Citrix NetScaler ADC and NetScaler Gateway Remote Code Execution Zero-Days
Citrix NetScaler ADC and NetScaler Gateway Remote Code Execution Zero-Days
Summary
Citrix disclosed two critical, unauthenticated remote code execution (RCE) vulnerabilities in NetScaler ADC and NetScaler Gateway (CVE-2026-88771 and CVE-2026-88772) alongside six lower-severity flaws (CVE-2026-88773 through CVE-2026-88778) in security bulletin CTX697096. Citrix confirmed that exploits of CVE-2026-88771 and CVE-2026-88772 have been observed on unmitigated deployments, and CISA confirmed active global exploitation corroborated by partner threat intelligence and victim reporting.
Independent root-cause research by watchTowr Labs, corroborated by CERT-EU, identifies CVE-2026-88771 as a pre-authentication command injection in a Perl diagnostic script (ns_monuploadd_err.pl) that unsafely shells out on log content it later parses, and CERT-EU reports this has been exploited in the wild to deploy a persistent PHP web shell.
Affected Systems and/or Applications
- Citrix NetScaler ADC and Citrix NetScaler Gateway, version 14.1 before 14.1-73.37
- Citrix NetScaler ADC and Citrix NetScaler Gateway, version 13.1 before 13.1-64.23
- Citrix NetScaler ADC 14.1-FIPS before 14.1-73.37 FIPS
- Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP before 13.1.37.279
- Secure Private Access Hybrid deployments built on the above versions
- CVE-2026-88771 affects all deployments, including default configurations
- CVE-2026-88772 affects deployments with DTLS enabled, which is on by default for VPN virtual servers
Technical Details
Vulnerability Mechanism
CVE-2026-88771 is a pre-authentication command injection vulnerability. Independent code-level analysis by watchTowr Labs attributes it more specifically to unsafe shell invocation (backticks) inside the Perl diagnostic script ns_monuploadd_err.pl, which periodically parses appliance logs to identify crashed Packet Engine (PPE) processes: the script extracts a filename fragment from log text via a grep | tail | sed | awk pipeline and interpolates that unsanitized value into a second backtick-executed find command, so shell metacharacters (e.g. a semicolon) in attacker-controlled log content break out into arbitrary command execution as root.
CVE-2026-88772 is a memory overflow vulnerability that can result in remote code execution or denial of service; it is reachable when DTLS is enabled, which is the default setting on VPN virtual servers.
Six additional vulnerabilities were disclosed in the same bulletin - CVE-2026-88773 (HTTP request smuggling, CVSS 9.3), CVE-2026-88774 (policy bypass via HTTP URL expressions, CVSS 7.0), CVE-2026-88775 (memory overflow DoS on Gateway/AAA servers, CVSS 8.8), CVE-2026-88776 (memory overflow affecting Oracle load balancers, CVSS 8.8), CVE-2026-88777 (memory overflow with non-HTTP L7 protocols, CVSS 8.8), and CVE-2026-88778 (TCP Initial Sequence Number prediction, CVSS 8.8) - none of which are reported as actively exploited.
Other observed exploitation of CVE-2026-88771/CVE-2026-88772 follows a two-step pattern: the payload is first staged by writing it into an HTTP access log (via the User-Agent header), then triggered/executed through a separate vector.
Exploitation Path
Two ways of the exploitation chain for CVE-2026-88771 exist for now:
- watchTowr Labs' proof-of-concept: a crafted HTTP request places an attacker-controlled string in a login-related parameter (e.g. the
loginfield on/nf/auth/doAuthentication.do) formatted to resemble an internal diagnostic message ("...pitboss PPE unexpectedly died NSPPE;:id>/var/tmp/watchTowr;# X"). When this text is later logged and parsed byns_monuploadd_err.pl— which can run up to 24 hours later, or be triggered on demand — the embedded semicolon breaks out of the intended log-field extraction and into the script's subsequent backtickfindcommand, executing the injected command as root. - CERT-EU's description of in-the-wild activity: attackers deliver a base64-encoded bash command inside the HTTP
User-Agentheader (containing anINDEXmarker), then poison NetScaler authentication logs with an entry resembling"pitboss: PPE NSPPE missed too many heartbeats;". Whenns_monuploadd_errnext executes, it parses the poisoned log entry (using| tail -1, so only the most recent matching line is honored — CERT-EU notes this explains repeated log "hammering" by attackers) and runs the injected command. Observed post-compromise activity includes a dropped PHP web shell that modifies/etc/httpd.confto enable the PHP engine for persistence.
Key Points
- Both zero-days are unauthenticated, network-exploitable, and reachable without special configuration on CVE-2026-88771's part.
- CVE-2026-88771's practical trigger is time-delayed/asynchronous: the injected payload must first be written to a log, then executed only when the vulnerable diagnostic script next runs (reported up to ~24 hours, or forced). It means that exploitation timing can lag initial payload delivery.
- Citrix has issued no workaround; the only remediation is upgrading to a fixed build.
- Citrix explicitly warns that patching closes the vulnerabilities but does not remove any persistence or artifacts an attacker may have already left on a compromised system.
- Compromise/IOC scanning is available through NetScaler Console version 14.1-73.36 and later, though Citrix acknowledges this scanning may not provide complete coverage.
Mitigation
Limit Exposure
No vendor-published workaround exists for either CVE. Until patched, organizations should minimize exposure of management interfaces and internet-facing NetScaler ADC/Gateway virtual servers where feasible. If patches cannot be applied within hours, organizations implement interim compensating controls such as broad geo-IP restrictions on affected virtual servers.
Patch/Upgrade
Upgrade Citrix NetScaler ADC and NetScaler Gateway to 14.1-73.37 or later, or 13.1-64.23 or later (14.1-73.37 FIPS or later; 13.1.37.279 FIPS/NDcPP or later, as applicable). An unverified, community-contributed hardening suggestion (not validated by Citrix) is enabling enhanced TCP Initial Sequence Number generation (set ns tcpParam -enhancedISNgeneration ENABLED) as a general hardening measure relevant to the separate TCP ISN prediction issue tracked as CVE-2026-88778.
What the Cyber Fusion Center is Doing
The CFC is monitoring the situation and analyzing the case to identify potential threat-hunting campaigns. This advisory will be updated if required.
References
- Citrix Security Bulletin CTX697096 - https://support.citrix.com/external/article/CTX697096/citrix-netscaler-adc-and-citrix-netscale.html
- CISA Alert: Critical Zero-Day Vulnerabilities Exploited - Citrix NetScaler ADC/Gateway (2026-09-27) - https://www.cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway
- watchTowr Intelligence - https://watchtowr.com/intelligence/citrix-netscaler-adc-citrix-netscaler-gateway-remote-code-execution-cve-2026-88771/
- OpenCVE - CVE-2026-88771 - https://app.opencve.io/cve/CVE-2026-88771

.avif)





.webp)