<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/two-unpatched-citrix-netscaler-zero-days-are-being-actively-exploited-patches-expected-next-week-e5eyibjzc" -->

---
title: Two unpatched Citrix NetScaler zero-days are being...
description: Two unpatched remote code execution vulnerabilities in Citrix NetScaler are being actively exploited in the wild, with no CVEs assigned and no official Citrix...
canonical: https://daily.dev/posts/two-unpatched-citrix-netscaler-zero-days-are-being-actively-exploited-patches-expected-next-week-e5eyibjzc
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Two unpatched Citrix NetScaler zero-days are being actively exploited, patches expected next week | daily.dev
og:description: Two unpatched remote code execution vulnerabilities in Citrix NetScaler are being actively exploited in the wild, with no CVEs assigned and no official Citrix...
og:url: https://daily.dev/posts/two-unpatched-citrix-netscaler-zero-days-are-being-actively-exploited-patches-expected-next-week-e5eyibjzc
og:image: https://api.daily.dev/og/posts/e5eyIbjZC.png
og:image:alt: Two unpatched Citrix NetScaler zero-days are being actively exploited, patches expected next week
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Two unpatched Citrix NetScaler zero-days are being actively exploited, patches expected next week

**[Collections](https://daily.dev/sources/collections)** · 4 min read · 6 upvotes · 0 comments

## Summary

Two unpatched remote code execution vulnerabilities in Citrix NetScaler are being actively exploited in the wild, with no CVEs assigned and no official Citrix advisory yet. The issue surfaced through a leaked pre-notification advisory from Dutch NCSC-NL, later confirmed by watchTowr and researcher Kevin Beaumont. Citrix reportedly discovered the flaws during incident response and plans patches early the following week. Until then, admins are urged to take internet-exposed NetScaler appliances offline or restrict access, given NetScaler's long history as an APT target with 13 entries in CISA's Known Exploited Vulnerabilities catalog.

## Content

Citrix disclosed eight vulnerabilities in NetScaler ADC and Gateway on September 27, 2026, two of which were already being exploited in the wild before patches existed. Both critical flaws carry a CVSSv4 score of 9.5 and allow unauthenticated remote code execution. CISA added them to its Known Exploited Vulnerabilities catalog and ordered federal civilian agencies to patch by September 30 under Binding Operational Directive 26-04.

## The two exploited vulnerabilities

**CVE-2026-88771** is a pre-authentication command injection in `ns_monuploadd_err.pl`. Unsanitized login and User-Agent fields get written to logs, which a Perl script later parses using shell backtick commands. An attacker can inject shell commands that execute as root — either up to 24 hours later when the script runs on schedule, or sooner if triggered manually. No special configuration is required, and attack complexity is rated low, making this broadly exploitable across default NetScaler deployments. The fix replaces the shell pipeline with strict regex-validated Perl parsing and list-form exec calls that don't invoke a shell.

**CVE-2026-88772** is a pre-authentication memory overflow in the NSPPE component's DTLS handshake fragment reassembly. Attackers craft DTLS records that claim a small fragment length while smuggling much larger data, causing a roughly 173KB reassembled message to overflow a 35,840-byte fixed scratch buffer by about 138KB. DTLS is enabled by default on VPN virtual servers, so most Gateway deployments are affected. Attack complexity is rated high, but researchers at watchTowr demonstrated a working exploit chain: bypass the cookie exchange, trigger a crash, hijack a virtual method call, and use a non-PIE ROP chain with mprotect to execute shellcode.

## What attackers are doing with access

Mandiant and Google Threat Intelligence Group tracked active exploitation of CVE-2026-88772 back to early September 2026, targeting government, financial services, technology, education, energy, and legal organizations across North America and Europe. Researchers suspect nation-state involvement.

After gaining root access, attackers deployed two custom malware families:

- **WHIPSHOT**: a PHP web shell that disguises command-and-control traffic inside HTTP headers
- **SLAPSHOT**: a Python tunneling proxy used for internal reconnaissance and credential theft

For persistence, attackers masked web shells as `.deb` and `.sig` files via `httpd.conf` modifications and set the SUID bit on `/bin/sh`.

Citrix published indicators of compromise via NetScaler Console, though it warned these may have limited forensic value on already-compromised systems.

## Timeline

The vulnerabilities were circulating privately before Citrix published anything. A leaked Dutch NCSC-NL pre-notification advisory described two unpatched RCE flaws being actively exploited, confirmed by watchTowr and researcher Kevin Beaumont. Security agencies and IT suppliers privately warned organizations to take internet-exposed appliances offline ahead of expected patches. Citrix reportedly discovered the issues during incident response investigations.

Patches shipped September 27. Over 23,000 NetScaler IP addresses remain exposed on the internet as of disclosure.

## Six additional vulnerabilities

The same advisory, CTX697096, covers six more CVEs (CVE-2026-88773 through CVE-2026-88778, rated 7.0–9.3), addressing HTTP request smuggling, WAF bypass, memory overflow, and TCP sequence prediction issues. None are confirmed exploited in the wild.

## Fixed versions

| Release line | Fixed version |
|---|---|
| NetScaler ADC and Gateway 14.1 | 14.1-73.37 and later |
| NetScaler ADC and Gateway 13.1 | 13.1-64.23 and later |
| FIPS and NDcPP builds | Corresponding updated builds available |

## What to do

Patch immediately, but don't stop there. Patching removes the vulnerability; it doesn't evict an attacker who's already inside. Unit 42 and Mandiant both recommend:

1. **Preserve forensic evidence before patching** — updates can overwrite artifacts needed to determine whether a system was compromised
2. **Hunt for signs of compromise**: suspicious admin sessions, unexpected outbound connections, unfamiliar files in web directories, SUID modifications
3. **Isolate affected systems** if compromise is suspected
4. **Rotate credentials** for accounts that authenticated through affected appliances
5. **Restrict network access** to management interfaces

Mandiant published detailed hunting queries, YARA rules, and IOCs. watchTowr released a detection artifact generator script on GitHub.

This brings CISA's total count of flagged Citrix vulnerabilities to 26 since November 2021. Roughly two-thirds of past NetScaler exploitation has been attributed to APT groups, and 13 NetScaler-related entries now sit in the KEV catalog.

## Questions this post answers

### Are there active exploits against Citrix NetScaler right now with no patch available?

Yes, two unpatched remote code execution vulnerabilities in Citrix NetScaler are being actively exploited in the wild. No CVEs have been assigned and no official Citrix advisory exists yet. The flaws are unrelated to previously disclosed CVE-2026-19490 and CVE-2026-19489, and Citrix discovered them during incident response rather than proactive research.

_Admins managing NetScaler exposure can track fast-moving vulnerability disclosures like this one on daily.dev._

### What should I do with my Citrix NetScaler appliance if there's no patch yet for the active zero-day exploits?

Take internet-exposed NetScaler appliances offline or restrict access until Citrix releases patches, expected early the following week. With active exploitation confirmed and no CVE or advisory published yet, restricting exposure is the only mitigation available, despite the disruption to organizations relying on NetScaler for remote access.

_Security teams weighing uptime against exposure risk follow guidance like this through daily.dev._

### How often is Citrix NetScaler targeted by nation-state hackers compared to other exploited vulnerabilities?

NetScaler has a long history as a high-value target, with 13 NetScaler-related entries in CISA's Known Exploited Vulnerabilities catalog and roughly two-thirds of past exploitation attributed to APT groups. Threat actors actively hunt for NetScaler flaws and often move quickly once details become public, unlike more opportunistic attacks against other products.

_Teams assessing NetScaler's risk profile can keep tabs on its exploitation history through daily.dev._

## Similar posts on daily.dev

- [Citrix NetScaler bug may be multiple flaws in one](https://daily.dev/posts/citrix-netscaler-bug-may-be-multiple-flaws-in-one-kggs3gauu) · The Register · 0 upvotes · 0 comments
- [CVE‑2026‑3055](https://daily.dev/posts/cve-2026-3055-agwr1jxtq) · Arctic Wolf · 0 upvotes · 0 comments
- [Critical Citrix NetScaler Flaw Draws CitrixBleed Comparisons as Exploitation Window Narrows](https://daily.dev/posts/critical-citrix-netscaler-flaw-draws-citrixbleed-comparisons-as-exploitation-window-narrows-iikwjwkhl) · IT Security Guru · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#zero-day](https://daily.dev/tags/zero-day)

[View this post on daily.dev](https://daily.dev/posts/two-unpatched-citrix-netscaler-zero-days-are-being-actively-exploited-patches-expected-next-week-e5eyibjzc)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Two unpatched Citrix NetScaler zero-days are being actively exploited, patches expected next week","url":"https://daily.dev/posts/two-unpatched-citrix-netscaler-zero-days-are-being-actively-exploited-patches-expected-next-week-e5eyibjzc","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/two-unpatched-citrix-netscaler-zero-days-are-being-actively-exploited-patches-expected-next-week-e5eyibjzc"},"datePublished":"2026-09-27T16:04:11.242Z","dateModified":"2026-09-29T13:57:11.721Z","description":"Two unpatched remote code execution vulnerabilities in Citrix NetScaler are being actively exploited in the wild, with no CVEs assigned and no official Citrix...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/4d3295ee2536198faf30afbadbe51442?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/4d3295ee2536198faf30afbadbe51442?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/two-unpatched-citrix-netscaler-zero-days-are-being-actively-exploited-patches-expected-next-week-e5eyibjzc","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":6},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,zero-day","timeRequired":"PT4M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"Two unpatched Citrix NetScaler zero-days are being actively exploited, patches expected next week"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/two-unpatched-citrix-netscaler-zero-days-are-being-actively-exploited-patches-expected-next-week-e5eyibjzc#faq","mainEntity":[{"@type":"Question","name":"Are there active exploits against Citrix NetScaler right now with no patch available?","acceptedAnswer":{"@type":"Answer","text":"Yes, two unpatched remote code execution vulnerabilities in Citrix NetScaler are being actively exploited in the wild. No CVEs have been assigned and no official Citrix advisory exists yet. The flaws are unrelated to previously disclosed CVE-2026-19490 and CVE-2026-19489, and Citrix discovered them during incident response rather than proactive research. Admins managing NetScaler exposure can track fast-moving vulnerability disclosures like this one on daily.dev."}},{"@type":"Question","name":"What should I do with my Citrix NetScaler appliance if there's no patch yet for the active zero-day exploits?","acceptedAnswer":{"@type":"Answer","text":"Take internet-exposed NetScaler appliances offline or restrict access until Citrix releases patches, expected early the following week. With active exploitation confirmed and no CVE or advisory published yet, restricting exposure is the only mitigation available, despite the disruption to organizations relying on NetScaler for remote access. Security teams weighing uptime against exposure risk follow guidance like this through daily.dev."}},{"@type":"Question","name":"How often is Citrix NetScaler targeted by nation-state hackers compared to other exploited vulnerabilities?","acceptedAnswer":{"@type":"Answer","text":"NetScaler has a long history as a high-value target, with 13 NetScaler-related entries in CISA's Known Exploited Vulnerabilities catalog and roughly two-thirds of past exploitation attributed to APT groups. Threat actors actively hunt for NetScaler flaws and often move quickly once details become public, unlike more opportunistic attacks against other products. Teams assessing NetScaler's risk profile can keep tabs on its exploitation history through daily.dev."}}]}
```

