| PATCH IMMEDIATELY, THEN ASSUME COMPROMISE CVE-2026-88771: Unauthenticated arbitrary command execution, CVSS 9.5. Affects default NetScaler ADC and Gateway configurations with no additional conditions required. CVE-2026-88772: Memory overflow on DTLS-enabled virtual servers, CVSS 9.5, leading to RCE or DoS. DTLS is enabled by default on DTLS VPN virtual servers. Citrix confirmed active exploitation of both CVEs before the bulletin was published. Both were added to the CISA Known Exploited Vulnerabilities catalog on September 27, 2026. Before you upgrade: collect logs, snapshots, support bundles, and core dumps from every affected device. The upgrade process can overwrite forensic evidence that cannot be recovered after patching. A public proof-of-concept for CVE-2026-88772 was released by independent security researchers on September 29, 2026. Mass automated scanning and exploitation attempts began within hours of that release. Forensic investigation has since established that exploitation began in early September 2026, more than three weeks before the bulletin was published. Any internet-accessible NetScaler deployment running a pre-patch build during this period must be investigated for compromise, not only patched. |
On September 27, 2026, Citrix published bulletin CTX697096 disclosing two critical vulnerabilities in NetScaler ADC and Gateway. Both carry a CVSS score of 9.5. Both had been exploited in the wild for weeks before the bulletin was published. The Netherlands NCSC had already issued a pre-disclosure warning to Dutch organizations, reporting confirmed exploitation at multiple Citrix customers worldwide.
The standard response when a critical patch drops is to apply it as fast as possible and treat the incident as closed. That response is incomplete here, and Citrix’s own bulletin makes that explicit. Patching stops new exploitation through these two vulnerabilities. It does not remove an attacker who entered before the fix was applied. It does not recover credentials that may have been harvested. It does not reverse configuration changes made after a device was compromised. The patch closes the door. The question that follows is whether someone was already inside when it was locked.
This post covers what the two vulnerabilities do, how the exploitation timeline developed, what attackers are doing with the access they establish, and the seven steps that turn a patch into a completed response rather than a closed ticket.
| 9.5 CVSS score carried by both CVEs, with CVE-2026-88771 exploitable on default configurations without any authentication required | 42,000+ internet-facing NetScaler ADC and Gateway instances publicly identified as potentially exposed at the time of disclosure, the large majority unpatched weeks later | 0 authentication steps required to exploit CVE-2026-88771 and execute arbitrary commands on the target device |
Sources: Citrix security bulletin CTX697096, September 2026 (statistics 1 and 3); internet exposure analysis and Kevin Beaumont independent research, September 2026 (statistic 2)

What These Vulnerabilities Do
CVE-2026-88771 is an improper input validation flaw in NetScaler ADC and Gateway. An unauthenticated remote attacker can send a crafted request that bypasses input validation and executes arbitrary commands on the underlying system. No authentication is required. No special configuration conditions beyond a reachable interface are needed. The vulnerability affects the default configuration.
CVE-2026-88772 is a memory overflow in the DTLS protocol handling code. When DTLS is active on a virtual server, a crafted DTLS handshake can overflow a memory buffer, resulting in either remote code execution or a denial-of-service condition. DTLS is enabled by default on DTLS VPN virtual servers. Organizations that have deployed NetScaler Gateway for VPN access with the default DTLS configuration are affected without any additional modification required on their part.
The technical mechanism underlying CVE-2026-88772 involves a parsing inconsistency in DTLS handshake handling. NetScaler accepts the fragment_length field in DTLS handshake records without validating it against the actual data present in the payload. By sending fragmented records where the declared fragment length does not match the actual payload size, an attacker can cause the device to overflow a memory buffer during reassembly. Security researchers have demonstrated that this overflow can be used to redirect control flow to arbitrary code executing with root privileges. The reliability of exploitation varies with device version, but no authentication is required at any point in the attack chain.
CTX697096 patches a total of eight vulnerabilities. CVE-2026-88771 and CVE-2026-88772 are the two with confirmed active exploitation and the highest severity scores. The remaining six vulnerabilities (CVE-2026-88773 through CVE-2026-88778) include HTTP request smuggling, policy bypass, and additional memory overflow flaws. None of those six carry confirmed active exploitation at the time of disclosure, but all are remediated in the same fixed builds listed in this bulletin. Upgrading to the minimum fixed build addresses the full set.
| CVE | Vulnerability Type | Authentication Required | Affected Configuration | CVSS | Primary Impact |
| CVE-2026-88771 | Improper input validation | None | Default configuration | 9.5 | Arbitrary command execution |
| CVE-2026-88772 | Memory overflow (DTLS) | None | DTLS VPN virtual server (default enabled) | 9.5 | RCE or DoS |
| CVE-2026-88773 to 88778 | HTTP request smuggling, policy bypass, memory overflow | Varies | Varies | Lower | Lateral abuse, policy circumvention |
Source: Citrix security bulletin CTX697096, September 2026
The Exploitation Timeline
The most significant detail in CTX697096 is not the CVSS score. It is the exploitation status at the time of disclosure: and how far back that exploitation actually started.
Citrix’s bulletin states that ‘exploits on unmitigated NetScaler deployments have been observed.’ Forensic investigation of compromised organizations has since established that exploitation began in early September 2026, more than three weeks before the public bulletin was available. Teams reading CTX697096 on September 27 were not receiving an early warning. They were receiving confirmation that a vulnerability already in active use for weeks had been identified and fixed. Threat monitoring telemetry recorded first automated exploitation attempts on September 24, three days before the Citrix advisory, indicating that scanning for vulnerable targets was already underway before the vulnerability was public knowledge.
The Netherlands NCSC’s involvement adds geographic and operational context. Their pre-disclosure advisory, distributed to Dutch organizations before the public bulletin was available, reported confirmed exploitation at multiple Citrix customers worldwide. Organizations reached by the NCSC warning did not yet have a published CVE or a patch to reference. They were being notified that their perimeter devices were targets of an ongoing campaign.
Both CVEs were added to the CISA Known Exploited Vulnerabilities catalog on September 27, 2026, the same day as the Citrix bulletin. The simultaneous KEV listing means exploitation intelligence had been collected and validated before the coordinated public disclosure. Both listings carried no remediation grace period given the severity and active exploitation status.
On September 29, 2026, independent security researchers published a proof-of-concept for CVE-2026-88772. Within hours, security monitoring services recorded a sharp escalation in scanning and exploitation attempts across the internet. As of that date, fewer than 10 percent of the approximately 42,000 internet-facing NetScaler instances identified as potentially exposed were running a patched build. The exploitation campaign shifted from targeted to opportunistic at that point. Organizations that had not yet patched were moving from a period of selective targeting to mass automated attack coverage. (Source: BleepingComputer and Help Net Security, September 2026; Kevin Beaumont independent research, September 2026)
| Confirmed Active Exploitation Before Public Disclosure Citrix, CTX697096, September 27, 2026: “Exploits on unmitigated NetScaler deployments have been observed. Customers are strongly advised to install the recommended builds immediately.” Netherlands NCSC, pre-disclosure advisory: “Exploitation has been identified at multiple Citrix customers worldwide.” CISA, September 27, 2026: Both CVEs added to the Known Exploited Vulnerabilities catalog concurrent with the Citrix bulletin, confirming that exploitation evidence had been collected and validated before public disclosure was coordinated. |
How Attackers Are Operating After Initial Access
Incident response investigation of compromised NetScaler deployments has produced a consistent post-exploitation pattern. The following describes the documented attack chain based on findings reported by incident response teams. (Source: BleepingComputer, September 2026)
After achieving initial code execution through CVE-2026-88771 or CVE-2026-88772, attackers escalate to root access through the device’s Packet Processing Engine or through heap memory corruption. From root, the /bin/sh binary is modified with the setuid bit, establishing a persistent privilege escalation path that survives a device restart and is independent of the original vulnerability.
Persistence is implemented through PHP webshells placed in the device’s Logon Point directory and routed through modified web server configuration. Attackers place a password-protected webshell at /var/netscaler/logon/LogonPoint/custom/.ctxs.receiver and add an Alias entry to httpd.conf so that incoming CSS file requests execute the shell rather than returning static content. The CSS routing conceals the shell’s activation from URL-based log review, since the requests appear to be routine stylesheet fetches.
Additional persistence has been documented through .deb and .sig files placed in software distribution directories, containing embedded PHP code that executes despite the non-PHP file extension. This provides a second persistence path that survives reviews focused on .php file extensions.
Once persistence is established, attackers deploy a PHP-based proxy tool and a Python-based TCP tunnel to relay traffic from external attacker infrastructure through the NetScaler appliance into internal network segments. This enables lateral movement without direct inbound connections from external addresses to internal hosts. Outbound traffic from compromised devices has been observed destined for a Hetzner-hosted server at 138.199.200.90, with DNS beaconing to subdomains under instances.httpworkbench.com. (Source: Help Net Security and Kevin Beaumont independent research, September 2026)
The post-exploitation pattern is consistent with targeted intrusion objectives rather than ransomware deployment. Independent researcher Kevin Beaumont tracked more than 100 victim organizations with active webshell installations as of September 29, 2026, and noted that the installations are not detectable from outside the device’s file system. Targeted sectors identified across investigation findings include government, financial services, education, legal, and professional services organizations.
Key Forensic Artifacts
| Artifact | Type | Notes |
| /var/netscaler/logon/LogonPoint/custom/.ctxs.receiver | PHP webshell | Password-protected; hidden via httpd.conf CSS routing |
| Modified /etc/httpd.conf | Configuration change | Suspicious Alias entries redirect CSS requests to the webshell path |
| /bin/sh with setuid bit | Privilege escalation path | Allows root re-escalation independent of original vulnerability |
| /tmp/.uxdport or /tmp/.uxdlock | Tunneling artifact | Temporary files associated with TCP tunnel deployment |
| .deb or .sig files with PHP content | Alternate persistence | Non-PHP extensions used to evade extension-based file review |
| Outbound connections to 138.199.200.90 | C2 indicator | Hetzner-hosted exfiltration and command-and-control server |
| DNS queries to *.instances.httpworkbench.com | Beaconing indicator | Associated with deployed tunneling tooling |
Source: BleepingComputer, September 2026; Help Net Security, September 2026; Kevin Beaumont independent research, September 2026
Fixed Builds
The following builds address all eight CVEs in CTX697096, including CVE-2026-88771 and CVE-2026-88772. Upgrade to the minimum fixed build listed for the applicable release branch, or to any later version in that branch.
| Product | Minimum Fixed Build |
| NetScaler ADC / Gateway 14.1 | 14.1-73.37 |
| NetScaler ADC / Gateway 13.1 | 13.1-64.23 |
| NetScaler ADC FIPS | 14.1-73.37 FIPS |
| NetScaler ADC FIPS and NDcPP 13.1 | 13.1-37.279 |
Source: Citrix security bulletin CTX697096, September 2026
The Mandatory Steps from Patch to Closure
Applying the patch resolves the vulnerability. It does not close the incident. Organizations with NetScaler ADC or Gateway deployments that were internet-accessible before the fixed build was applied should treat the following seven steps as required, not optional, before declaring the response complete.
Step 1: Capture Evidence Before You Upgrade
From every affected device, collect system logs, a full snapshot, a support bundle, and a core dump before initiating the upgrade. The upgrade process can overwrite or delete artifacts required for forensic analysis. Evidence collection must happen before patching, not after. If a device was accessed during the exploitation window, the artifacts collected in this step are the primary inputs for any subsequent forensic investigation. Evidence collected after patching may be incomplete or absent.
Step 2: Upgrade and Verify the Running Build
Apply the fixed build from the table above. Once the upgrade completes, explicitly confirm that the running version matches the target build before proceeding to subsequent steps. Do not treat a completed upgrade process as confirmation that the correct build is active. Verify the version independently.
Step 3: Rotate Every Credential the Device Touched
Rotate all passwords, secrets, and certificates stored on the device or processed through it during the period it was running a vulnerable build. This includes: service account passwords used for management access to the appliance, API keys authenticated through the NetScaler, VPN credentials and pre-shared keys terminated at the Gateway, SSL certificates the appliance handled, and any other credential material that passed through the device. Assume that a capable attacker with arbitrary command execution access could have harvested any of these during the exploitation window.
Step 4: Run the IOC Scan in NetScaler Console
NetScaler Console version 14.1-73.36 or later provides a Security Advisory page with an automated IOC scan covering indicators associated with CVE-2026-88771 and CVE-2026-88772. This scan requires telemetry to be enabled. Run it against all affected instances after the upgrade is complete. Document the results as part of the incident record before proceeding to manual investigation.
Step 5: Do Not Treat a Clean Scan Result as a Clean System
| IOC SCANNING DOES NOT COVER EVERY TECHNIQUE Citrix states explicitly in CTX697096 that the automated IOC scan does not cover every technique a threat actor may have used after gaining access through these vulnerabilities. A scan result showing no indicators is a partial result, not confirmation of a clean system. It eliminates specific known indicators. It does not eliminate the possibility that the device was accessed during the exploitation window through a technique the scan does not detect. Manual investigation (Step 6) is required in addition to the automated scan, not instead of it. |
Step 6: Hunt for Persistence Manually
Conduct a manual review of each affected device for indicators the automated scan does not cover. Incident response findings from confirmed compromises have identified a consistent set of artifacts associated with the observed attack chain. Prioritize each of the following during manual review:
- /var/netscaler/logon/LogonPoint/custom/.ctxs.receiver: PHP webshell hidden behind CSS routing; check httpd.conf for matching Alias entries that redirect stylesheet requests to non-standard paths
- /etc/httpd.conf: look for Alias or handler directives that associate CSS, image, or other static file extensions with PHP execution or file paths outside the expected web root
- /bin/sh: check for the setuid bit, which should not be present under normal operation and indicates post-exploitation privilege escalation setup
- /tmp/.uxdport or /tmp/.uxdlock: temporary files associated with deployed network tunneling tooling
- .deb and .sig files in software distribution directories: inspect for PHP content embedded in files with non-PHP extensions, used to create persistence that survives extension-based file review
- Outbound connections to 138.199.200.90 and DNS queries to subdomains of instances.httpworkbench.com: associated with the C2 and tunneling infrastructure observed in confirmed compromises
In addition to artifact-based review: look for unexpected running processes, unauthorized configuration changes, outbound connections to destinations outside the known integration list, and unauthorized administrative sessions. Export logs to an external SIEM if not already in place. Enable File Integrity Monitoring to establish a post-investigation baseline.
Step 7: Preserve Evidence and Escalate If Findings Exist
If any step in the investigation surfaces a suspicious finding, preserve the evidence before taking further remediation action. Engage a qualified forensic incident response team and maintain chain of custody for all collected artifacts. Taking cleanup action on a potentially compromised device before forensic preservation is complete can permanently destroy the evidence needed to determine the scope, duration, and impact of any access that occurred during the exploitation window.

What Brandefense Detects
NetScaler ADC and Gateway are perimeter-facing by design. They are network-discoverable, version-identifiable, and appear in external attack surface inventories when the right monitoring is in place. For both CVE-2026-88771 and CVE-2026-88772, the exposure is visible from outside the network before an attacker targets it, provided the organization has external visibility into what is running on its perimeter.
| Brandefense Capability | Coverage for CVE-2026-88771 and CVE-2026-88772 |
| Vulnerability Intelligence | Tracks CVE-2026-88771 and CVE-2026-88772 using Priority Score context that combines CVSS, EPSS, CISA KEV listing status, exploit availability, and active community signals. Both CVEs carry KEV designation as of September 27, 2026, and public PoC availability as of September 29, 2026, signals reflected in the Priority Score weighting that elevate them above raw CVSS-only prioritization. The Vulnerability DB provides build-to-CVE mapping, allowing organizations to assess which discovered NetScaler instances are running a pre-patch version without manual cross-referencing. |
| Security Findings / VULNERABILITY | Surfaces discovered NetScaler ADC and Gateway instances running pre-patch build versions as BRNDE-EASM- incidents in the VULNERABILITY category. Each finding links the discovered entity to the relevant CVE, the detected running version, and the fixed target build from CTX697096. Findings remain open until the patched build is confirmed on the entity, giving security teams a tracked remediation record for each exposed instance across the external attack surface. |
| Entity Discovery | Discovers NetScaler ADC and Gateway instances through the Domains, IPs, Technologies, and Web Sites tables. Technology fingerprinting identifies the running build version where detectable, providing Vulnerability Intelligence with the asset context needed to correlate discovered entities against CVE-2026-88771 and CVE-2026-88772 automatically. Includes instances from subsidiaries and acquired entities that may not appear in a centrally maintained asset inventory. |
| Security Findings / MISCONFIGURATION | Identifies externally accessible NetScaler management interfaces and DTLS-enabled virtual servers that are discoverable from the public internet as MISCONFIGURATION findings. The DTLS condition required for CVE-2026-88772 exploitation is identifiable through external scanning, providing advance visibility into the specific configuration that expands the vulnerability’s attack surface beyond the base Gateway exposure. |
RELATED READING
No Patch Exists Yet: Who Owns the Pre-Disclosure Window? : the period between exploitation beginning and a patch becoming available: who monitors it, who is responsible, and what organizations can do before a CVE number is assigned https://brandefense.io/blog/pre-disclosure-exploitation/
From Disclosure to Exploit: How Fast Are Threat Actors Weaponizing New CVEs? : the shrinking window between a CVE being published and a working exploit being available in the wild, and what that compression means for patch prioritization on perimeter devices https://brandefense.io/blog/disclosure-to-exploit-speed/
Vulnerability Exploitation Trends: H1 2026: What Threat Actors Are Actually Using : which CVE classes and device categories saw the most active exploitation in the first half of 2026, and where edge devices ranked as an attacker priority https://brandefense.io/blog/vulnerability-exploitation-trends-h1-2026/
Agentic Ransomware: What Happens When Malware Doesn’t Need a Human Operator to Decide Who to Hit Next? : how automated exploitation of perimeter vulnerabilities fits into the broader evolution of attacker tooling, and why unauthenticated RCE on edge devices matters beyond the immediate CVE response https://brandefense.io/blog/agentic-ransomware-autonomous-attack-defense/
Final Thoughts
As of September 29, 2026, the situation has moved beyond the initial disclosure response. A public proof-of-concept for CVE-2026-88772 is available, mass automated scanning is underway, and fewer than 10 percent of the roughly 42,000 identified internet-facing NetScaler instances were running a patched build at that point. More than 100 victim organizations have been identified with active webshell installations that are not detectable from outside the device’s file system. The window between a targeted intrusion campaign and opportunistic mass exploitation closed within 48 hours of the public PoC release.
CVE-2026-88771 and CVE-2026-88772 follow a pattern that is increasingly common with critical edge device vulnerabilities: a default-on attack surface, a CVSS score that guarantees prioritization, and a disclosure timeline that confirms exploitation was already documented before the bulletin reached the teams responsible for patching. The technical fixes are available, the affected builds are specified, and the upgrade path is clear. The harder part is the seven steps that follow patching.
Citrix explicitly calls out that the automated IOC scan does not cover every technique, which is an acknowledgment from the vendor that a confirmed-clean scan result cannot be the endpoint of the response. For any deployment that was network-accessible during the exploitation window that opened in early September, the investigation steps in this post are necessary precisely because the automated tooling is not sufficient on its own. The patch closes the door. The investigation answers the question of what happened while it was open.








