Home/ Blog/ Security news/ Article
Blog · Security news

NetScaler CVE-2026-88772: Pre-Auth RCE Zero-Day, Patch Then Hunt

CVE-2026-88771 and CVE-2026-88772 hit Citrix NetScaler as zero-days, exploited before a patch. Patching does not remove the web shell attackers left.

Sealed network edge gateway with a hidden tunnel still open to the servers behind it

Upgrading NetScaler this week closes the door. It does not tell you whether someone already walked through it. Two critical Citrix NetScaler flaws, CVE-2026-88771 and CVE-2026-88772, were exploited as zero-days for weeks before a fix existed, and the attackers left persistence behind: web shells, a tunneling tool, and a root backdoor that a firmware update does not remove. CISA added both to its Known Exploited Vulnerabilities (KEV) catalog on September 27, 2026, with a September 30 federal deadline. Patching is step one. Hunting your own appliance is step two.

What broke, and who is exposed

The two bugs are distinct, and both carry a CVSS score of 9.5. CVE-2026-88771 is an improper input validation flaw that lets an unauthenticated attacker run commands, and it affects every NetScaler Application Delivery Controller (ADC) and Gateway deployment regardless of how it is configured. CVE-2026-88772 is a memory overflow in how the appliance parses the Datagram Transport Layer Security (DTLS) handshake; a pre-authentication attacker can corrupt an internal buffer and execute code with root privileges. It needs DTLS enabled, which is the default on Gateway VPN virtual servers.

Citrix fixed it in NetScaler builds 14.1-73.37, 13.1-64.23, and the parallel FIPS and NDcPP releases. Run a build below those and you are exposed. Palo Alto Networks' Unit 42 counted more than 50,000 internet-exposed NetScaler instances as of September 27. The security firm watchTowr published proof-of-concept code, so the barrier to entry is now low. Citrix has released patches for the supported branches.

NetScaler dual zero-day: exploited before the fixEarly Sep: Campaign begins. Sep 24: Exploits seen. Sep 27: KEV listed. Sep 29: Patch shipped.NetScaler dual zero-day: exploited before the fixEarly SepCampaign beginsSep 24Exploits seenSep 27KEV listedSep 29Patch shipped
Source: Mandiant, GreyNoise, CISA KEV, Citrix (September 2026).

Past NetScaler advisories usually came with an escape hatch. The July memory leak only hit appliances acting as a SAML identity provider, and one denial-of-service fix in that same batch stayed inert until you flipped a setting, which we wrote about at the time. This pair has no such hatch. CVE-2026-88771 needs no special role at all, and CVE-2026-88772's one precondition ships on by default. The usual reassurance, "we do not run that configuration," does not apply here.

Why a patched appliance can still be owned

The zero-day timeline is the whole problem. Mandiant and Google's threat intelligence team traced the campaign to early September; GreyNoise recorded exploitation attempts on September 24; the patch arrived at the end of the month. Every appliance reachable from the internet during that window had time to be hit before any fix was available. And the intruders planted persistence that outlives the vulnerable code.

Mandiant reported two custom tools. WHIPSHOT is a PHP web shell that pulls its commands out of HTTP headers and answers with a bogus 404 so the traffic looks routine. SLAPSHOT is a Python tunneler that pushes TCP connections into the internal network and tidies up behind itself, dropping idle sessions after about fifteen minutes. Alongside them, the attackers edited the appliance's Apache configuration so files with extensions like .deb, .sig, .css, or .ico execute as PHP, and set /bin/sh setuid root so any later shell runs with full privileges.

None of that is removed by installing a new build. The upgrade replaces the vulnerable binary. It does not audit the filesystem, revert the Apache config, or clear a setuid bit an attacker set. That is the trap in the word "patched." On an edge appliance that was internet-facing before the fix shipped, patched and clean are not the same state.

The cleanup logic also shapes how you hunt. SLAPSHOT tears its own tunnels down after minutes of inactivity, and the web shell disguises its traffic as ordinary 404s, so the loud moment was the exploitation itself, not a steady signal you could still catch on the wire today. If you only watch for active command-and-control, you will miss it. Look at the filesystem.

Where to look on the appliance

If you run NetScaler and it faced the internet this month, treat it as suspect until proven otherwise. The indicators Mandiant published are filesystem and log artifacts you can check on the appliance shell:

Compromise checks on a NetScaler appliance shell
ls -la /var/netscaler/logon/LogonPoint/custom/.ctxs.receiver
grep -iE 'Alias|AliasMatch' /etc/httpd.conf
ls -la /tmp/.uxdport /tmp/.uxdlock
find / -perm -4000 -name sh 2>/dev/null
grep -i 'Handshake failure-Internal Error' /var/log/ns.log

A .ctxs.receiver file under the LogonPoint custom directory, unexpected Alias entries in httpd.conf, the /tmp/.uxdport or /tmp/.uxdlock files left by SLAPSHOT, and a setuid /bin/sh are the strong signals. Two log patterns corroborate exploitation: repeated DTLS handshake failures logged as "Handshake failure-Internal Error," and packet-engine crashes that fail to restart cleanly. Neither log line is proof on its own, but paired with any file above it warrants a full investigation.

The edge-appliance pattern keeps repeating

This is the third NetScaler advisory we have written up since July, and the story rhymes with the rest of the edge-device beat. Ivanti Sentry was patched and still breached. INC ransomware built a whole affiliate business on edge-device flaws that were patched months earlier. The constant is the pre-patch window and the habit of closing the ticket the moment the build number changes. We said the same thing when Citrix shipped its August auth-bypass fix.

Remote-access gateways sit at the perimeter, terminate VPN sessions, and hold credentials. They are the first thing an attacker wants and the last thing most teams instrument. Continuous log collection and threat hunting on the appliance and the hosts behind it is how you catch the post-exploitation stage, which is the stage that survives a patch.

Patch first, then rebuild what was exposed

Patch to the fixed build first, because the door stays open until you do. Then decide, per appliance, whether it was reachable from the internet during September. If it was, the safest path is not a quick scan but a rebuild: restore the appliance from a known-good image, rotate every credential and secret it held (VPN, LDAP bind accounts, session keys, certificates), and review what those credentials could reach. A web shell you miss on one gateway is a foothold into everything behind it. The patch buys back your perimeter. It does not give you back the trust you had before September.

Topics

Frequently asked questions

Which NetScaler versions are affected by CVE-2026-88771 and CVE-2026-88772?

All NetScaler ADC and Gateway builds before 14.1-73.37 and 13.1-64.23, plus the matching FIPS and NDcPP builds, are affected. CVE-2026-88771 hits any configuration, while CVE-2026-88772 needs DTLS, which is on by default for Gateway VPN virtual servers. Upgrade to the fixed builds.

Are the NetScaler flaws being exploited in the wild?

Yes. Both were exploited as zero-days before a patch existed. GreyNoise observed exploitation attempts on September 24, 2026, and CISA added both to its Known Exploited Vulnerabilities catalog on September 27 with a September 30 federal deadline. The firm watchTowr has published proof-of-concept code.

Does patching NetScaler remove the attacker?

No. The update replaces the vulnerable code but does not remove persistence planted during the pre-patch window. Web shells, a setuid root shell, and modified Apache configuration survive the upgrade. Any appliance exposed to the internet before the fix should be investigated or rebuilt.

How do I tell if my NetScaler was compromised?

Check the appliance for known indicators: a .ctxs.receiver file under the LogonPoint custom directory, unexpected Alias entries in httpd.conf, /tmp/.uxdport or /tmp/.uxdlock files, and a setuid /bin/sh. Repeated DTLS handshake failures and packet-engine crashes are corroborating log signals.

What are WHIPSHOT and SLAPSHOT?

WHIPSHOT is a PHP web shell that reads commands from HTTP header fields and returns fake 404 responses to hide activity. SLAPSHOT is a Python tunneling tool that forwards traffic into the internal network and drops idle sessions after roughly 15 minutes. Mandiant reported both tools in this campaign.

What is the fastest mitigation if I cannot patch immediately?

For CVE-2026-88772 only, disabling DTLS and blocking inbound UDP on port 443 upstream stops that specific attack path. It does not address CVE-2026-88771, which needs no special configuration. Installing the fixed build is the only fix that closes both flaws.

Ready to meet the Guardians?

Deploys fast - agentless for monitoring and cloud, a lightweight agent for deep endpoint security. Just Suriq, standing watch.