Back to Intelligence

Citrix NetScaler Zero-Day Under Active Exploitation: Detection and Remediation Guide for the Third 2025/2026 Flaw

SA
Security Arsenal Team
October 7, 2026
12 min read

Citrix has shipped an emergency patch for yet another NetScaler vulnerability that is already being exploited in the wild — the third actively exploited zero-day hitting the NetScaler ADC and NetScaler Gateway product line in a matter of days, according to reporting by The HIPAA Journal. For those of us who have been responding to NetScaler intrusions since the original CitrixBleed campaign, the pattern is painfully familiar: an internet-facing edge device, a pre-authentication vulnerability, exploitation confirmed before many organizations had even patched the previous flaw, and healthcare and enterprise environments squarely in the blast radius.

If you operate NetScaler ADC or NetScaler Gateway — especially as a VPN, ICA proxy, or AAA virtual server front-ending clinical or enterprise applications — treat this as an active incident, not a routine patch cycle. Attackers are not waiting. The compressed timeline between the last two patches and this one tells us exploitation infrastructure is already built, operationalized, and being pointed at anything still listening on the internet.

Why This Demands Immediate Action

  • Edge device, pre-auth exposure. NetScaler appliances sit at the perimeter. A successful exploit typically means code execution or session theft before any authentication occurs.
  • Confirmed in-the-wild exploitation. This is not a theoretical CVSS exercise. Threat actors are using it now, and historically NetScaler zero-days move from targeted exploitation to mass scanning within 72 hours of disclosure.
  • Healthcare is explicitly in scope. This was reported via The HIPAA Journal for a reason — hospitals and covered entities run NetScaler Gateway heavily for remote EHR access, and they are consistently among the last to patch edge infrastructure.
  • Patching is not remediation. If the appliance was internet-facing and unpatched during the exploitation window, you must assume compromise and hunt accordingly. A patched-but-backdoored appliance is still a breached network.

Technical Analysis

Affected Products

Based on Citrix's recent advisory cadence for this wave of actively exploited flaws, the vulnerable code path affects:

  • NetScaler ADC (formerly Citrix ADC) — supported feature release and LTSR branches
  • NetScaler Gateway (formerly Citrix Gateway) — same code base, same exposure
  • Appliances configured as a Gateway / VPN virtual server, AAA virtual server, or load balancer front-ending authentication are the highest-risk configuration, consistent with every recent NetScaler exploitation campaign

End-of-life ADC/Gateway builds (12.1, 13.0, and older LTSRs past their support window) do not receive fixes and must be migrated off immediately. If you are still running an EOL build on the internet in 2026, this is your third warning in as many weeks.

How These Attacks Work (Defender's View)

While Citrix has kept technical details of this third flaw closely held — standard practice during active exploitation — the post-exploitation tradecraft across this wave of NetScaler intrusions has been consistent, and that is what your detection engineering should target:

  1. Initial access via a crafted request to the internet-facing virtual server, exploiting the vulnerable component without authentication.
  2. Web shell deployment. Actors write PHP or shell-based web shells into web-served directories on the appliance — historically paths under /netscaler/portal/, /var/vpn/, /var/ns_gui/, and theme/customization directories that survive reboots and some upgrades.
  3. Persistence. Dropped scripts, rogue cron entries, and modified rc files. We have also seen actors implant binaries masquerading as legitimate NetScaler processes.
  4. Credential and session theft. Memory scraping of the AAA process to harvest valid session tokens and credentials — the CitrixBleed pattern — enabling the actor to return through the front door with legitimate sessions even after patching.
  5. Lateral movement into the internal network using the appliance's trusted position, often via RDP, SMB, or SSO into VDI/Citrix Virtual Apps infrastructure.

The critical defensive insight: the exploit itself is hard to detect in logs; the post-exploitation behavior is not. Web shell file writes, nshttpd spawning shells, anomalous NITRO API configuration calls, and authentication with hijacked tokens are all observable if you're collecting the right telemetry.

Exploitation Status

  • Actively exploited in the wild — confirmed by Citrix's advisory and independent reporting.
  • Given the prior two flaws in this sequence, expect this to be added to the CISA Known Exploited Vulnerabilities (KEV) catalog with a short federal remediation deadline; monitor CISA KEV daily.
  • Mass scanning for vulnerable NetScaler instances historically begins within days of patch release as actors reverse the fix. The window between "patch available" and "commodity exploitation" for this product line is now measured in hours.

Detection & Response

Sigma Rules

The following rules target the observable post-exploitation tradecraft documented across active NetScaler intrusions: web shell writes into web-served directories, the NetScaler HTTP daemon spawning shell interpreters, and probing of known web shell paths from the internet. Ship your NetScaler syslog (via nslog/syslog action) and any reverse-proxy/WAF telemetry into your SIEM before expecting these to fire — most organizations we assess have zero file-integrity or process telemetry from their appliances, and that gap is exactly what these actors exploit.

YAML
---
title: NetScaler Web Shell File Creation in Web-Served Directories
id: 9c1e4a27-3b8d-4f52-a6e1-7d2c8b4f9012
status: experimental
description: Detects creation of PHP or shell script files in NetScaler web-served directories, a hallmark of post-exploitation web shell deployment following ADC/Gateway compromise.
references:
  - https://www.cisa.gov/news-events/cybersecurity-advisories
  - https://attack.mitre.org/techniques/T1505/003/
author: Security Arsenal
date: 2026/01/15
tags:
  - attack.persistence
  - attack.t1505.003
logsource:
  category: file_event
  product: linux
detection:
  selection_paths:
    TargetFilename|contains:
      - '/netscaler/portal/'
      - '/var/vpn/'
      - '/var/ns_gui/'
      - '/ns_gui/'
  selection_ext:
    TargetFilename|endswith:
      - '.php'
      - '.sh'
      - '.pl'
      - '.py'
  condition: selection_paths and selection_ext
falsepositives:
  - Legitimate NetScaler customization or portal theme deployments by administrators
level: high
---
title: NetScaler HTTP Daemon Spawning Shell Interpreter
id: 2f7b9c14-8a3e-4d61-bf52-6e1a9c3d8274
status: experimental
description: Detects the NetScaler nshttpd web server process spawning shell interpreters or command execution utilities, indicating command execution via a web shell or exploited vulnerability.
references:
  - https://attack.mitre.org/techniques/T1059/004/
  - https://attack.mitre.org/techniques/T1505/003/
author: Security Arsenal
date: 2026/01/15
tags:
  - attack.execution
  - attack.t1059.004
  - attack.t1505.003
logsource:
  category: process_creation
  product: linux
detection:
  selection_parent:
    ParentImage|contains:
      - 'nshttpd'
      - 'httpd'
      - 'nginx'
  selection_child:
    Image|endswith:
      - '/sh'
      - '/bash'
      - '/csh'
      - '/tcsh'
      - '/perl'
      - '/python'
      - '/nc'
      - '/curl'
      - '/wget'
  condition: selection_parent and selection_child
falsepositives:
  - Rare administrative scripts invoked through custom NetScaler portal integrations
level: critical
---
title: Inbound Requests to Suspicious Scripts on NetScaler Gateway Paths
id: 4d8e2f61-7c9b-4a35-9e12-8b6d3f5a2071
status: experimental
description: Detects HTTP requests to newly dropped script files or known web shell locations on NetScaler Gateway/AAA virtual server paths from external sources, indicating web shell access or exploitation probing.
references:
  - https://attack.mitre.org/techniques/T1190/
  - https://attack.mitre.org/techniques/T1505/003/
author: Security Arsenal
date: 2026/01/15
tags:
  - attack.initial_access
  - attack.t1190
  - attack.t1505.003
logsource:
  category: webserver
detection:
  selection:
    cs-uri|contains:
      - '/vpn/'
      - '/logon/'
      - '/netscaler/'
      - '/menu/'
  selection_script:
    cs-uri|endswith:
      - '.php'
      - '.jsp'
      - '.sh'
  filter_known:
    cs-uri|contains:
      - 'logonpoint'
      - 'LogonPoint'
      - 'tmindex'
      - 'gateway_api'
  condition: selection and selection_script and not filter_known
falsepositives:
  - Legitimate custom portal pages; baseline your environment's known script paths and tune the filter
level: high

KQL (Microsoft Sentinel / Defender)

This query hunts NetScaler syslog and CEF-ingested traffic (most Sentinel customers receive NetScaler logs via the Citrix ADC / CEF connector or generic Syslog) for requests to script files under gateway paths, configuration changes via the NITRO API from unusual sources, and authentication anomalies consistent with hijacked sessions. Run it over the full window the appliance was unpatched, not just the last 24 hours.

KQL — Microsoft Sentinel / Defender
let NetScalerPaths = dynamic(["/vpn/", "/logon/", "/netscaler/", "/menu/", "/nitro/"]);
let ScriptExts = dynamic([".php", ".jsp", ".sh", ".pl", ".py"]);
let KnownGood = dynamic(["logonpoint", "LogonPoint", "tmindex", "gateway_api", "/vpn/js/", "/vpn/images/", "/vpn/css/", "/logon/themes/"]);
union isfuzzy=true
    (CommonSecurityLog
    | where TimeGenerated > ago(30d)
    | where DeviceVendor =~ "Citrix" or DeviceProduct has_any ("NetScaler", "ADC")
    | where RequestURL has_any (NetScalerPaths)
    | where RequestURL has_any (ScriptExts)
    | where not(RequestURL has_any (KnownGood))
    | project TimeGenerated, SourceIP, RequestURL, RequestMethod, DeviceAction, DestinationHostName
    ),
    (Syslog
    | where TimeGenerated > ago(30d)
    | where HostIP has_any ("netscaler") or Computer has_any ("netscaler", "ns", "adc")
    | where SyslogMessage has_any (NetScalerPaths)
    | where SyslogMessage has_any (ScriptExts)
    | where not(SyslogMessage has_any (KnownGood))
    | project TimeGenerated, Computer, HostIP, ProcessName, SyslogMessage
    )
| summarize FirstSeen=min(TimeGenerated), LastSeen=max(TimeGenerated), Hits=count() by SourceIP, RequestURL, DestinationHostName
| order by LastSeen desc;
// Secondary hunt: NITRO API configuration calls from non-management sources
CommonSecurityLog
| where TimeGenerated > ago(30d)
| where RequestURL startswith "/nitro/v1/config/"
| summarize ConfigCalls=count(), DistinctSources=dcount(SourceIP), Sources=make_set(SourceIP) by RequestURL
| order by ConfigCalls desc;

Validate the Sources in the NITRO query against your known management jump hosts and automation (Ansible, Terraform, ADM). Any NITRO config call from a source outside your management plane during the exposure window is an incident until proven otherwise.

Velociraptor VQL

Velociraptor cannot run on the NetScaler appliance itself (it's a hardened FreeBSD-based platform), but it is invaluable for hunting the internal side of a NetScaler compromise: which internal hosts were touched from the appliance's IP, and whether attacker tooling landed on your Windows estate after initial access. This artifact identifies processes on endpoints holding network connections to or from your NetScaler appliance IPs — any inbound connection from the NSIP to a workstation or server that isn't documented management traffic is a lateral movement lead.

VQL — Velociraptor
-- Hunt for endpoint network connections involving NetScaler appliance IPs
-- Parameterize with your appliance NSIP/SNIP ranges before deployment
LET NetScalerIPs = ('10.10.20.5', '10.10.20.6', '203.0.113.15')

SELECT Pid,
       Name,
       Exe,
       CommandLine,
       Username,
       netstat().LocalAddr.IP AS LocalIP,
       netstat().LocalAddr.Port AS LocalPort,
       netstat().RemoteAddr.IP AS RemoteIP,
       netstat().RemoteAddr.Port AS RemotePort,
       netstat().Status AS ConnStatus
FROM pslist()
WHERE (netstat().RemoteAddr.IP in NetScalerIPs
       OR netstat().LocalAddr.IP in NetScalerIPs)
  AND NOT (netstat().RemoteAddr.Port in (80, 443) AND ConnStatus =~ 'TIME_WAIT')

Follow-up: for any host identified above, run a glob() hunt for recently created executables and scripts in user-writable directories (C:\Users\*\AppData\**\*.exe, C:\ProgramData\**\*.ps1 with recent timestamps) and pull triage collections before anything is reimaged.

Remediation & Verification Script

Run this from a management host with SSH access to the appliance. It verifies build/patch state, hunts for web shells and rogue persistence, and flags anomalous processes. Run it before and after patching — artifacts found pre-patch are your incident scope.

Bash / Shell
#!/bin/bash
# NetScaler Compromise Assessment & Patch Verification - Security Arsenal
# Usage: ./netscaler_triage.sh <nsip> <admin_user>

NSIP="$1"
NSUSER="${2:-nsroot}"
SSH="ssh -o StrictHostKeyChecking=accept-new ${NSUSER}@${NSIP}"

echo "=== [1] Build and patch level ==="
$SSH "shell grep -i version /flash/nsconfig/.build; show ns version" 2>/dev/null

echo "=== [2] Web shell hunt: scripts in web-served dirs modified in last 60 days ==="
$SSH "shell find /netscaler/portal /var/vpn /var/ns_gui /ns_gui \
  -type f \( -name '*.php' -o -name '*.sh' -o -name '*.pl' -o -name '*.py' \) \
  -mtime -60 -exec ls -la {} \;" 2>/dev/null

echo "=== [3] Unexpected files in portal root (compare against known-good) ==="
$SSH "shell ls -latr /netscaler/portal/ | head -30" 2>/dev/null

echo "=== [4] Rogue persistence: crontab and rc entries ==="
$SSH "shell cat /etc/crontab; ls -la /var/cron/tabs/ 2>/dev/null; \
  grep -r 'curl\|wget\|nc \|base64' /nsconfig/rc.netscaler 2>/dev/null" 2>/dev/null

echo "=== [5] Anomalous processes (non-Citrix binaries) ==="
$SSH "shell ps aux | grep -v -E 'nshttpd|nsconfigd|nsaggregat|nsproflog|nsppe|nstrace|sshd|ntpd|snmpd|kthread|kernel|init|syslogd|cron' | head -40" 2>/dev/null

echo "=== [6] Recent config changes via NITRO/shell (audit trail) ==="
$SSH "shell ls -latr /var/nstmp/ /tmp/ 2>/dev/null | head -30; \
  zcat /var/log/ns.log* 2>/dev/null | grep -i 'nitro\|add system user\|set system user' | tail -40" 2>/dev/null

echo "=== [7] Outbound connections from appliance (C2 check) ==="
$SSH "shell netstat -an | grep ESTABLISHED | grep -v -E ':80 |:443 |:22 |:3010 |:3008 |:3009 '" 2>/dev/null

echo "=== [8] AAA session table anomaly check ==="
$SSH "show aaa session | wc -l" 2>/dev/null

echo "Done. Any unexpected .php/.sh in [2], cron entries in [4], or outbound sessions in [7] = escalate to IR immediately."

Remediation

  1. Patch now — do not wait for a maintenance window. Apply the fixed NetScaler ADC/Gateway builds listed in the current Citrix security bulletin (Citrix Security Bulletins, also mirrored at support.citrix.com). This is the third actively exploited flaw in this product line in days; the previous two patches are prerequisites, not alternatives. Verify you are on a supported branch — if your build is EOL, no fix exists and the appliance must be upgraded or taken offline.

  2. Kill all sessions after patching. Run kill icaconnection -all and kill aaa session -all on the appliance. Every recent NetScaler campaign has involved session-token theft; a patched appliance with live stolen sessions is still an open door. This was the single most-skipped step in our CitrixBleed IR engagements.

  3. Hunt before you trust. Execute the triage script above and review at minimum 30 days of telemetry covering the window the appliance was unpatched. Any web shell artifact, rogue cron entry, or unexplained NITRO config call converts this from a patch event into a full incident response — preserve the appliance's filesystem and memory before rebooting or reimaging.

  4. Rotate everything the appliance touched. All credentials that authenticated through the Gateway, all service accounts used by the appliance for LDAP/StoreFront/VDI, and any certificates whose private keys live on the device. Assume memory was scraped.

  5. Reduce the attack surface permanently. Restrict management interface (NSIP) and NITRO API access to a dedicated management VLAN reachable only from hardened jump hosts. Confirm the management GUI is not — and has never been — internet-exposed. We still find this in roughly one in three assessments.

  6. Monitor CISA KEV for the formal listing and deadline (cisa.gov/known-exploited-vulnerabilities-catalog). Prior NetScaler KEV entries carried 3-7 day federal remediation windows; treat that deadline as your internal SLA regardless of sector.

  7. For healthcare organizations specifically: document your exposure window and triage results now. If PHI-adjacent systems (EHR access portals, clinical VDI) sit behind this Gateway, your HIPAA incident-determination clock may already be running, and your OCR-facing documentation starts with the evidence you collect today.

Related Resources

Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.