Two zero-days, already exploited, patch available

Citrix NetScaler appliances are under active attack through two critical vulnerabilities that were exploited in the wild before any patch existed. Citrix disclosed eight vulnerabilities on September 27 in bulletin CTX697096. The two headline flaws, CVE-2026-88771 and CVE-2026-88772, both score 9.5 on the CVSS v4 scale and both lead to unauthenticated remote code execution. CISA added both to its Known Exploited Vulnerabilities catalog the same day, citing confirmed global exploitation.

The first bug, CVE-2026-88771, is an improper input validation flaw. It needs no special configuration to exploit: every NetScaler ADC and Gateway deployment is affected, including those running the default configuration with no extra features enabled. Citrix rates the attack complexity as low. The second, CVE-2026-88772, is a memory overflow that can produce remote code execution or a denial of service, but it requires DTLS to be enabled, which is the default on VPN virtual servers, so most remote-access deployments meet the precondition whether their admins know it or not.

What attackers did once inside

Mandiant’s incident response work shows why this is worse than a routine patch Tuesday. The exploit crashes the NetScaler Packet Processing Engine, and attackers land with root-level access on an appliance that sits at the network edge. From there the tradecraft gets creative. Attackers changed permissions on /bin/sh to keep root access, then edited the web server configuration so file extensions that normally never execute, .deb, .sig, .ico, were processed as PHP. Web shells dressed as Debian packages could sit in plain sight.

Mandiant documented two previously undocumented malware families in these intrusions: WHIPSHOT, a PHP web shell disguised as a Debian package, and SLAPSHOT, a Python TCP tunneling tool used to reach deeper into internal networks. The campaigns began at least in early September and hit organizations in North America and Europe across government, financial services, education, legal, and professional services sectors. GreyNoise observed an exploitation attempt on September 24, three days before public disclosure, with the attacker setting the setuid bit on /bin/sh and planting a password-protected PHP web shell in the NetScaler logon directory.

How wide is the exposure

The Shadowserver Foundation counted more than 20,000 internet-exposed NetScaler instances around the disclosure window. That is the population for which reliable exploitation is a matter of time. The other six vulnerabilities in the bulletin are serious but have no confirmed exploitation: a 9.3 request smuggling flaw (CVE-2026-88773), a 7.0 policy bypass (CVE-2026-88774), three 8.8 memory overflows in specific configurations (CVE-2026-88775 through 88777), and an 8.8 flaw producing predictable TCP initial sequence numbers (CVE-2026-88778). Citrix urges upgrading for all eight regardless.

Verifying your own exposure takes a few minutes. For CVE-2026-88772, inspect the running configuration for virtual servers of type DTLS, and on a NetScaler Gateway do not assume DTLS is off, since the default leaves it enabled on VPN virtual servers. For CVE-2026-88771 there is nothing to check: if the box runs an unpatched build, it is vulnerable. Inventory matters too. Appliances managed through NetScaler Console report differently from standalone units, and the bulletin notes that Secure Private Access hybrid deployments using NetScaler instances are affected as well.

What to do, in order

First, check for compromise before you patch. CISA and NHS England’s cyber alert both make the same point: the update process can destroy forensic evidence, so capture artifacts first. Citrix publishes indicators of compromise through NetScaler Console. The IoCs worth hunting for include a web shell at /var/netscaler/logon/LogonPoint/custom/.ctxs.receiver, unexpected Alias or AliasMatch entries in httpd.conf, the setuid bit set on /bin/sh, .deb or .sig or .ico files containing PHP, files named .uxdport or .uxdlock in /tmp, and unexplained Packet Processing Engine crashes.

Second, upgrade on an emergency basis, outside your normal patch cycle. Fixed builds are NetScaler ADC and Gateway 14.1-73.37 and 13.1-64.23, with FIPS variants at 14.1-73.37 FIPS and 13.1-37.279 for the FIPS and NDcPP editions. Rapid7 recommends treating this as an emergency regardless of maintenance windows, and investigating every vulnerable appliance for compromise rather than only the ones that look suspicious.

Third, if you cannot patch yet, mitigation is partial at best. Disabling DTLS and blocking inbound UDP/443 covers only CVE-2026-88772. There is no workaround for CVE-2026-88771, which affects everything by default. And if you are still running NetScaler 12.1 or 13.0, those branches are end of life and will never receive a fix, so migration is the only option.

Finally, rotate credentials stored on or reachable from any affected appliance, and treat any positive IOC hit as a full network breach investigation, not a web shell cleanup.

This keeps happening

The pattern rhymes with the 2023 CVE-2023-3519 campaign, where NetScaler boxes were backdoored with web shells for months before anyone noticed. Internet-exposed edge appliances without endpoint monitoring remain the softest target in enterprise networks, and disclosure practice has changed too: national CERTs received private notification before the vendor bulletin went public, which shrinks the window defenders get from days to hours. The practical lesson is unchanged. Know what NetScaler appliances you run, know their versions, and when an edge appliance bulletin drops, treat compromise assessment as part of the patch, not an optional extra.

Leave a Reply

Your email address will not be published. Required fields are marked *