The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Sunday added two critical Citrix NetScaler ADC and Gateway flaws to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation.
The vulnerabilities are listed below -
CVE-2026-88771 (CVSS score: 9.5) - An improper input validation vulnerability that could allow an unauthenticated attacker to
Ravie LakshmananSep 28, 2026Vulnerability / Network Security
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Sunday added two critical Citrix NetScaler ADC and Gateway flaws to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation.
The vulnerabilities are listed below -
While CVE-2026-88771 affects all NetScaler ADC and NetScaler Gateway deployments, CVE-2026-88772 requires the DTLS configuration to be enabled on NetScaler ADC or NetScaler Gateway, an option that is turned on by default on VPN virtual servers. The relevant configuration is as follows -
add vpn vserver vpn1 SSL 10.0.0.0 443 -Listenpolicy NONE
Both the issues have been addressed in the versions below -
"CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally," the agency said.
"Because updating Citrix NetScaler appliances can be complex and may require downtime, CISA is issuing this alert to help organizations assess exposure, prioritize mitigation, and account for these vulnerabilities into their risk-management activities."
Citrix has also made generic indicators of compromise (IoCs) available through NetScaler Console to help customers determine if their deployments have been impacted. If a compromise is suspected, customers are recommended to perform the following steps to secure their environments -
In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies have been given time until September 30, 2026, to apply the fixes.
UpdatewatchTowr Labs, on September 28, 2026, said CVE-2026-88771 is rooted in a Perl script named "ns_monuploadd_err.pl" that's used to process NetScaler crash/error information. The preemptive exposure management firm found that the script constructs a shell command using input that can be influenced by an attacker to achieve remote code execution as root.
In other words, an unauthenticated attacker can inject arbitrary shell commands through data that NetScaler writes to its logs, which is then fed as input to a shell command, leading to command injection and remote code execution. This, in turn, can be achieved by sending a pre-authentication request to the "/nf/auth/doAuthentication.do" endpoint to trigger the flaw -
POST /nf/auth/doAuthentication.do HTTP/1.1
Host: netscaler-aaa-server
Content-Type: application/x-www-form-urlencoded
login=<@urlencode_all>pitboss PPE unexpectedly died NSPPE;:`id>/var/tmp/watchTowr`;# X</@urlencode_all>&passwd=x&savecredentials=false&nsg-x1-logon-button=Log+OnPalo Alto Networks Unit 42 said it identified more than 50,277 publicly exposed instances of Citrix NetScaler devices potentially vulnerable to both of the zero-days as of September 27, 2026.
According to GreyNoise, the earliest known exploitation attempt targeting its sensor occurred on September 24. The activity originated from the IP address "149.104.78[.]141," although the malicious cyber actor (MCA) was unsuccessful in their efforts.
"The MCA attempted to set both the Set User ID (setuid) and Set Group ID (setgid) bits on /bin/sh to obtain a root shell and install a password-protected webshell that accepts communication by the cookie value sent by the adversary," the threat intelligence firm said. "This may be to avoid persisting their commands in web logs."
The threat actor is also said to have attempted to configure the web server to treat their installed dot file (".ctxs.receiver") as a PHP file despite not having a .php extension, and create an alias which would route requests for a non-existent cascading style sheet ("receiver.min.css") to .ctxs.receiver.
"The MCA also attempted to create an additional AliasMatch setting which would provide similar functionality but allow for a more flexible pattern match so that variable characters added to the receiver.min.[0-9a-f].css file path would still route to the web shell," GreyNoise said. "Lastly, the adversary attempted to kill the httpd process to restart the server."
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution | 0 | 8.39 | 30-09-2026 |
| 2 | Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT | 0 | 7.9 | 30-09-2026 |
| 3 | Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation | 0 | 9.26 | 27-09-2026 |
| 4 | WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV | 0 | 9.71 | 25-09-2026 |
| 5 | SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild | 0 | 6.8 | 26-09-2026 |
| 6 | Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager | 0 | 9.95 | 30-09-2026 |
| 7 | Citrix Netscaler: Kritische Sicherheitslücken erlauben Codeeinschleusung | 0 | 9.03 | 27-09-2026 |
| 8 | Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets | 0 | 9.2 | 30-09-2026 |
| 9 | Две zero-day без пароля открыли хакерам корпоративные VPN | 0 | 15.56 | 28-09-2026 |
| 10 | Два нулевых дня в Citrix NetScaler эксплуатируют неделями, администраторы отключают шлюзы | 0 | 9.11 | 29-09-2026 |