Zero-Day Exploitation of Citrix NetScaler ADC and Gateway: CVE-2026-88771 and CVE-2026-88772

|Last updated on Sep 30, 2026|4 min read

Overview

On September 27, 2026, Citrix disclosed eight new vulnerabilities affecting NetScaler ADC and NetScaler Gateway, including two critical remote code execution (RCE) vulnerabilities: CVE-2026-88771 and CVE-2026-88772. Both of these RCE vulnerabilities carry a critical CVSSv4 score of 9.5, and both have been confirmed as being actively exploited in the wild as zero-days prior to the vendor disclosure. 

CVE-2026-88771 affects vulnerable NetScaler deployments in their default configuration, with no additional product features required. The vendor has also indicated that the attack complexity for exploiting CVE-2026-88771 is low, meaning reliable RCE is likely against all vulnerable NetScaler appliances regardless of their configuration. This is especially concerning due to the prevalence of NetScaler appliances.

CVE-2026-88772 is a memory corruption vulnerability and requires the DTLS feature to be enabled on the appliance. The vendor has indicated that the attack complexity is high, meaning achieving reliable exploitation may be more difficult for an attacker than that of CVE-2026-88771.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) reports active exploitation is occurring globally, and added both CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) catalog on September 27, 2026. Multiple CERTs worldwide have begun issuing alerts due to the critical nature of this situation.

The following table summarizes all eight vulnerabilities:

CVE

CVSSv4

Vulnerability

Exploitation confirmed

CVE-2026-88771

9.5 (Critical)

Improper input validation leading to RCE in a default configuration (CWE-20)

Yes (CISA)

CVE-2026-88772

9.5 (Critical)

Memory overflow leading to RCE in a DTLS configuration (CWE-119)

Yes (CISA)

CVE-2026-88773

9.3 (Critical)

HTTP request smuggling (CWE-444)

No

CVE-2026-88774

7.0 (High)

Policy bypass involving URL expressions (CWE-16)

No

CVE-2026-88775

8.8 (High)

Memory overflow in Gateway or AAA configuration (CWE-119)

No

CVE-2026-88776

8.8 (High)

Memory overflow in load balancer of type Oracle configuration (CWE-119)

No

CVE-2026-88777

8.8 (High)

Memory overflow in a LB/CS or CGNAT-LSN/NAT64 configuration (CWE-119)

No

CVE-2026-88778

8.8 (High)

Predictable TCP initial sequence numbers (CWE-342)

No

Mitigation guidance

The following vendor-supplied updates are available to remediate all eight vulnerabilities. Rapid7 strongly recommends updating affected NetScaler appliances on an emergency basis, outside of normal patching cycles, and investigating vulnerable appliances for signs of compromise.

  • Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later releases.

  • Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1.

  • Citrix NetScaler ADC 14.1-FIPS, 14.1-73.37 FIPS and later releases of 14.1-FIPS.

  • Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.279 and later releases of 13.1-FIPS and 13.1-NDcPP.

For the latest mitigation guidance, please refer to the vendor advisory.

Rapid7 MDR Observed Exploitation

Rapid7 observed the earliest exploitation attempts at 2026-09-20T14:28:43 UTC. Only two attempts were seen on September 20, which does not indicate widespread exploitation at that time.

The command injection observed on September 20 is captured below:

Timestamp: 2026-09-20T14:28:43.000Z
Account: wfr
Result: FAILED_BAD_LOGIN
Source_ip: 149.104.78.208
Source_data: "Authentication is rejected for WFR pitboss PPE nsppe missed too many heartbeats NSPPE;tar${IFS}czf$IFS/var/netscaler/gui/vpn/c$IFS-C$IFS/flash${IFS}nsconfig; (client ip : 149.104.78.208 , vserver ip: <redacted>  ), extended error, if any : "

This payload executes tar czf /var/netscaler/gui/vpn/c -C /flash nsconfig, which creates a gzipped archive named c in /var/netscaler/gui/vpn/ containing the full contents of /flash/nsconfig.

This location is significant because the Gateway serves /var/netscaler/gui/vpn/ publicly at https://<gateway>/vpn/. Once the command runs, an unauthenticated request to GET https://<gateway>/vpn/c will return the archive to any requester, with no login required.

The /flash/nsconfig directory contains material that would give an attacker significant follow-on access, including:

  • ns.conf, the full device configuration, including encrypted passwords for the nsroot account and other admin accounts, as well as bind passwords for LDAP, RADIUS, and TACACS

  • ssl/, containing SSL certificates and private keys

  • SSH host keys, license files, and HA sync settings

As of this writing, Rapid7 has identified two organizations compromised through exploitation of CVE-2026-88771. The first compromise involved the command injection detailed above and the other involved a webshell placed at /var/netscaler/logon/LogonPoint/custom/.ctxs.receiver (SHA256: ed082f744f035035900f67edf438f2f7d0528ac501234f63d476d65273cdb9a1), observed on September 24.

Rapid7 customers

Exposure Command, InsightVM, and Nexpose

Exposure Command, InsightVM, and Nexpose customers can assess exposure to all the CVEs listed in the blog with authenticated vulnerability checks available in the September 28 content release.

Intelligence Hub

Customers leveraging Rapid7’s Intelligence Hub can track the latest developments surrounding CVE-2026-88771 and CVE-2026-88772, including indicators of compromise (IOCs) and Suricata detection rules.

Managed Detection Response (MDR)

The following detection rules are available for InsightIDR and Managed Detection Response (MDR) customers:

  • Suspicious Web Request -  Citrix NetScaler ADC and Gateway Appliance Exploitation (CVE-2026-88771)

Updates

  • September 28, 2026: Initial publication.

  • September 29, 2026: Suricata detection rules for CVE-2026-88771 are now available in Intelligence Hub.

  • September 30, 2026: Added Rapid7 MDR Observed Exploitation section to include details of the cases flagged by the SOC team.

  • September 30, 2026: Added Rapid7 MDR customers section.

Article tags