ALERT ESSENTIALS
Citrix disclosed eight NetScaler ADC and Gateway vulnerabilities on September 27, 2026, including two critical zero-days, CVE-2026-88771 and CVE-2026-88772 (both CVSS 9.5), that attackers exploited before any patch existed. CISA added both to its Known Exploited Vulnerabilities (KEV) catalog and reports global exploitation; Citrix has released fixed builds, and there is no workaround for CVE-2026-88771. Upgrading closes the holes but does not evict an attacker who is already inside, so preserve evidence and run Citrix’s indicator-of-compromise (IoC) scan before you patch. Treat every internet-facing NetScaler as potentially compromised until proven otherwise.
THREAT DESCRIPTION
NetScaler ADC (Application Delivery Controller) and NetScaler Gateway sit at the network edge, brokering VPN, load-balancing and authentication traffic. CVE-2026-88771 is an unauthenticated command-injection flaw that affects every deployment, default configuration included. According to watchTowr’s root-cause analysis, attacker-controlled text from a logon attempt, such as the username, is written to appliance logs and later passed to a shell by a background script without validation, so the command can run up to 24 hours after the request. CVE-2026-88772 is a memory overflow in the Datagram Transport Layer Security (DTLS) service on UDP/443, reachable on any Gateway where DTLS has not been explicitly disabled. Observed post-exploitation includes web shells (malicious scripts that give remote control) altered web-server configuration, a shell rigged to run with root rights, and, per Mandiant, a tunnel into the internal network used to harvest credentials.
Exploitation began weeks before disclosure. Unit 42 logged fingerprinting as early as August 21 and web-shell delivery on September 21, GreyNoise recorded exploitation on September 24, and a September 26 Dutch NCSC pre-notification sent administrators pulling appliances offline before Citrix said anything publicly. Exposure counts vary by scanner, from more than 20,000 internet-facing instances (Shadowserver) to 50,277 (Unit 42 Xpanse, September 27). Public proof-of-concept code for both flaws appeared September 28–29, so expect opportunistic exploitation of unpatched appliances to climb. The reporting reviewed does not attribute the activity to a named threat actor.
HEALTHCARE IMPACT
On-prem SharePoint farms are common in healthcare for clinical collaboration and partner document sharing, typically reachable by a broad set of accounts — any one of which meets this flaw’s low bar. A compromised server can expose PHI-adjacent documents and pivot into identity-integrated systems; if patient data was accessible, HIPAA breach notification obligations apply. Shadowserver was tracking 10,000+ internet-exposed SharePoint servers as of early July.
AFFECTED PRODUCTS / CVE REFERENCE
13.1 < 13.1-64.23;
14.1-FIPS < 14.1-73.37 FIPS;
13.1-FIPS/NDcPP < 13.1-37.279.
Also 13.0 and 12.1 (no fix)†. All deployments affected.
13.1-64.23 (64.24 if show ns variable returns output);
14.1-73.37 FIPS;
13.1-37.279
9.5
Remediate by
Sept 30, 2026
(passed)
13.1: End of Maintenance 9/15/26; EOL 9/15/27
FIPS/NDcPP: Unknown
13.0: EOL 7/15/24†
12.1: EOL 5/30/23†
9.5
Remediate by
Sept 30, 2026
(passed)
to
CVE-2026-88778
Six configuration-dependent flaws
7.0–9.3
16,
119,
342
(no exploitation reported)
† EOL/EOS systems cannot receive vendor patches. Immediate isolation or migration is required. NetScaler 13.1 has been in End of Maintenance since Sept 15, 2026; Citrix still shipped this fix, but expect no further code-level updates. CVSS v4.0 scores are Citrix’s as CVE Numbering Authority; NVD had not published its own analysis at last check.
RECOMMENDATIONS
Patching & Remediation
- Triage before you patch. Preserve evidence on every internet-facing appliance first; upgrades and reboots can erase traces (CISA).
- Snapshot the VM with memory, run show techsupport, and copy /var/log/*, /var/nslog/* and the HTTP logs off the box.
- Run the Citrix IoC scan in NetScaler Console (Security Advisory > Indicators of Compromise; use IoC version 3 or later) or request it via Citrix Support citing CTX697096. A clean result means nothing was found, not that the appliance is clean.
- Upgrade every NetScaler to a fixed build now, including both HA nodes, DR, lab and Secure Private Access hybrid instances. Download via your Citrix account; builds are listed in Citrix bulletin CTX697096.
- Fixed builds: 14.1-73.37; 13.1-64.23 (use 13.1-64.24 if show ns variable returns any output, to avoid a reboot loop); 14.1-73.37 FIPS; 13.1-37.279 for 13.1-FIPS/NDcPP.
- Confirm your identity provider signs SAML assertions before upgrading; unsigned assertions are no longer accepted: grep -i “samlRejectUnsignedAssertion OFF” /nsconfig/ns.conf
- If you cannot patch today: nothing mitigates CVE-2026-88771, so take the Gateway off the internet or limit it to known source IP ranges. For CVE-2026-88772 only, disable DTLS (set vpn vserver <name> -dtls OFF) or block inbound UDP/443.
- Enable Enhanced ISN Generation for CVE-2026-88778; the upgrade alone does not fix it: set ns tcpparam -enhancedISNgeneration ENABLED, then save ns config -all (repeat in each admin partition).
- Hunt for compromise, including on patched appliances. Full indicator list is in the Technical Companion.
- Web shells: any PHP under /var/netscaler/logon/LogonPoint/custom/ or /var/vpn, including hidden .ctxs.receiver; check /etc/httpd.conf with grep -Ein “application/x-httpd-php|php_flag|AliasMatch” /etc/httpd.conf
- Injection in logs: zgrep -E ‘died NSPPE;|heartbeats.*;|\$\{?IFS|pitboss.*;’ /var/log/ns.log* /var/log/messages*
- Directory access: LDAP or SMB connections from the NetScaler to domain controllers, and ldapsearch or openssl in /var/log/sh.log*.
- If compromise is suspected, rebuild; do not just upgrade. Isolate the appliance but keep it powered on until evidence is captured, then deploy a new updated instance and migrate the configuration under security review (Citrix CTX694799).
- Rotate every secret on the box: nsroot/admin, LDAP bind, RADIUS, TACACS, SNMP and API credentials, plus TLS certificates and private keys. Do not sync HA from the suspect node.
- Retire unsupported builds. NetScaler 12.1 and 13.0 are EOL and get no fix; isolate and migrate them to 14.1 rather than attempting to patch. Patch 13.1 now, then plan the move to 14.1 before its September 2027 EOL.
- Forward NetScaler logs (ns.log, /var/log/messages, HTTP logs) to a SIEM; appliances often keep only about a day locally.
Admin / Executive Recommendations
- Authorize this as an emergency change, pre-approve clinician remote-access downtime procedures, and inventory every internet-facing NetScaler, including DR, test and MSP-managed units, with written patch and compromise status from each managing vendor.
- If indicators are found, engage incident response and privacy counsel early; credential or ePHI exposure can start HIPAA breach-assessment timelines, so document decisions.
- Fund the 13.1-to-14.1 migration before the September 2027 EOL, or record a formal risk acceptance.
Sources
- Citrix Bulletin CTX697096: support.citrix.com/external/article/CTX697096
- CISA Alert (KEV): cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway
- NVD: nvd.nist.gov/vuln/detail/CVE-2026-88771 and CVE-2026-88772
- Tenable Plugin 350844: tenable.com/plugins/nessus/350844
- Unit 42 Threat Brief: unit42.paloaltonetworks.com/netscaler-zero-days-exploited
- Google/Mandiant Guidance: cloud.google.com/blog/topics/threat-intelligence/defending-against-active-exploitation-of-citrix-netscaler-adc-and-gateway-appliances

From Fortified Health Security
Fortified Health Security is committed to maturing your healthcare organization’s cybersecurity posture. We will monitor and update this bulletin as the situation progresses.
Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies.
Should you have any questions about this threat or any other issue you are facing, please reach out to us. We’re here to help you on your cybersecurity journey.
Email: connect@fortifiedhealthsecurity.com Phone: 615-600-4002