Two Citrix NetScaler Zero-Days Under Mass Exploitation: CISA Set September 30 as the Deadline
Two critical Citrix NetScaler flaws are being exploited without authentication to take full control of the appliance in minutes, and CISA set September 30 as the deadline to patch. Updating closes the door; it does not remove whoever is already inside.
What Happened and in What Order
The September 27 CTX697096 Bulletin: Eight Flaws, Two Zero-Days
On Sunday, September 27, 2026, Citrix and Cloud Software Group published security bulletin CTX697096, an emergency update fixing eight vulnerabilities in customer-managed NetScaler ADC and NetScaler Gateway. Two of them are critical zero-days that were already being exploited in the wild before a patch existed. The company acknowledges having observed exploitation against unmitigated deployments and urges customers to install the updated versions as soon as possible.
Exploited Before the Patch and at Scale After the Proof of Concept
The pattern is the familiar one: first a few attackers with prior knowledge, then the stampede. As soon as a proof of concept went public, exploitation spread across the internet within minutes, with specialist outlets reporting more than a hundred organisations affected and analysts describing web shells, tunnelling malware and escalation to root privileges. The KEV entry and several analyses place the planting of those backdoors throughout September, that is, before the patches existed.
CISA, the KEV Catalog and the September 30 Deadline
The US cybersecurity agency added both vulnerabilities to its Known Exploited Vulnerabilities catalog on September 27, with a remediation deadline for federal agencies of September 30, 2026. Being in the KEV is not a recommendation: it is an obligation with a clock. For any organisation outside the public sector, it is the most reliable signal that the flaw is genuinely being used.
Read also
The Two Flaws, Explained Plainly
CVE-2026-88771: Improper Input Validation and Unauthenticated RCE
The first vulnerability is an improper input validation flaw, classified as CWE-20, that lets an unauthenticated attacker execute arbitrary commands on the appliance. Severity score: 9.5 out of 10 on the CVSS 4.0 scale. In plain terms, you need no user account, no password and no session to tell the box to run whatever you send it.
Why Default Configuration Is Enough to Be Vulnerable
The most uncomfortable detail is the reach: according to Citrix and incident response analyses, the flaw affects all NetScaler ADC and Gateway deployments, including the default configuration, with no optional feature required. There is no checkbox you ticked wrongly. If the appliance is exposed with factory settings, it was already reachable.
CVE-2026-88772: a Memory Overflow in the Packet Engine and the Role of DTLS
The second is a memory overflow in the product's packet processing engine that can lead to remote code execution or denial of service. Also rated 9.5, but with different conditions: it requires DTLS to be enabled and is triggered by malformed or fragmented DTLS record headers. Several analyses describe the exploitation as bypassing authentication and crashing the engine in an uncontrolled way to obtain initial root-level access.
Fixed Versions and What to Do if Your Appliance Is Out of Support
The bulletin identifies the fixed branches as 14.1-73.37 and later, and 13.1-64.23 and later. If you run a release that no longer receives maintenance, there is no patch to install: the decision is no longer about updating, it is about planning to take the appliance off public exposure while you replace it.
Why an Edge Appliance Is the Favourite Target
One Door, Every Key: VPN, Internal Apps and Certificates on the Same Box
An edge appliance is the building's front desk, not just another office: it terminates the VPN, publishes internal applications, validates identities and holds certificates. Compromising it is not winning a room; it is walking away with the keys to all of them.
From RCE to Root, and From Root to the Internal Network
Unauthenticated remote execution means issuing orders before identifying yourself, as if the doorman took instructions from anyone shouting from the street. Root is, afterwards, sitting at the concierge's desk: from there analysts document credential theft and lateral movement into the internal networks the appliance was protecting.
NetScaler's Track Record: Not the First Time, Not the Last
The product has a string of exploitation episodes over recent years, and in August 2026 another NetScaler vulnerability also entered the KEV catalog with its own deadline. This is not bad luck: it is the classic attack surface of edge appliances, exposed software that is widely deployed and hard to update without a maintenance window.
Patching Is Not Cleaning: the Step Almost Everyone Skips
Web Shells, Tunnels, Stolen Credentials and Deleted Logs
A patch changes the lock. If someone already copied the key, the new lock does not evict them. That is why forensic analyses insist that updating does not clean a suspect appliance: web shells, the tunnel and stolen credentials keep working after the update, and there are signs that part of the logs was deleted to hinder the investigation.
Preserving Evidence Before Touching Anything: What Forensics Guides Require
The recommendations are concrete and cheap to follow: keep local logs and, above all, remote ones through external syslog and the management console, and document the time, time zone and time-sync configuration before isolating the appliance. Without that data there is no incident scope, no third-party notification and no way to know which credentials were taken. Rebuilding from scratch without copying the logs first destroys the evidence permanently.
Rotate and Revoke: Users, Sessions, Tokens, Certificates and API Keys
Changing one user's password is not enough. You have to revoke active sessions, invalidate tokens and certificates the appliance issued or stored, and rotate the API keys and secrets held on it. Until that happens, the attacker keeps a way back that does not depend on the original flaw.
What to Do If You Run a NetScaler
The Sequence: Update, Isolate, Hunt, Rotate, Review
- Update to the fixed versions in the bulletin, starting with appliances facing the internet.
- Isolate the appliance if compromise is suspected, after copying the logs and noting the time and time zone.
- Hunt for signs of intrusion: unrecognised files and processes, new scheduled tasks, odd outbound connections, accounts that appeared from nowhere.
- Rotate credentials, sessions, tokens, certificates and API keys.
- Review how they got in, what they touched and which control was missing so it does not happen again.
What to Look For: Signs of Compromise at the Edge and in the Logs
Detection signatures published by security vendors point to web shells planted in appliance paths, processes with names resembling legitimate ones and outbound traffic to destinations absent from your inventory. These are third-party tools, not official validation: treat them as leads, not as a clean bill of health. If the appliance is critical and compromise is confirmed, rebuilding from scratch with the new patch applied before reconnecting is the honest option.
What Not to Do: Rebuild Without Copying Logs and Close the Incident the Same Day
The two classic mistakes are symmetrical: wiping before copying the evidence, and declaring the incident resolved the same day the patch went in. The first erases the answer to what happened; the second leaves the attacker inside with a brand-new lock on the door.
What to Do If You Don't Run NetScaler but Expose Something to the Internet
Exposure Inventory: What Answers From Outside and Who Knows About It
The first question is not "do I run NetScaler?" but "what in my organisation answers from the internet, and who on my team knows about it?". An appliance nobody had inventoried is the usual finding in this kind of incident; that list should exist before an alert arrives.
The Five Controls That Shrink the Impact of Any Zero-Day
- Keep logs off the appliance that generates them.
- Give every service and account the least privilege it needs.
- Rotate credentials and certificates on a schedule, not only after a scare.
- Cut public exposure down to what is strictly necessary.
- Have a written response plan, with roles and step order, before the incident.
What Is Still Unknown
There is no confirmed public attribution of the attacks, no definitive scope for the number of compromised organisations and no reliable count of exposed devices. It is also unclear how long the backdoors had been planted before September 27. Every figure in circulation comes with its outlet and its date, not as a settled fact.
Conclusion
The NetScaler emergency leaves three lessons that apply to any exposed server: edge appliances concentrate too much power, patching is not cleaning, and evidence has to be copied before you touch the box. If you run NetScaler, the sequence is update, isolate, hunt, rotate, review; if you don't, review your exposure inventory and keep your logs off the appliance. Earlier episodes such as GitLab and plugin4shell follow the same logic.


