On September 27, 2026, CISA added two Citrix NetScaler vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation in the wild:
- CVE-2026-88771 — Citrix NetScaler Improper Input Validation Vulnerability (CWE-20)
- CVE-2026-88772 — Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CWE-119, a classic buffer boundary/memory corruption class)
If you run NetScaler ADC or NetScaler Gateway — on-prem, virtual (VPX), or as a customer-managed instance — treat this as an incident-grade event, not a routine patching ticket. Every time a NetScaler flaw lands in the KEV, exploitation follows the same playbook we have seen for years: initial access via the edge appliance, webshell or payload staging on the device, session/credential theft, and then pivoting into the internal network. The input-validation and memory-buffer weakness classes here are exactly the categories that historically enable unauthenticated remote code execution or pre-auth access on these appliances.
Why This Matters Right Now
NetScaler appliances sit at the perimeter terminating TLS, brokering authentication, and front-ending internal applications. A compromise here gives an adversary:
- A pre-authentication foothold on a device that sees every remote user session
- Access to cached credentials, session tokens, and MFA cookies — the exact material harvested in past NetScaler campaigns (the session-hijack pattern from the 2023-era NetScaler flaws remains the dominant post-exploitation behavior in this product family)
- A stealthy persistence point — NetScaler boxes are notoriously under-monitored, rarely have EDR coverage, and survive reboot cycles via dropped scripts and cron persistence
CISA's inclusion in the KEV means exploitation is confirmed, not theoretical. Under Binding Operational Directive (BOD) 26-04, Federal Civilian Executive Branch (FCEB) agencies are required to prioritize rapid remediation of KEV-listed vulnerabilities — and while BOD 26-04 is binding on the federal enterprise, private-sector organizations should treat the KEV due date as their own internal SLA. Ransomware crews and initial access brokers routinely weaponize KEV additions within days of publication.
Technical Analysis
Affected Products
- Citrix NetScaler ADC (formerly Citrix ADC)
- Citrix NetScaler Gateway (formerly Citrix Gateway)
These flaws affect the NetScaler packet processing and HTTP handling stack — the components exposed when an appliance is configured as a Gateway (VPN, ICA Proxy, CVPN, RDP Proxy) or as an AAA virtual server. Consult the official Citrix security bulletin for the precise affected builds and fixed versions for your release train (13.1, 14.1, and any applicable FIPS/NDcPP builds). Note that end-of-life trains (e.g., 12.1, 13.0) will not receive fixes — if you are on an EOL build, migration is your only durable remediation.
Vulnerability Classes and Likely Exploitation Mechanics
- CVE-2026-88771 (CWE-20, Improper Input Validation): The appliance fails to properly validate attacker-supplied input to a reachable service. On NetScaler, this class has historically enabled path traversal, request smuggling, or injection into internal handler logic — frequently exploitable without authentication when the affected virtual server is internet-facing.
- CVE-2026-88772 (CWE-119, Improper Restriction of Operations within the Bounds of a Memory Buffer): A memory boundary violation in a packet-pipeline or protocol-handling component. This is the class that enables memory corruption leading to code execution or disclosure of memory contents (the mechanism behind session-token theft in past NetScaler exploitation).
From a defender's perspective, the attack chain to hunt for is consistent with prior NetScaler campaigns:
- Unauthenticated probe/exploit against the Gateway or AAA vServer endpoints (
/vpn/,/logon/LogonPoint/, CGI paths under/cgi/) - Webshell or payload drop — historically under
/netscaler/portal/scripts/,/netscaler/portal/templates/, or/var/tmp/on the appliance - Execution of system commands from the web server process context (
httpdspawning shells or utilities it never legitimately runs) - Credential/session harvesting — dumping memory or configuration, harvesting
ns.confsecrets, stealing session cookies for MFA bypass - Persistence — cron entries, modified rc scripts, dropped binaries, or rogue SSH keys in
/root/.ssh/or/nsconfig/
Exploitation Status
| Indicator | Status |
|---|---|
| CISA KEV inclusion | ✅ Confirmed (September 27, 2026) |
| Active in-the-wild exploitation | ✅ Confirmed per CISA |
| Public PoC | Assume imminent; weaponization follows KEV listings rapidly |
| BOD 26-04 federal remediation mandate | ✅ Applies to FCEB agencies — verify your agency's due date in the KEV entry |
Detection & Response
Because NetScaler appliances typically lack EDR, your detection strategy must layer appliance-level log review, network telemetry, and downstream endpoint hunting (for evidence of pivoting from the device).
First Actions (Do These Before You Hunt)
- Inventory every internet-facing NetScaler ADC/Gateway instance, including dev/test and DR appliances — these are routinely forgotten and routinely exploited.
- Capture volatile evidence before patching: appliance logs (
/var/log/ns.log,/var/log/httpaccess.log,/var/log/httperror.log,/var/log/bash.log,/var/log/sh.log), running process list, crontabs, and/tmp//var/tmpcontents. - Check Citrix's bulletin for IoCs and, if exploitation is confirmed on a device, treat all secrets that ever transited it as compromised.
Sigma Rules
The following rules target downstream indicators: anomalous requests hitting NetScaler-served paths (ingested via reverse proxy/WAF/load balancer logs), and the classic post-exploitation pattern of the NetScaler web stack spawning command shells (if you forward appliance shell logs via syslog). The Windows process-creation rule covers the post-compromise pivot, where attackers landing through NetScaler dump credentials or execute reconnaissance from newly interactive sessions.
---
title: Suspicious Process Spawning From Web Server Parent - Potential NetScaler Webshell Pattern
id: 3f7c1a92-8d4e-4b61-a2c9-5e6f7a8b9c0d
status: experimental
description: Detects command shells, scripting engines, or system utilities spawned by a web server process (httpd/nginx/apache), consistent with webshell execution following exploitation of an edge appliance such as Citrix NetScaler (CVE-2026-88771, CVE-2026-88772). Apply to Linux syslog process audit data forwarded from NetScaler appliances and adjacent web infrastructure.
references:
- https://www.cisa.gov/news-events/alerts/2026/09/27/cisa-adds-two-known-exploited-vulnerabilities-catalog
- https://attack.mitre.org/techniques/T1505/003/
- https://attack.mitre.org/techniques/T1190/
author: Security Arsenal
date: 2026/09/27
tags:
- attack.initial_access
- attack.persistence
- attack.t1190
- attack.t1505.003
logsource:
product: linux
service: auditd
detection:
selection_parent:
ParentImage|endswith:
- '/httpd'
- '/nginx'
- '/apache2'
selection_child:
Image|endswith:
- '/sh'
- '/bash'
- '/dash'
- '/curl'
- '/wget'
- '/perl'
- '/python'
- '/python3'
- '/nc'
- '/ncat'
- '/netstat'
- '/whoami'
- '/id'
condition: selection_parent and selection_child
falsepositives:
- Rare; legitimate web server plugins invoking system utilities during maintenance windows
level: high
---
title: Webshell File Creation in NetScaler Portal and CGI Directories
id: 8b2e5d14-6f3a-4c97-b1d8-2a4c6e8f0a1b
status: experimental
description: Detects creation of script files in NetScaler portal, template, and CGI directories — the canonical webshell staging locations observed in NetScaler exploitation campaigns, including activity associated with CVE-2026-88771 and CVE-2026-88772. Apply to file integrity monitoring or forwarded syslog from NetScaler appliances.
references:
- https://www.cisa.gov/news-events/alerts/2026/09/27/cisa-adds-two-known-exploited-vulnerabilities-catalog
- https://attack.mitre.org/techniques/T1505/003/
author: Security Arsenal
date: 2026/09/27
tags:
- attack.persistence
- attack.t1505.003
logsource:
product: linux
category: file_event
detection:
selection_path:
TargetFilename|contains:
- '/netscaler/portal/scripts/'
- '/netscaler/portal/templates/'
- '/netscaler/ns_gui/'
- '/var/vpn/'
- '/var/netscaler/gui/'
- '/var/tmp/'
- '/tmp/'
selection_ext:
TargetFilename|endswith:
- '.php'
- '.pl'
- '.py'
- '.sh'
- '.cgi'
- '.jsp'
filter_known:
TargetFilename|contains:
- '/netscaler/portal/scripts/common/'
condition: selection_path and selection_ext and not filter_known
falsepositives:
- Legitimate NetScaler GUI customization or theme deployments (change-control these events)
level: high
---
title: Credential Dumping or Reconnaissance Following Interactive Session on Internal Host
id: 1c9a4f77-2e5b-4d38-a6c1-9f0b3d5e7a2c
status: experimental
description: Detects credential access and reconnaissance tooling executed on internal Windows systems shortly after perimeter exploitation, a common post-NetScaler-compromise pivot pattern observed with CVE-2026-88771 and CVE-2026-88772. Tune the host list to jump boxes and servers reachable from your NetScaler DMZ segment.
references:
- https://www.cisa.gov/news-events/alerts/2026/09/27/cisa-adds-two-known-exploited-vulnerabilities-catalog
- https://attack.mitre.org/techniques/T1003/
- https://attack.mitre.org/techniques/T1018/
author: Security Arsenal
date: 2026/09/27
tags:
- attack.credential_access
- attack.discovery
- attack.t1003
- attack.t1018
logsource:
category: process_creation
product: windows
detection:
selection:
CommandLine|contains:
- 'sekurlsa::'
- 'lsadump::'
- 'comsvcs.dll'
- 'MiniDump'
- 'procdump'
- 'ntdsutil'
- 'vssadmin create shadow'
- 'nltest /dclist'
- 'net group "Domain Admins"'
filter_service:
User|contains: 'SYSTEM'
Image|endswith: '\\MsMpEng.exe'
condition: selection and not filter_service
falsepositives:
- Authorized penetration testing and red team activity
- Backup and snapshot management tooling invoking vssadmin
level: high
KQL — Microsoft Sentinel (via Syslog/CEF ingestion from NetScaler)
NetScaler forwards logs via syslog (configure an audit server action and policy to send to your syslog collector/Sentinel agent). This query hunts for exploit-probe patterns against Gateway/AAA paths, error-spike anomalies characteristic of memory-corruption attempts, and post-exploitation shell activity on the appliance:
// NetScaler exploitation hunt: CVE-2026-88771 / CVE-2026-88772
// Requires NetScaler syslog/audit log forwarding to Sentinel (Syslog or CommonSecurityLog)
let lookback = 14d;
union (Syslog | where TimeGenerated > ago(lookback)),
(CommonSecurityLog | where TimeGenerated > ago(lookback))
| extend rawmsg = tostring(column_ifexists("SyslogMessage", column_ifexists("Message", "")))
| where rawmsg has_any (
"/vpn/", "/logon/LogonPoint", "/cgi/", "/logon/",
"httpd", "crash", "segmentation", "core dumped", "pid ",
"bash.log", "sh -c", "/var/tmp", "/netscaler/portal/scripts", "cron"
)
| extend Indicator = case(
rawmsg has "core dumped" or rawmsg has "segmentation", "Possible memory corruption crash (CVE-2026-88772)",
rawmsg has "/netscaler/portal/scripts", "Possible webshell staging path",
rawmsg has "/var/tmp", "Possible payload staging in /var/tmp",
rawmsg has "sh -c" or rawmsg has "bash", "Shell execution on appliance",
rawmsg has "/cgi/", "Probe of CGI handler path",
"Gateway/AAA endpoint request")
| summarize EventCount = count(), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated),
SampleMessages = take_any(rawmsg, 3)
by Computer, HostIP, Indicator
| order by EventCount desc
And a downstream pivot hunt in Defender data — interactive logons and process execution on internal hosts sourced from your NetScaler DMZ subnet in the hours after suspicious appliance activity:
// Hunt for post-exploitation pivot from NetScaler DMZ segment
let lookback = 7d;
let dmz_prefixes = dynamic(["10.10.", "172.16.20."]); // <-- replace with your NetScaler SNIP/MIP subnets
DeviceNetworkEvents
| where TimeGenerated > ago(lookback)
| where RemoteIP startswith_any (dmz_prefixes)
| where LocalPort in (445, 3389, 5985, 5986, 22, 135)
| join kind=inner (
DeviceProcessEvents
| where TimeGenerated > ago(lookback)
| where FileName in~ ("cmd.exe", "powershell.exe", "psexec.exe", "wmic.exe", "nltest.exe", "net.exe")
| project DeviceName, ProcTime = TimeGenerated, FileName, ProcessCommandLine, AccountName
) on DeviceName
| where ProcTime between (TimeGenerated .. TimeGenerated + 30m)
| project TimeGenerated, DeviceName, RemoteIP, LocalPort, FileName, ProcessCommandLine, AccountName
| order by TimeGenerated desc
Velociraptor VQL
If you have Velociraptor deployed on jump hosts, management servers, or any Linux systems adjacent to the appliance — or if you acquire the NetScaler shell environment — this artifact hunts for child processes of the web stack, recently modified files in webshell staging paths, and cron-based persistence:
-- NetScaler post-exploitation hunt: webshell children, staging dirs, cron persistence
-- Run against NetScaler-adjacent Linux systems or appliance shell acquisitions
SELECT Pid, Ppid, Name, CommandLine, Exe, Username, CreateTime
FROM pslist()
WHERE (
CommandLine =~ '(?i)(sh -c|bash|curl|wget|perl|python|nc |ncat)'
AND Name =~ '(?i)^(sh|bash|dash|perl|python.*|curl|wget|nc|ncat)$'
)
OR Exe =~ '(?i)/var/tmp/'
OR Exe =~ '(?i)/netscaler/portal/(scripts|templates)/'
-- Persistence and staging artifacts: recent files in high-risk paths + cron tampering
SELECT FullPath, Size, Mtime, Atime
FROM glob(globs=[
'/netscaler/portal/scripts/**',
'/netscaler/portal/templates/**',
'/var/tmp/**',
'/tmp/*.sh',
'/tmp/*.pl',
'/var/cron/tabs/*',
'/etc/crontab',
'/nsconfig/rc.netscaler'
])
WHERE Mtime > (now() - 1209600) -- files modified in last 14 days
ORDER BY Mtime DESC
Remediation & Verification Script
Run the following from a management workstation with SSH access to the appliance (or adapt for the NetScaler shell). It performs a compromise assessment before patching — never patch first and ask questions later on a KEV-listed device.
#!/usr/bin/env bash
# NetScaler pre-patch compromise assessment: CVE-2026-88771 / CVE-2026-88772
# Run on the NetScaler shell (drop from CLI with: shell) or via a jump box.
set -u
OUT="/var/tmp/netscaler_triage_$(date +%Y%m%d_%H%M%S)"
mkdir -p "$OUT" && echo "[+] Evidence output: $OUT"
# 1) Record running build for patch-gap verification
echo "=== BUILD ===" | tee "$OUT/build.txt"
show ns version 2>/dev/null | tee -a "$OUT/build.txt"
# 2) Suspicious processes: shells/utilities parented to httpd or running from tmp
echo "=== SUSPICIOUS PROCESSES ===" | tee "$OUT/processes.txt"
ps aux | grep -Ei '(/var/tmp/|/tmp/[a-z0-9]+|bash|/bin/sh|perl|python|nc |ncat)' \
| grep -Ev 'grep|/usr/sbin/(cron|sshd)' | tee -a "$OUT/processes.txt"
# 3) Webshell sweep in canonical staging directories
echo "=== RECENT FILES IN WEB/PERSISTENCE PATHS ===" | tee "$OUT/files.txt"
for d in /netscaler/portal/scripts /netscaler/portal/templates /var/vpn \
/netscaler/ns_gui /var/tmp /tmp; do
[ -d "$d" ] && find "$d" -type f \( -name '*.php' -o -name '*.pl' \
-o -name '*.py' -o -name '*.sh' -o -name '*.cgi' \) \
-mtime -30 -ls 2>/dev/null | tee -a "$OUT/files.txt"
done
# 4) Cron and startup persistence
echo "=== CRON / RC PERSISTENCE ===" | tee "$OUT/persistence.txt"
cat /etc/crontab 2>/dev/null | tee -a "$OUT/persistence.txt"
ls -la /var/cron/tabs/ 2>/dev/null | tee -a "$OUT/persistence.txt"
for u in /var/cron/tabs/*; do [ -f "$u" ] && { echo "-- $u"; cat "$u"; } ; done >> "$OUT/persistence.txt" 2>&1
grep -Ev '^\s*(#|$)' /nsconfig/rc.netscaler 2>/dev/null | tee -a "$OUT/persistence.txt"
# 5) Rogue SSH authorized keys
echo "=== SSH KEYS ===" | tee "$OUT/ssh_keys.txt"
for k in /root/.ssh/authorized_keys /home/*/.ssh/authorized_keys /nsconfig/ssh/authorized_keys; do
[ -f "$k" ] && { echo "-- $k"; cat "$k"; } | tee -a "$OUT/ssh_keys.txt"
done
# 6) Failed/successful logon anomalies in ns.log
echo "=== AUTH ANOMALIES (last 72h) ===" | tee "$OUT/auth.txt"
grep -Ei 'login|authentication' /var/log/ns.log* 2>/dev/null \
| grep -Ei 'fail|denied|invalid|unknown user' | tail -200 | tee -a "$OUT/auth.txt"
# 7) HTTP access log review for probe/exploit paths
echo "=== SUSPICIOUS HTTP REQUESTS ===" | tee "$OUT/http.txt"
grep -Eih '(/cgi/|\.\./|/logon/LogonPoint|%2e%2e|/vpn/index|portal/scripts)' \
/var/log/httpaccess.log* 2>/dev/null | tail -500 | tee -a "$OUT/http.txt"
echo "[+] Triage complete. Preserve $OUT before patching."
echo "[+] Next: apply Citrix fixed build per the security bulletin, then"
echo " 'kill nsconmsg -d' NOT required — instead: reboot, kill all sessions:"
echo " > kill aaa session -all ; kill system session -all"
Remediation
Execute in this order — the sequence matters on a device with confirmed active exploitation:
- Patch to the fixed build. Obtain the exact fixed versions for your release train from the official Citrix security bulletin for CVE-2026-88771 and CVE-2026-88772 (linked from the CISA alert and Citrix's security bulletin page). Verify the build post-upgrade with
show ns versionand record it against your change record. - Assume pre-patch compromise. Patching closes the door but does not evict an intruder already inside. Run the triage script above (or Citrix's published IoC checker for this CVE pair, if released) on every appliance before and after patching. In past NetScaler incidents, attackers established persistence that survived patching entirely.
- Kill all sessions after patching. From the CLI:
kill aaa session -allandkill system session -all. For memory-disclosure-class flaws (CWE-119), session tokens harvested before patching remain valid until invalidated — this is the exact lesson organizations learned the hard way in the CitrixBleed-era incidents. - Rotate everything that transited the appliance. Reset credentials for any user who authenticated through the Gateway during the exposure window, rotate service accounts and LDAP bind accounts configured on the appliance, and reissue TLS certificates/private keys stored on the device.
- Rebuild if IoCs are found. A compromised NetScaler should be rebuilt from a known-good image and configuration backup taken before the exposure window — not cleaned in place. Restore
ns.confonly after reviewing it line-by-line for injected responder/rewrite policies and rogue users. - Reduce the attack surface. Restrict management interface (NSIP) access to a dedicated management network, disable the GUI on internet-facing interfaces, and confirm no AAA/Gateway vServer is exposed beyond its intended audience. Geo-filter or ACL Gateway access where the business allows.
- Meet the mandate. FCEB agencies: remediate by the due date assigned in the KEV Catalog entry under BOD 26-04 and report per directive requirements. Everyone else: set your internal SLA to match — the KEV deadline is your best evidence-based proxy for adversary timelines.
- Instrument for next time. Forward NetScaler syslog, HTTP access logs, and shell command logs (
bash.log,sh.log,ns.log) to your SIEM today. An appliance you cannot log is an appliance you cannot defend.
If you cannot patch immediately, the only meaningful interim mitigations are taking the affected vServers offline or placing the appliance behind a compensating control that terminates untrusted traffic — there is no configuration toggle that safely neutralizes an input-validation flaw against an unauthenticated remote attacker. Do not bet your perimeter on a workaround.
Related Resources
Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.