Back Op-C Citrix NetScaler Zero-Days CVE-2026-88771 & CVE-2026-88772 Exploited
Two critical zero-day vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway are being actively exploited to compromise vulnerable appliances.
Tracked as CVE-2026-88771 and CVE-2026-88772, both vulnerabilities carry a CVSS 4.0 score of 9.5 and can result in remote code execution. Citrix released fixes on September 27, 2026, after exploitation had already been observed against unmitigated NetScaler deployments.
The US Cybersecurity and Infrastructure Security Agency (CISA) subsequently added both vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog , stating that threat intelligence and partner reporting confirm attackers are exploiting the flaws globally.
CVE-2026-88771 and CVE-2026-88772 Overview
The more broadly exploitable of the two vulnerabilities is CVE-2026-88771, an improper input validation flaw that allows a remote, unauthenticated attacker to execute arbitrary commands.
Unlike many NetScaler vulnerabilities that require particular features to be enabled, Citrix states that all affected NetScaler ADC and NetScaler Gateway deployments meet the precondition for CVE-2026-88771, including systems running the default configuration. No additional functionality needs to be enabled.
CVE-2026-88772 is a separate memory overflow vulnerability that can result in either remote code execution or denial of service. Exploitation requires Datagram Transport Layer Security (DTLS) to be enabled. However, DTLS is enabled by default on NetScaler VPN virtual servers unless administrators explicitly disable it, significantly increasing the potential exposure.
Both vulnerabilities were exploited as zero-days before Citrix released patched builds.
The two flaws form part of a larger September NetScaler security update covering eight vulnerabilities. The same advisory also fixes a critical HTTP request smuggling vulnerability tracked as CVE-2026-88773, alongside several memory corruption, policy bypass and TCP sequence prediction issues. Citrix has currently confirmed active exploitation only of CVE-2026-88771 and CVE-2026-88772.
How Attackers Exploit CVE-2026-88771
Security researchers have since reconstructed how CVE-2026-88771 can provide attackers with command execution on vulnerable NetScaler appliances.
Analysis from CERT-EU indicates that the vulnerability effectively creates a log injection-to-command execution chain.
Attackers were observed submitting specially crafted values that caused malicious data to be written into NetScaler authentication logs. A NetScaler Perl script called ns_monuploadd_err.pl, which processes Packet Engine crash information, then searched these logs for particular error messages.
The vulnerable code did not sufficiently validate the values extracted from those log entries before incorporating them into another shell command.
As a result, shell metacharacters embedded in attacker-controlled log data could eventually be interpreted as commands rather than ordinary text.
One unusual characteristic of the vulnerability is that execution does not necessarily occur immediately. The malicious log entry is processed when the vulnerable monitoring script runs, creating a delay between initial exploitation attempts and command execution.
Web Shells Observed Following Exploitation
CERT-EU investigations also provide insight into what attackers are doing after gaining command execution.
Researchers observed malicious HTTP requests containing Base64-encoded Bash commands inside User-Agent fields. Once executed, these commands modified the NetScaler Apache configuration to enable PHP processing and deployed a PHP web shell in an internet-accessible directory.
This allows attackers to maintain persistent remote access to the appliance even after the original vulnerability is patched.
CERT-EU determined that attackers were repeatedly injecting malicious entries into both HTTP and authentication logs. The authentication-log payload triggered command execution, while the accompanying HTTP log contained the Base64-encoded commands that were subsequently decoded and executed.
This behavior highlights an important incident response consideration: installing the security update alone may not remove an attacker that has already established persistence.
CISA similarly recommends that organizations investigate exposed appliances and preserve forensic evidence before upgrading wherever operationally possible.
Affected Citrix NetScaler Versions
The following customer-managed NetScaler releases are affected:
Secure Private Access Hybrid deployments using NetScaler instances are also affected.
The bulletin applies to customer-managed NetScaler deployments. Citrix says its managed cloud services have been updated by the company.
Administrators running NetScaler 13.1 should also note that Citrix has identified an unrelated upgrade issue in build 13.1-64.23 that can result in cyclic reboots under specific configurations. Affected customers are advised to upgrade to 13.1-64.24 instead.
Mitigation and Incident Response
Organizations should upgrade vulnerable NetScaler appliances to the appropriate fixed release as soon as possible.
For internet-facing appliances that were exposed before patching, defenders should first preserve relevant forensic evidence where possible. Citrix recommends retaining NetScaler logs and remote syslog records, generating a technical support bundle, and capturing snapshots of virtual NetScaler instances suspected of compromise.
If compromise is suspected, affected appliances should be isolated from the network.
Organizations should also consider rotating credentials and secrets that may have been accessible through the compromised device. Citrix specifically recommends replacing service-account credentials, RADIUS secrets, OAuth tokens, API keys, SNMP community strings and potentially affected user credentials, as well as revoking certificates and private keys stored on the appliance.
Centralizing NetScaler logging in an external SIEM can also improve the ability to identify both historical exploitation and future compromise attempts. Citrix now explicitly recommends forwarding appliance logs to an external logging or SIEM platform for threat detection and forensic investigation.
Stay Safe. Stay Secure. OP Innovate Research Team
Get the latest cybersecurity alerts and insights
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
