// AI threat desk · 2 Oct 2026
Home/CVE · Vulns & Patches
Vulns & PatchesCriticalCVECVSS 9.5

CISA Lists Two Citrix NetScaler Critical Flaws as Exploited, CVSS 9.5

The US CISA added two critical Citrix NetScaler ADC and Gateway flaws, CVE-2026-88771 and CVE-2026-88772, both CVSS 9.5, to its KEV catalogue on Sep 27, 2026, citing active exploitation worldwide. Federal agencies must patch by Sep 30.

Illustration: a data centre server rack.
File photo: Illustration: a data centre server rack.. Photo: rawpixel (CC0)
Key takeaways
  • CISA added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) catalogue on Sep 27, 2026. Both carry a CVSS score of 9.5.
  • watchTowr Labs said CVE-2026-88771 stems from a Perl script that handles error logs. Attackers can run commands as root without authentication via the /nf/auth/doAuthentication.do endpoint.
  • Unit 42 counted more than 50,277 publicly exposed NetScaler devices worldwide as of Sep 27 that may be affected. GreyNoise detected the earliest exploitation attempt on Sep 24.
On this page

CISA confirms active exploitation of two Citrix NetScaler flaws

The US Cybersecurity and Infrastructure Security Agency (CISA) issued an advisory on Sep 27, 2026, adding CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) catalogue. CISA said reports and partner intelligence confirm threat actors are actively exploiting both flaws worldwide.

CVE-2026-88771 is an improper input validation flaw with a CVSS score of 9.5. It lets an unauthenticated attacker execute arbitrary commands, affecting all NetScaler ADC and NetScaler Gateway deployments. CVE-2026-88772 is an improper restriction of operations within memory buffer bounds flaw, also scored 9.5, which can lead to remote code execution or denial of service. It only triggers on devices with DTLS enabled, a setting on by default for VPN virtual servers.

How the attack works: a faulty logging script used as a command injection channel

Security firm watchTowr Labs explained in a GitHub analysis published the same day that CVE-2026-88771 originates in a Perl script called ‘ns_monuploadd_err.pl’. The script processes NetScaler crash or error log data, but builds shell commands using input that attackers can control.

In other words, an unauthenticated attacker can inject arbitrary shell commands through data written to NetScaler logs. The data is then fed into a shell for execution, causing command injection and remote code execution. Attackers can trigger the flaw by sending a pre-authentication request to the ‘/nf/auth/doAuthentication.do’ endpoint.

Wide exposure, with attempts seen but not confirmed successful

According to Palo Alto Networks' Unit 42, more than 50,277 publicly exposed Citrix NetScaler devices worldwide may be affected by the two zero-day flaws as of Sep 27, 2026.

Threat intelligence firm GreyNoise said its sensors detected the earliest exploitation attempt against the flaw on Sep 24, originating from IP address 149.104.78[.]141. The attempt was not successful. GreyNoise said the attacker tried to set the setuid and setgid bits on /bin/sh to gain a root shell, and attempted to install a password-protected webshell that communicates via cookie values. The attacker also tried disguising hidden installed files as CSS paths to evade detection, and finally attempted to kill the httpd process to restart the server.

CISA sets deadline for federal agencies to patch

Because of the active exploitation, CISA has ordered Federal Civilian Executive Branch (FCEB) agencies to complete patching by Sep 30, 2026. Citrix has also provided generic indicators of compromise (IoCs) via NetScaler Console to help customers determine whether their deployments have been affected.

CISA noted that updating Citrix NetScaler devices can be complex and may require downtime. It issued the alert to help agencies assess their exposure, prioritise mitigation steps, and incorporate both flaws into their risk management activities.

What to do now

  1. Upgrade NetScaler ADC and NetScaler Gateway to 14.1-73.37, 13.1-64.23, or the corresponding FIPS/NDcPP patched versions.
  2. If compromise is suspected, preserve evidence from the NetScaler ADC VPX instance first, then investigate all servers and systems connected to the device for further signs of compromise.
  3. Rebuild the device and update it to the latest firmware. Rotate all local account passwords and key encryption keys (KEK).
  4. If restoring from backup, replace all restored SSL certificates.
  5. Harden device configurations according to best practices and monitor for indicators of compromise.

FAQ

How severe are these two vulnerabilities?

CVE-2026-88771 and CVE-2026-88772 both carry a CVSS score of 9.5, rated critical. CISA has confirmed both are being actively exploited worldwide.

Which NetScaler devices are affected?

CVE-2026-88771 affects all default deployments of NetScaler ADC and NetScaler Gateway. CVE-2026-88772 only affects devices with DTLS enabled, a setting on by default for VPN virtual servers.

Is a patch available?

Yes. Citrix has fixed both vulnerabilities in NetScaler ADC/Gateway 14.1-73.37 and later, 13.1-64.23 and later, and the corresponding FIPS and NDcPP versions.

What is CISA's KEV catalogue?

The [Known Exploited Vulnerabilities](/glossary#kev) (KEV) catalogue is an authoritative list maintained by CISA of vulnerabilities confirmed to have been actively exploited by attackers. Organisations use it to prioritise patching.

Has any organisation been successfully breached?

Based on available information, the exploitation attempt detected by GreyNoise on Sep 24 was not successful. CISA and other sources have not named any specific organisations that have been successfully compromised.

Sources

  1. CISA Adds Two Known Exploited Vulnerabilities to Catalog, CISAPrimary
  2. Known Exploited Vulnerabilities Catalog, CISAPrimary
  3. watchTowr-vs-Citrix-Netscaler-CVE-2026-88771, watchTowr LabsPrimary
Explore with AI