / HTTP_X_UX_<n>.

Log Tampering / Anti-Forensic Activity

  • "File does not exist" errors for .sig or other non-standard files in /var/log/httperror*.
  • Gaps or truncated lines in /var/log/httpaccess.log around /vpn/scripts/ or /vpn/media/.
  • Removal of /vpn/scripts/linux references from /etc/crontab.

Privilege Changes

Unexpected SUID permissions on /bin/sh (-rwsr-xr-x, root-owned).

Administrative Activity

  • In /var/log/sh.log, forced appliance restarts (/netscaler/nsshutdown -R) or manual Apache restarts (httpd -k restart) outside change windows.
  • Unexpected changes to files under /nsconfig/.

Process Activity

  • Python processes launched via nohup, or containing Base64-encoded payloads.

Tunnelling Tool Artefacts

  • Presence of hidden files in /tmp directory.
  • Check for suspicious listening process with sockstat -4 -l.

Network Activity

  • Outbound connections from the NetScaler to destinations outside the approved egress list.
  • Prioritise connections to PAM or credential vaults, domain controllers on unexpected ports, many internal hosts in a short period, and outbound SMTP/TCP 25.

Downstream Authentication / Credential Activity

Anomalous privileged or RDP logons, credential dumping, or unusual PAM activity on systems accessible from the NetScaler.

Internal Environment

  • Reconnaissance, credential access or lateral movement originating from, or shortly after, activity on the affected NetScaler.
  • In HA pairs, assess both nodes independently, since a compromised node may have replicated modified configs to the standby

 

Reporting

Organizations identifying attempted exploitation or confirmed compromise should report the incident through the appropriate national reporting channel.
NCII entities should continue to comply with applicable reporting obligations under the Cyber Security Act 2024 (Act 854) and associated regulations. Other organizations are encouraged to submit cybersecurity incident reports through NACSA's designated reporting channels.


Disclaimer


This advisory reflects information available to NC4 as of 30 September 2026. Exploitation activity remains under investigation, and technical details, indicators of compromise, exploitation methods and threat actor attribution may change as Citrix and cybersecurity authorities publish additional information.
Organizations should continue to monitor official Citrix and cybersecurity advisories for updates.

 

 

 

References

1. Citrix - Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778 (CTX697096)    https://support.citrix.com/external/article/CTX697096

2. Citrix - NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778 - Security Updates    https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/

3. Citrix - Steps to Take if NetScaler ADC is Suspected to be Compromised (CTX694799)    https://support.citrix.com/external/article/CTX694799/steps-to-take-if-netscaler-adc-is-suspec.html

4. Google Threat Intelligence Group / Mandiant - Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances, 29 September 2026    https://cloud.google.com/blog/topics/threat-intelligence/defending-against-active-exploitation-of-citrix-netscaler-adc-and-gateway-appliances

5. CERT-EU - Security Advisory 2026-014: Critical Vulnerabilities in Citrix NetScaler ADC and Gateway    https://cert.europa.eu/publications/security-advisories/2026-014/

6. CISA - CISA Adds Two Known Exploited Vulnerabilities to Catalog, 27 September 2026    https://www.cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway

Advisory