The CISA, CERT-EU, and the NCSC are warning that two critical NetScaler vulnerabilities, CVE-2026-88771 and CVE-2026-88772 (both CVSS 9.5/10), are being actively exploited in the wild. Citrix released patches yesterday (September 27, 2026) for eight vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway products.
- CVE-2026-88771 is an unauthenticated remote code execution vulnerability caused by improper input validation and affects all NetScaler ADC and Gateway deployments, including default configurations.
- CVE-2026-88772 is a memory overflow vulnerability that can lead to remote code execution or denial-of-service attacks when DTLS is enabled, which is the default on NetScaler Gateway deployments.
IOCs
Early reports indicate webshells observed in:
“/var/netscaler/logon/LogonPoint/custom/.ctxs.receiver”
Weblogs containing base64 encoded commands to the following files are also likely indicators:
“/vpn/scripts/linux/nsgclient18.deb” and “/vpn/scripts/linux/nsgclient18_32.deb”
Additionally look for web requests containing the string:
“login=pitboss%20PPE%20unexpectedly%20died%20NSPPE%3Bfetch%24%7BIFS%7D-q%24%7BIFS%7D-T0%24%7BIFS%7D20%24%7BIFS%7D–no-verify-peer:24%7BIFS:7D–no-ver”
(decoded: “login=pitboss PPE unexpectedly died NSPPE;fetch${IFS}-q${IFS}-T0${IFS}20${IFS}–no-verify-peer:24{IFS:7D–no-ver”)
Suggested Action
CyberMaxx strongly urges applying patches immediately. Please reference the Citrix disclosure: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096
Also see the accompanying blog (https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/#Indicators_of_Compromise__cabcb4) for additional details.
Affected Versions and Fixed Builds
| Product | Vulnerable | Fixed | Notes |
| NetScaler ADC and Gateway 14.1 | before 14.1-73.37 | 14.1-73.37 | — |
| NetScaler ADC and Gateway 13.1 | before 13.1-64.23 | 13.1-64.23 or 13.1-64.24 | Use 13.1-64.24 if show ns variable returns results |
| NetScaler ADC 14.1-FIPS | before 14.1-73.37 FIPS | 14.1-73.37 FIPS | — |
| NetScaler ADC 13.1-FIPS / NDcPP | before 13.1-37.279 | 13.1-37.279 | — |