Citrix NetScaler Zero-Day: 7 Steps to Take Today

A Citrix NetScaler zero-day pair, tracked as CVE-2026-88771 and CVE-2026-88772, has been exploited in the wild for weeks, and patches only shipped on Sunday, September 28, 2026.

If your company runs NetScaler ADC or Gateway as its front door for remote access, this is not a “patch next maintenance window” story. Attackers were inside some networks long before the public heard a word. Let me walk through what is known and what to do first.

What Happened With the Citrix NetScaler Zero-Day

Two separate flaws were disclosed, and either can be used on its own. CVE-2026-88771 is an improper input validation bug that allows unauthenticated remote code execution on default configurations, with no user interaction. CVE-2026-88772 is a memory overflow that can lead to remote code execution or denial of service, but it only applies when DTLS is enabled, which is the default on virtual VPN servers.

According to Help Net Security, researcher Kevin Beaumont said the exploitation had been unfolding for the entire month. The Dutch National Cyber Security Center warned European governments about active attacks, rumors went public on Friday, and Citrix released fixes the following Sunday.

Which Versions Are Affected

The list is wide. NetScaler ADC and Gateway version 14.1 before 14.1-73.37 and version 13.1 before 13.1-64.23 are vulnerable. Certain NetScaler ADC FIPS builds are affected too, and so are Secure Private Access Hybrid deployments that rely on NetScaler instances.

Check your exact build number rather than assuming. Many teams discover a forgotten appliance in a branch office or a disaster recovery site during exactly this kind of incident.

Why This One Is Nasty

Zero-days on edge devices are the worst case for defenders. The appliance sits on the internet by design, it holds credentials and session data, and many companies have weak logging on it.

Reporting indicates attackers deployed a unique webshell per target and ran anti-forensics commands to hide their tracks. Citrix published a detection script, but it only works if logs have not rotated since the compromise. Given that the attacks ran for weeks, rotation is a real concern.

Tenable noted that roughly two-thirds of historical NetScaler attacks involved state-linked APT groups, while about one-third involved ransomware crews. In plain terms: you may be dealing with a spy, a criminal, or both.

Government agencies are reacting fast. As reported here, CISA ordered federal civilian agencies to patch by September 30 and perform forensic triage. That deadline has already passed, so private companies are now the ones playing catch-up.

The 7 Steps to Take Today

Do these in order. Do not skip step two.

Step 1: Find every NetScaler instance. Include virtual appliances, test systems and anything managed by a vendor. Write down the build number for each.

Step 2: Preserve evidence before patching. The Dutch NCSC advises backing up device memory and logs going back at least one month before you upgrade. Patching wipes volatile data, and that data may be the only proof of what happened.

Step 3: Patch. Move to 14.1-73.37 or later, or 13.1-64.23 or later, following Citrix’s advisories for FIPS and Secure Private Access builds.

Step 4: Hunt through your SIEM. Researchers suggest searching for suspicious base64 strings and unusual command patterns in logs. Run Citrix’s detection script too, but do not treat a clean result as proof of safety if logs have rotated.

Step 5: Assume credentials are exposed. Rotate passwords, service accounts, certificates and any secrets that passed through the gateway. Force fresh sessions for remote users.

Step 6: Review what the appliance could reach. A compromised gateway is a bridge into your internal network. Look for new accounts, lateral movement and unusual access to file servers or directory services.

Step 7: Tighten the design. Limit management interfaces to internal networks, segment the gateway from critical systems, and set up alerts for configuration changes.

Lessons Beyond This Single Bug

Here is the uncomfortable truth. Every year brings another edge device zero-day, and the pattern rarely changes. Attackers find a flaw, use it quietly, and the world learns about it after the damage is done.

So the long-term fix is not only faster patching. It is assuming that any internet-facing box can fall, and designing so that one fall does not hand over the whole company. That means zero trust access, strong network segmentation, and logging that is stored off the device and kept long enough to be useful.

It also means rehearsing. Run a tabletop exercise where your VPN gateway is compromised and ask who has authority to shut it down at 2 a.m. If the answer is unclear, you have found your next project.

Key Takeaways

  • Two flaws, two paths in: CVE-2026-88771 and CVE-2026-88772 can each be exploited independently, and the first needs no authentication on default setups.
  • Exploitation came first: Attacks ran for weeks before patches arrived on September 28, 2026.
  • Collect evidence before you patch: Back up memory and at least a month of logs so investigators have something to work with.
  • A clean script is not a clean bill of health: Citrix’s detection only works if logs have not rotated.
  • Design for failure: Segmentation, off-box logging and zero trust limit the damage when an edge device falls.

How TecniForge Can Help

At TecniForge, we help businesses navigate these technology shifts. Whether you need custom software development, AI integration, or cloud migration, our team builds scalable solutions. Talk to our experts.

One last question for your security lead: if your remote access gateway were compromised today, how long would it take you to find out?


Discover more from TecniForge

Subscribe to get the latest posts sent to your email.