Back to blog
CitrixNetScalerRCEzero-dayKEV

Citrix NetScaler: two pre-auth RCEs, 50,277 exposed instances, CISA deadline Sept 30

Published on 2026-09-286 min readActionShield

> TL;DR: CISA added two critical Citrix NetScaler flaws to the Known Exploited Vulnerabilities. CVE-2026-88771: unauthenticated arbitrary code execution, CVSS 9.5, across all NetScaler ADC and Gateway deployments. CVE-2026-88772: memory corruption, RCE or DoS, CVSS 9.5, when DTLS is enabled — the default on VPN virtual servers. FCEB remediation deadline: September 30, 2026. First exploitations were observed on September 24.

Two CVEs, one attacker profile

  • CVE-2026-88771 — improper input validation. Unauthenticated arbitrary code execution, on all NetScaler ADC and Gateway deployments. CVSS 9.5.
  • CVE-2026-88772 — improper restriction of operations within the bounds of a memory buffer. RCE or denial of service, conditioned on DTLS being enabled — the default on VPN virtual servers. CVSS 9.5.
  • Two flaws, two CVSS 9.5s, one reachable without any authentication. For a VPN gateway or load balancer, that is the most direct entry profile there is.

    What watchTowr's PoC shows

    watchTowr Labs researchers traced CVE-2026-88771 back to a Perl script, ns_monuploadd_err.pl. The script processes crash or error information and builds a shell command from attacker-influenced input. Result: code execution as root.

    The trigger: a pre-authentication POST to /nf/auth/doAuthentication.do. The PoC injects, for example, id>/var/tmp/watchTowr into the login parameter. No session, no cookie, no token.

    It is the same class of flaw seen in NetScaler for years: an error input that becomes a shell command. Fixes exist since versions 14.1-73.37 and 13.1-64.23 (and their FIPS equivalents) — but CISA's KEV listing indicates attacks are already underway.

    Attacks are already observed

  • GreyNoise: first confirmed exploitation attempt on September 24, 2026, from 149.104.78.141. Observed behavior: setuid/setgid on /bin/sh, a cookie-based password-protected webshell, .ctxs.receiver handled as PHP, receiver.min.css routed to the webshell, and httpd killed to force a restart.
  • Palo Alto Networks Unit 42: 50,277 instances of NetScaler publicly exposed and potentially vulnerable, as of September 27, 2026.
  • The post-exploitation behavior — a CSS file executing as PHP, a process killed to force a reload — looks like an actor settling in for the long term, not testing.

    What to check right now

  • Patch before the September 30 deadline: 14.1-73.37+, 13.1-64.23+, 14.1-FIPS 14.1-73.37+, 13.1-FIPS/13.1-NDcPP 13.1.37.279+.
  • If you cannot patch immediately, isolate: the gateway is an entry point, not a mandatory path — a temporary detour is better than a permanent exposure.
  • Collect IoCs via NetScaler Console (Citrix publishes them), then preserve evidence before rebuilding.
  • After an incident: revoke credentials, investigate contacted systems, rebuild the appliance, rotate local passwords and the KEK, and replace restored SSL certificates.
  • Look for artifacts in your logs: POSTs to /nf/auth/doAuthentication.do with abnormal payloads, unexpected files in the appliance's filesystem.
  • The takeaway

    NetScaler is no longer a surprise: it is the same gateway for years, the same class of flaw, the same post-exploitation IOCs. The difference in 2026 is the speed between the KEV and the first exploits — observed three days before the CISA listing. The 50,277 exposed instances are not an abstract number: they are a list of candidates. Your gateway is on it, or it is not. Check which of the two.

    Building software? CleanIssue performs security audits for your product in real-world conditions, no source code access needed. For a first read of your exposure, start with an external review of your application.

    Related articles

    Three adjacent analyses to keep exploring the same attack surface.

    Want to know what your AI agent can do?

    Tell us about your agent, its tools, and client context. We will come back with the right review scope.

    Discuss your audit