Citrix NetScaler: two pre-auth RCEs, 50,277 exposed instances, CISA deadline Sept 30
> TL;DR: CISA added two critical Citrix NetScaler flaws to the Known Exploited Vulnerabilities. CVE-2026-88771: unauthenticated arbitrary code execution, CVSS 9.5, across all NetScaler ADC and Gateway deployments. CVE-2026-88772: memory corruption, RCE or DoS, CVSS 9.5, when DTLS is enabled — the default on VPN virtual servers. FCEB remediation deadline: September 30, 2026. First exploitations were observed on September 24.
Two CVEs, one attacker profile
Two flaws, two CVSS 9.5s, one reachable without any authentication. For a VPN gateway or load balancer, that is the most direct entry profile there is.
What watchTowr's PoC shows
watchTowr Labs researchers traced CVE-2026-88771 back to a Perl script, ns_monuploadd_err.pl. The script processes crash or error information and builds a shell command from attacker-influenced input. Result: code execution as root.
The trigger: a pre-authentication POST to /nf/auth/doAuthentication.do. The PoC injects, for example, id>/var/tmp/watchTowr into the login parameter. No session, no cookie, no token.
It is the same class of flaw seen in NetScaler for years: an error input that becomes a shell command. Fixes exist since versions 14.1-73.37 and 13.1-64.23 (and their FIPS equivalents) — but CISA's KEV listing indicates attacks are already underway.
Attacks are already observed
149.104.78.141. Observed behavior: setuid/setgid on /bin/sh, a cookie-based password-protected webshell, .ctxs.receiver handled as PHP, receiver.min.css routed to the webshell, and httpd killed to force a restart.The post-exploitation behavior — a CSS file executing as PHP, a process killed to force a reload — looks like an actor settling in for the long term, not testing.
What to check right now
/nf/auth/doAuthentication.do with abnormal payloads, unexpected files in the appliance's filesystem.The takeaway
NetScaler is no longer a surprise: it is the same gateway for years, the same class of flaw, the same post-exploitation IOCs. The difference in 2026 is the speed between the KEV and the first exploits — observed three days before the CISA listing. The 50,277 exposed instances are not an abstract number: they are a list of candidates. Your gateway is on it, or it is not. Check which of the two.
Building software? CleanIssue performs security audits for your product in real-world conditions, no source code access needed. For a first read of your exposure, start with an external review of your application.
Related articles
Three adjacent analyses to keep exploring the same attack surface.
N-able N-central CVE-2026-86218: CVSS 10 Pre-Auth RCE Exploited, One Month After August Flaw
A static code injection (CVE-2026-86218, CVSS 10.0) enables pre-authentication remote code execution in N-central, fixed by the September 5 Hotfix 4. N-able confirms active exploitation, CISA lists it in KEV (September 11 deadline), and Huntress investigates a fully patched customer server compromised September 4. Two chainable same-day flaws allow creating a rogue administrator account.
SharePoint CVE-2026-58644: a critical RCE zero-day added to the CISA KEV catalog
A deserialization flaw (CVSS 9.8) in Microsoft SharePoint Server lets an attacker authenticated as Site Owner execute arbitrary code remotely. Actively exploited as a zero-day, added to the CISA KEV catalog on July 16, 2026 with a July 19 remediation deadline.
GitLab CVE-2026-85706: Unauthenticated Arbitrary File Read (CVSS 10), Scanned Within Hours
A path traversal in the repository commits API (CVE-2026-85706, CVSS 10.0) lets an unauthenticated user read arbitrary files from the GitLab server — logs and configuration holding credentials and secrets — as soon as one public project exists. Active probes observed September 11; CISA KEV with a September 14 deadline. Fixes: 19.1.8, 19.2.6, 19.3.2, also covering an EE deserialization flaw (CVE-2026-87719, 9.9).
Sources
Related services
If this topic maps to a real risk in your stack, these are the most relevant ActionShield audits.