Citrix NetScaler Zero-Days: What You Need to Check

Citrix NetScaler Zero-Days: What You Need to Check

Citrix administrators have had an uncomfortable few days. Two critical vulnerabilities in NetScaler ADC and NetScaler Gateway are being actively exploited, with evidence showing that attackers were compromising systems before patches became publicly available. The situation has prompted warnings from security authorities and researchers, including the Dutch NCSC and CERT-EU.

The vulnerabilities, CVE-2026-88771 and CVE-2026-88772, both received a critical CVSS 4.0 score of 9.5. Citrix released fixes on September 27, but by then both vulnerabilities had already been exploited as zero-days. This means organisations should not only ask whether their NetScaler appliances have been updated, but also whether attackers may have reached them before the patches became available.

What Are the Two Vulnerabilities?

CVE-2026-88771 is an improper input validation vulnerability that allows an unauthenticated attacker to execute arbitrary commands. According to the official Citrix security bulletin, all affected NetScaler ADC and NetScaler Gateway deployments are vulnerable, including appliances using the default configuration. No additional feature needs to be enabled.

CVE-2026-88772 is a memory overflow vulnerability that can result in remote code execution or denial of service. Exploitation requires DTLS to be enabled, but this should not provide much reassurance to Gateway administrators because Citrix states that DTLS is enabled by default on VPN virtual servers.

Affected systems should be upgraded to the following versions:

Product branch Fixed version
NetScaler ADC / Gateway 14.1 14.1-73.37
NetScaler ADC / Gateway 13.1 13.1-64.23
NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS
NetScaler ADC 13.1-FIPS / NDcPP 13.1-37.279

Check Your NetScaler

Administrators can check the installed NetScaler version directly from the CLI:

show version

For CVE-2026-88772, the configuration should also be checked for VPN and DTLS virtual servers:

show ns runningConfig | grep -i "vpn vserver"
show ns runningConfig | grep -i "DTLS"

Citrix provides additional instructions for determining whether an appliance meets the vulnerability preconditions in its security bulletin. Remember that CVE-2026-88771 requires no special configuration: if you are running one of the affected versions, the vulnerability applies.

Check for Signs of Compromise

Updating an appliance prevents further exploitation of these vulnerabilities, but it cannot undo a compromise that has already occurred. This is particularly important because CERT-EU's technical investigation found attackers placing Base64-encoded commands into HTTP logs and ultimately deploying PHP webshells on compromised appliances.

CERT-EU recommends searching authentication logs for the message PPE missed too many heartbeats, looking for Base64 content in HTTP User-Agent fields and checking the integrity of httpd.conf. Administrators can begin searching their logs with:

grep -Ri "PPE.*missed too many heartbeats" /var/log/

These checks can identify known signs associated with the attacks, but a clean result should not be regarded as proof that an appliance was never compromised. The Dutch NCSC advisory therefore recommends preserving relevant logs and a memory dump before updating an exposed appliance so that potentially valuable forensic evidence is not lost.

Important: Installing the Citrix update closes these vulnerabilities, but it does not remove an attacker who may already have gained access. For systems that were exposed while vulnerable, patching and investigating for compromise should go hand in hand.

How BaseFortify Can Help

BaseFortify uses Common Platform Enumeration (CPE) information to connect vulnerabilities to the software components organisations have registered. Rather than simply reporting that a new Citrix vulnerability exists, CPE matching helps determine whether a product and version in your environment corresponds to an affected product identified in the CVE data.

For example, the BaseFortify report for CVE-2026-88771 currently includes the following Citrix product:

Vendor:   citrix
Product:  netscaler_gateway
Version:  14.1
Affected: versions before 14.1-73.37

This information originates from the CPE data associated with the vulnerability. If a matching Citrix component is registered in an organisation's inventory, BaseFortify can use the CPE information to associate the vulnerability with that component. The CVE-2026-88771 report currently contains multiple CPE ranges covering both NetScaler Gateway and NetScaler Application Delivery Controller.

Our reports for CVE-2026-88771 and CVE-2026-88772 provide the affected CPEs alongside CVSS information, exploitability data, CISA Known Exploited Vulnerabilities information, mitigation guidance and attack context.

Both reports also include an AI Q&A section with quick answers covering areas such as detection, impact and mitigation. For questions that are not covered by the predefined Q&A, the CVE AI Assistant can be consulted directly from the report and asked questions specifically about that vulnerability.

You can create a BaseFortify account to register and monitor your own components. The Starter plan is free and provides a straightforward way to begin tracking components against newly published vulnerabilities.

For organisations running Citrix NetScaler, the immediate priority is to identify affected appliances, preserve forensic evidence, investigate for signs of compromise and install the appropriate Citrix update as soon as possible. With exploitation beginning before public disclosure, installing the update should be accompanied by checking whether an attacker may already have gained access.

Resources