The CISA, CERT-EU, and the NCSC are warning that two critical NetScaler vulnerabilities, CVE-2026-88771 and CVE-2026-88772 (both CVSS 9.5/10), are being actively exploited in the wild. Citrix released patches yesterday (September 27, 2026) for eight vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway products.

  • CVE-2026-88771 is an unauthenticated remote code execution vulnerability caused by improper input validation and affects all NetScaler ADC and Gateway deployments, including default configurations.
  • CVE-2026-88772 is a memory overflow vulnerability that can lead to remote code execution or denial-of-service attacks when DTLS is enabled, which is the default on NetScaler Gateway deployments.

IOCs

Early reports indicate webshells observed in:

“/var/netscaler/logon/LogonPoint/custom/.ctxs.receiver”

Weblogs containing base64 encoded commands to the following files are also likely indicators:

“/vpn/scripts/linux/nsgclient18.deb” and “/vpn/scripts/linux/nsgclient18_32.deb”

Additionally look for web requests containing the string:

“login=pitboss%20PPE%20unexpectedly%20died%20NSPPE%3Bfetch%24%7BIFS%7D-q%24%7BIFS%7D-T0%24%7BIFS%7D20%24%7BIFS%7D–no-verify-peer:24%7BIFS:7D–no-ver”

(decoded: “login=pitboss PPE unexpectedly died NSPPE;fetch${IFS}-q${IFS}-T0${IFS}20${IFS}–no-verify-peer:24{IFS:7D–no-ver”)

Suggested Action

CyberMaxx strongly urges applying patches immediately. Please reference the Citrix disclosure: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096

Also see the accompanying blog (https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/#Indicators_of_Compromise__cabcb4) for additional details.

Affected Versions and Fixed Builds

Product Vulnerable Fixed Notes
NetScaler ADC and Gateway 14.1 before 14.1-73.37 14.1-73.37 —
NetScaler ADC and Gateway 13.1 before 13.1-64.23 13.1-64.23 or 13.1-64.24 Use 13.1-64.24 if show ns variable returns results
NetScaler ADC 14.1-FIPS before 14.1-73.37 FIPS 14.1-73.37 FIPS —
NetScaler ADC 13.1-FIPS / NDcPP before 13.1-37.279 13.1-37.279 —