Two pre-authentication flaws in NetScaler ADC and Gateway (CVE-2026-88771 and CVE-2026-88772, CVSS 9.5) were exploited before any fix existed and are now used by many attacker groups. Updating is urgent but not enough: every appliance exposed before patching must be checked for web shells.
What happened
On 27 September 2026 Citrix released fixes for eight vulnerabilities in NetScaler ADC and NetScaler Gateway. Two of them let an unauthenticated attacker run code on the appliance, and both were already being exploited before the patches came out:
- CVE-2026-88771 (CVSS 9.5): insufficient input validation that allows command injection through crafted authentication data.
- CVE-2026-88772 (CVSS 9.5): memory corruption in the DTLS handling of the packet engine (NSPPE), giving root-level access.
According to Citrix, every unpatched appliance is vulnerable in its default configuration. Public exploit code exists for both flaws, and since 28 September researchers have seen mass exploitation by several independent groups, used to recruit devices into botnets and to resell access to victims' networks.
What attackers do once inside
Investigations by Mandiant/Google and LevelBlue describe dozens of compromised organisations in Europe and North America — government, finance, technology, education and professional services. Observed activity includes:
- PHP web shells (one family is named WHIPSHOT) disguised as
.debor.sigfiles and reached through URLs that look like icon requests under/vpn/media/; - a Python tunnelling tool (SLAPSHOT) used to reach internal hosts and harvest credentials;
- theft of the NetScaler configuration, reverse shells and creation of privileged accounts;
- persistence through changes to the appliance's own web server configuration.
What to do now
- List every NetScaler ADC and Gateway you run, FIPS builds included, and check its version.
- Update without waiting to 14.1-73.37 (14.1-73.37 FIPS), 13.1-64.23, or 13.1-NDcPP 13.1.37.279 for 13.1-FIPS. If you cannot patch today, take the appliance off the internet until you can — the Dutch NCSC reportedly advised organisations to shut them down.
- Assume it may already be compromised, since the flaws were exploited before the fix. Look for DTLS
Handshake failure-Internal Errorentries in syslog,NSPPE … exit with orphan ringsorpitboss NOT restarting NSPPEin/var/log/messages, unexpected files in/var/netscaler/gui/vpn/scripts/linux/, changes to the web server configuration and administrator accounts you did not create. - If you find anything, treat it as an incident: isolate the appliance, rebuild it from a clean image, rotate every credential that went through it (LDAP/AD service accounts, certificates, user sessions), then look for lateral movement inside your network.
Our take
VPN gateways and load balancers face the internet, sit outside the reach of endpoint protection and handle your users' passwords — which is exactly why attackers go after them. Keep their administration interface off the internet, send their logs to a system an intruder cannot alter, and plan emergency patch windows for these devices before the next zero-day.
Sources
- CERT-FR — CERTFR-2026-ALE-011
- CERT-FR — CERTFR-2026-AVI-1235
- Citrix — Security bulletin CVE-2026-88771 to CVE-2026-88778
- The Hacker News — Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT
- The Hacker News — Citrix NetScaler Post-Exploitation Payload Creates Superuser
- UnderNews — Le GTIG dévoile l’exploitation d’une faille zero-day Citrix
Worried your servers are exposed? Our team audits, patches and monitors Linux and cloud infrastructure 24/7.
Talk to an expert