Two pre-authentication flaws in NetScaler ADC and Gateway (CVE-2026-88771 and CVE-2026-88772, CVSS 9.5) were exploited before any fix existed and are now used by many attacker groups. Updating is urgent but not enough: every appliance exposed before patching must be checked for web shells.

What happened

On 27 September 2026 Citrix released fixes for eight vulnerabilities in NetScaler ADC and NetScaler Gateway. Two of them let an unauthenticated attacker run code on the appliance, and both were already being exploited before the patches came out:

  • CVE-2026-88771 (CVSS 9.5): insufficient input validation that allows command injection through crafted authentication data.
  • CVE-2026-88772 (CVSS 9.5): memory corruption in the DTLS handling of the packet engine (NSPPE), giving root-level access.

According to Citrix, every unpatched appliance is vulnerable in its default configuration. Public exploit code exists for both flaws, and since 28 September researchers have seen mass exploitation by several independent groups, used to recruit devices into botnets and to resell access to victims' networks.

What attackers do once inside

Investigations by Mandiant/Google and LevelBlue describe dozens of compromised organisations in Europe and North America — government, finance, technology, education and professional services. Observed activity includes:

  • PHP web shells (one family is named WHIPSHOT) disguised as .deb or .sig files and reached through URLs that look like icon requests under /vpn/media/;
  • a Python tunnelling tool (SLAPSHOT) used to reach internal hosts and harvest credentials;
  • theft of the NetScaler configuration, reverse shells and creation of privileged accounts;
  • persistence through changes to the appliance's own web server configuration.

What to do now

  1. List every NetScaler ADC and Gateway you run, FIPS builds included, and check its version.
  2. Update without waiting to 14.1-73.37 (14.1-73.37 FIPS), 13.1-64.23, or 13.1-NDcPP 13.1.37.279 for 13.1-FIPS. If you cannot patch today, take the appliance off the internet until you can — the Dutch NCSC reportedly advised organisations to shut them down.
  3. Assume it may already be compromised, since the flaws were exploited before the fix. Look for DTLS Handshake failure-Internal Error entries in syslog, NSPPE … exit with orphan rings or pitboss NOT restarting NSPPE in /var/log/messages, unexpected files in /var/netscaler/gui/vpn/scripts/linux/, changes to the web server configuration and administrator accounts you did not create.
  4. If you find anything, treat it as an incident: isolate the appliance, rebuild it from a clean image, rotate every credential that went through it (LDAP/AD service accounts, certificates, user sessions), then look for lateral movement inside your network.

Our take

VPN gateways and load balancers face the internet, sit outside the reach of endpoint protection and handle your users' passwords — which is exactly why attackers go after them. Keep their administration interface off the internet, send their logs to a system an intruder cannot alter, and plan emergency patch windows for these devices before the next zero-day.

Sources

Worried your servers are exposed? Our team audits, patches and monitors Linux and cloud infrastructure 24/7.

Talk to an expert