watchTowr reported that attackers may be actively exploiting two unpatched remote-code-execution vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances. Citrix had not confirmed the claims or published CVE IDs, affected versions, indicators of compromise, technical details, or fixes, leaving the reports unverified but potentially severe because the appliances commonly serve as internet-facing application-delivery and VPN gateways.
Organizations should inventory NetScaler deployments, restrict or remove unnecessary external and management access, preserve authentication and administrative logs, and monitor exposed appliances for signs of compromise. Teams should be prepared to isolate internet-facing systems where residual risk is unacceptable and rapidly apply Citrix guidance when available; the reported flaws are separate from the vendor's August advisory for actively exploited authentication-bypass vulnerability CVE-2026-19490 and denial-of-service flaw CVE-2026-19489.

See which actors are running it and whether you're in range.
37 events from the most recent confirmed update back to the earliest known activity.
Kevin Beaumont reported awareness of more than 100 organizations affected by the NetScaler zero-day activity and assessed the campaign as espionage-focused. This expanded the reported victim scope beyond Mandiant's prior assessment of dozens of compromised organizations.
GreyNoise observed malicious exploitation of CVE-2026-88771 and CVE-2026-88772 beginning around 8:30 a.m. EDT on September 28, followed by a substantial surge that evening. It assessed that activity had progressed from mass reconnaissance to broad exploitation by multiple actors, including web-shell and malware deployment for botnet recruitment and access brokering.
A contributor opened ProjectDiscovery Nuclei template pull request #17336 proposing a non-destructive detector for CVE-2026-88771 based on poisoned login-request response patterns and an nsepa.deb build-value check. The template was still open, marked unverified, and awaiting maintainer review, so its detection and validation claims had not been accepted by ProjectDiscovery.
The UK National Cyber Security Centre issued an alert covering CVE-2026-88771 through CVE-2026-88778 in customer-managed NetScaler ADC and Gateway appliances. It confirmed active exploitation of CVE-2026-88771 and CVE-2026-88772 and advised organizations to isolate affected systems where possible, investigate using Citrix indicators, update, and continue threat hunting.
As of September 27, 2026, Palo Alto Networks Cortex Xpanse observed more than 50,277 internet-exposed NetScaler ADC and Gateway instances potentially vulnerable to CVE-2026-88771 and CVE-2026-88772.
CISA added Citrix NetScaler CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities catalog. It directed organizations to apply Citrix mitigations, assess internet exposure, conduct forensic triage, and use the provided indicators of compromise in the NetScaler console.
Canada's Cyber Centre issued Alert AL26-024 warning that CVE-2026-88771 and CVE-2026-88772 were reportedly being actively exploited across multiple Citrix customer environments worldwide. It urged prioritization of internet-facing systems, evidence preservation, compromise and persistence investigations, and preparation for recovery actions.
Citrix's September 27 NetScaler security bulletin also addressed CVE-2026-88778, a vulnerability involving predictable TCP initial sequence numbers. This issue was disclosed alongside CVE-2026-88771 through CVE-2026-88777, although confirmed active exploitation applied specifically to CVE-2026-88771 and CVE-2026-88772.
watchTowr publicly warned that reports indicated multiple unpatched remote-code-execution vulnerabilities in Citrix NetScaler ADC and Gateway appliances. The reported flaws were allegedly identified during forensic investigations and exploited in real-world attacks, but Citrix had not confirmed them, assigned CVEs, or released fixes.
GreyNoise observed three attempted CVE-2026-88771 exploitation sessions from 149.104.78.141 against a Project Swarm NetScaler Gateway sensor on September 24, more than three days before public disclosure. The unsuccessful activity attempted to create a root-capable shell and install a concealed cookie-controlled PHP webshell through Apache configuration changes.
Mandiant identified September 3, 2026 as the earliest known exploitation of CVE-2026-88772 and assessed that advanced suspected state-sponsored actors mass-exploited the flaw against dozens of organizations in North America and Europe. The intrusions involved privileged access, lateral movement, sensitive-data theft, internal reconnaissance, credential theft, and novel tunneling malware.
Reporting on the PitScaler campaign said attackers chained CVE-2026-88771, CVE-2026-88772, and CVE-2026-88773 to achieve unauthenticated remote code execution against default NetScaler ADC and Gateway configurations. The activity was reported as active during September 2026 and assessed as likely espionage-focused.
Reporting on exploitation of CVE-2026-88771 and CVE-2026-88772 said attackers deployed webshells unique to each compromised NetScaler appliance and executed anti-forensic commands to delete evidence. The attacks were reported to have occurred throughout September 2026, complicating retrospective detection where logs had rotated.
Google Threat Intelligence Group assessed that exploitation of CVE-2026-88772 had been active since at least early September 2026, targeting or likely affecting organizations in North America and Europe across government, financial, education, legal, and professional-services sectors. Google and Mandiant reported WHIPSHOT and SLAPSHOT were used for persistence and tunneling, including internal reconnaissance and credential theft in at least one intrusion; no public attribution was made.
Norway’s National Security Authority issued a warning about a Citrix NetScaler vulnerability observed under active exploitation. The supplied reference does not identify the CVE or provide further technical details.
Gurucul published threat-hunting indicators for exploitation of CVE-2026-88771 and CVE-2026-88772, including additional IP addresses, three SHA-256 hashes, and suspicious NetScaler file paths. The notice recommended hunting for the indicators in network and endpoint telemetry, including Windows Event ID 4663 activity involving the specified paths.
Finland's National Cyber Security Centre reported receiving information that Citrix NetScaler vulnerabilities were exploited in Finland before Citrix released fixes. It identified hundreds of NetScaler instances in Finland, contacted their administrators, and warned that patching alone may not remove attacker persistence.
watchTowr determined that inconsistent DTLS handshake-length validation in NetScaler's NSPPE can allow an attacker to overflow a 35,840-byte scratch buffer with an oversized chained packet payload. The researchers reported that the overflow can be weaponized for arbitrary shellcode execution as root, including through use of mprotect() to bypass NX protections.
Lupovis observed live exploitation attempts against exposed, unpatched NetScaler appliances within minutes of watchTowr Labs releasing its CVE-2026-88771 proof of concept. The activity was characterized as opportunistic internet-wide scanning, representing an escalation from the earlier targeted zero-day activity.
Mandiant published containment and hunting guidance for CVE-2026-88771 and CVE-2026-88772, identifying UDP/443 DTLS as the delivery path for CVE-2026-88772 and advising upstream blocking or DTLS disablement where patching is delayed. It documented WHIPSHOT and SLAPSHOT tunneling tools, Apache/PHP configuration tampering, a SUID /bin/sh backdoor, log scrubbing, and YARA and host/log indicators for compromise detection.
Hungary’s National Cyber Security Institute issued an alert on actively exploited NetScaler ADC and Gateway vulnerabilities CVE-2026-88771 and CVE-2026-88772. It urged deployment of fixed releases and, for suspected compromise, evidence preservation, isolation, credential and certificate rotation, investigation of connected systems, and appliance rebuilding.
watchTowr disclosed technical details and a proof-of-concept for CVE-2026-88771, showing that attacker-controlled HTTP values logged by NetScaler can reach the ns_monuploadd_err.pl monitoring script and be interpolated into shell commands executing as root. The analysis identified the unauthenticated /nf/auth/doAuthentication.do endpoint as one delivery path and described Citrix's parsing, validation, and shell-execution fixes.
Truesec identified suspicious shell executions, unexpected cron tasks, and memory crash dumps in /var/crash/ as potential indicators of NetScaler compromise. It also identified 104.248.244.66, 139.180.152.138, and 77.83.199.39 as potential command-and-control IP addresses associated with the activity.
The Dutch Ministry of the Interior reportedly took all Citrix environments offline over a weekend in response to the NetScaler vulnerabilities. Two major Dutch hospitals temporarily prevented patients from viewing records, while Frisius MC in Leeuwarden shut down some digital systems as a precaution.
Slovenia’s SI-CERT published an advisory on Citrix NetScaler CVE-2026-88771 through CVE-2026-88778, warning that CVE-2026-88771 and CVE-2026-88772 were actively exploited against unpatched devices. It advised immediate upgrades, stated no temporary workaround exists, and noted that CVE-2026-88778 also requires Enhanced ISN Generation to be enabled.
CERT-FR issued an alert covering Citrix NetScaler ADC and Gateway vulnerabilities CVE-2026-88771 and CVE-2026-88772, warning that both were actively exploited before patches were available. The alert stated that default-configured unpatched appliances are vulnerable and noted that Citrix provides indicators of compromise through the NetScaler console.
Australia’s ASD Australian Cyber Security Centre confirmed that CVE-2026-88771 and CVE-2026-88772 were exploited as zero-days before fixes were available. At the time of its notice, ACSC said it had not received reports of confirmed exploitation in Australia.
NCSC-NL warned that exploitation of CVE-2026-88771 and CVE-2026-88772 had been confirmed, describing unauthenticated command execution and potential gateway takeover for CVE-2026-88771 and service-disrupting memory failures for CVE-2026-88772. It urged urgent updates, preservation of memory dumps and at least one month of logs before patching, and post-patch monitoring for suspicious activity.
CISA ordered U.S. Federal Civilian Executive Branch agencies, under Binding Operational Directive 26-04, to secure vulnerable Citrix NetScaler appliances affected by CVE-2026-88771 and CVE-2026-88772. The directive requires remediation by September 30, 2026.
Cloud Software Group's NetScaler updates were reported to address seven critical flaws, CVE-2026-88771 through CVE-2026-88777. Beyond the two previously confirmed RCE-related flaws, the disclosure identified HTTP request smuggling, a Feature Policy bypass, and additional memory-overflow vulnerabilities; exploitation was reported as observed.
Citrix confirmed active exploitation of CVE-2026-88771 and CVE-2026-88772, two critical NetScaler ADC and Gateway vulnerabilities that can enable unauthenticated remote code execution. It issued fixed releases and urged organizations to patch all nodes and conduct compromise assessments, noting that patching does not remove attacker persistence from prior intrusions.
Canada's Cyber Center urged organizations to apply emergency patches and monitor for unauthorized access associated with the actively exploited Citrix NetScaler authentication-bypass vulnerability CVE-2026-19490.
Organizations reportedly began shutting down or isolating some internet-exposed NetScaler appliances following the unconfirmed RCE zero-day reports and national-authority guidance.
NCSC-NL reportedly issued a pre-notification to organizations regarding two unpatched Citrix NetScaler ADC and Gateway vulnerabilities, assessing that each could independently permit unauthenticated remote code execution. One reported flaw allegedly enables direct in-memory shellcode execution; neither issue had a public CVE, patch, or confirmed indicators of compromise at the time described.
CISA added Citrix NetScaler authentication-bypass vulnerability CVE-2026-19490 to the Known Exploited Vulnerabilities catalog.
Singapore's Cyber Security Agency warned that exploitation attempts targeting the NetScaler authentication-bypass vulnerability CVE-2026-19490 had been observed.
Citrix published a bulletin covering CVE-2026-19490, a critical authentication-bypass flaw under active exploitation, and CVE-2026-19489, a memory-overflow denial-of-service vulnerability. The bulletin provided fixed NetScaler ADC and Gateway versions and stated there was no workaround.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 17 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
50 references tracked. Mallory keeps watching after this page renders.
nsm.no
Open sourcemalware.news
Open sourcecommunity.gurucul.com
Open sourcekyberturvallisuuskeskus.fi
Open sourcecommunity.citrix.com
Open sourcecommunity.citrix.com
Open sourcecommunity.citrix.com
Open sourcecommunity.citrix.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.