Two NetScaler Zero-Days Are Exploited—Every Default Deployment Needs a Check

|Author: QUASA Editorial Team|5 min read| 13
Two NetScaler Zero-Days Are Exploited—Every Default Deployment Needs a Check

On September 27, 2026, Citrix’s NetScaler security bulletin disclosed eight vulnerabilities in customer-managed NetScaler ADC and NetScaler Gateway, including the actively exploited CVE-2026-88771 and CVE-2026-88772; it states, “Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed.” The first flaw affects every deployment running an affected build, including a default configuration. The second requires DTLS, which is enabled by default on VPN virtual servers.

Administrators therefore need to check the installed build on every customer-managed instance before using configuration to narrow exposure to the DTLS flaw. The CERT-EU advisory recommends updating affected software and assessing possible compromise on internet-facing appliances that ran affected builds. An update addresses the software flaws; the assessment asks whether someone gained access before it was installed.

Inventory every customer-managed instance first

CVE-2026-88771 is the first triage test because it needs no additional feature or setting. Improper input validation can allow an unauthenticated attacker to execute commands on an affected appliance. Disabling DTLS, removing a VPN virtual server or finding no HTTP policy does not change this flaw’s default-configuration exposure.

Identify each customer-managed NetScaler ADC and NetScaler Gateway instance, its product branch and its installed build. Include NetScaler instances used in Secure Private Access Hybrid deployments. Citrix-managed cloud services and Citrix-managed Adaptive Authentication are updated by Cloud Software Group, so the bulletin’s customer-managed upgrade instruction has a different owner for those services.

Mark which affected appliances were reachable from the internet while vulnerable. Build and configuration determine which fixes apply; internet exposure determines where the recommended compromise assessment is especially urgent. Keeping those observations separate prevents a protected management interface from being mistaken for proof that the appliance itself was unreachable.

Test the DTLS condition separately

CVE-2026-88772 is a memory overflow that can lead to remote code execution or denial of service when DTLS is enabled. On a NetScaler Gateway VPN virtual server, DTLS remains enabled by default unless the configuration explicitly sets -dtls OFF. A virtual server configured with type DTLS also meets the condition.

Inspect the active configuration rather than relying on how the service was originally deployed. An explicit -dtls OFF rules out this flaw’s DTLS prerequisite for that VPN virtual server, but an affected build still needs the CVE-2026-88771 update. Record both the DTLS state and the build: they answer different questions about the same appliance.

Use the fixed build for the correct branch

The fixed release depends on whether the instance uses a standard, FIPS or NDcPP branch. The bulletin identifies these branch-specific thresholds:

  • NetScaler ADC and NetScaler Gateway 14.1: 14.1-73.37 or a later 14.1 release.
  • NetScaler ADC and NetScaler Gateway 13.1: 13.1-64.23 or a later 13.1 release.
  • NetScaler ADC 14.1-FIPS: 14.1-73.37 FIPS or a later 14.1-FIPS release.
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP: 13.1-37.279 or a later release in the respective branch.

Check the installed build after updating, not just the downloaded package or the planned change. A standard build threshold does not establish that a FIPS or NDcPP instance has received its branch-specific fix. For a branch absent from the bulletin’s fixed-release list, obtain a supported upgrade path rather than applying a threshold from another branch.

Use configuration to sort the remaining flaws

The other vulnerabilities in the bulletin have narrower conditions, making them a second pass through the same inventory. CVE-2026-88773 concerns HTTP request smuggling when HTTP configuration is enabled. CVE-2026-88774 concerns a feature-policy bypass involving an HTTP URL-based policy expression. Load-balancing, content-switching, VPN and authentication virtual servers of type HTTP or SSL are relevant to that inspection.

CVE-2026-88775 applies to Gateway or AAA virtual-server configurations. CVE-2026-88776 requires a load-balancing virtual server of type Oracle. CVE-2026-88777 concerns specified non-HTTP application-layer protocol configurations on load-balancing, content-switching, CGNAT-LSN or NAT64 deployments. These checks establish which conditions existed before the update; they do not reduce the need to fix a build exposed to CVE-2026-88771.

CVE-2026-88778 concerns TCP initial sequence-number prediction. Its configuration test combines a qualifying TCP-related virtual-server type with Enhanced ISN Generation being disabled; the bulletin calls for the TCP configuration change on impacted deployments. Recording the setting alongside the installed build gives administrators a way to verify both the software update and that separate configuration action.

Assess access that predates the update

Unit 42’s threat brief describes web-shell activity associated with both exploited paths: malicious files appeared in a Gateway client-package directory, while a command-injection chain placed a PHP web shell behind changes to the web-server configuration. That evidence makes a build check alone insufficient for an internet-facing appliance that was vulnerable before patching.

Preserve available remote syslog and NetScaler Console logs, a technical support bundle and, where applicable, a VPX snapshot before cleaning a suspected compromise. Review the Gateway client-package directory and web-server configuration for unauthorized changes, then correlate appliance and access logs with suspicious administrative sessions, unexpected outbound connections and gaps in logging. Those broader hunting signs are investigative leads, not proof by themselves that either vulnerability was successfully exploited.

If the assessment finds an intrusion, investigate what access remains beyond the appliance through the organization’s incident-response process. A fixed build establishes the appliance’s current software state; retained logs and host evidence determine what may have happened while the vulnerable build was exposed.

Also read:

Share:

Subscribe to our newsletter

Get the latest Web3, AI, and crypto news delivered straight to your inbox.

0