Citrix NetScaler ADC and Gateway (CVE-2026-88771)
CVE-2026-88771CWE-20OWASP A03:2021CVSS 9.8Updated October 1, 20262 min read
CVE-2026-88771 is a command injection in Citrix NetScaler ADC and NetScaler Gateway. Text an attacker slips into the appliance's own log files is later executed as a shell command, as root and without any login. It works in the default configuration. Attackers exploited it for weeks before the patch of 27 September 2026, so a patched appliance may still be compromised.
- Affected
- NetScaler ADC and Gateway 14.1 before 14.1-73.37 and 13.1 before 13.1-64.23; ADC FIPS before 14.1-73.37 FIPS; ADC FIPS and NDcPP before 13.1-37.279
- Patched in
- 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS and 13.1-37.279 (FIPS and NDcPP) or later
- Actively exploited
- yes
On Sunday 27 September 2026 Citrix patched eight vulnerabilities in NetScaler ADC and NetScaler Gateway. Two were already being exploited, and by then attackers had been inside some networks for more than three weeks. CVE-2026-88771 needs nothing more than a reachable appliance.
What is CVE-2026-88771
NetScaler ADC and Gateway usually sit at the very front of the network, handling VPN and application access. CVE-2026-88771 is a command injection in a maintenance script. As CERT-EU worked out, the script ns_monuploadd_err.pl periodically searches the appliance’s logs for a specific error message and pastes part of the matching line unquoted into a shell command. An attacker can write that line themselves: a login attempt with a crafted username lands in the log as exactly that error, followed by shell commands. The next time the script runs, they execute as root.
Citrix classifies the flaw as improper input validation (CWE-20) and publishes only a CVSS v4.0 score of 9.5. NVD rates it 9.8 on CVSS v3.1.
What the attackers did
According to eSentire, the flaw was exploited as a zero-day from as early as 5 September. The attackers used it to enable PHP on the appliance and plant a webshell reachable from the internet. In one intrusion eSentire investigated, the webshell was in use from that day with signs of data exfiltration, after which the attacker opened sessions on internal virtual desktops.
The companion flaw CVE-2026-88772, a memory overflow in the DTLS handling, was abused in the same period. Mandiant and Google Threat Intelligence Group attribute its exploitation since early September to suspected state-linked actors, without naming a group. Researcher Kevin Beaumont reported on 28 September tracking more than 100 victim organisations. As of 1 October 2026, exploitation is ongoing.
In Europe, CERT-EU traced the flaw after the European Court of Auditors and the European Central Bank spotted the attackers’ requests in their logs. Germany’s BSI warns at level 3 (orange) and counts several thousand affected appliances in Germany alone. The Dutch central government disconnected Citrix environments from the internet as a precaution.
A log file is input too
Log files feel internal and trustworthy, and that is the mistake. Almost everything in a log was typed by someone else: a username, a URL, a User-Agent. Code that feeds a log line to a shell has a command injection with one extra step. According to watchTowr’s analysis, the patched script parses the log in Perl, accepts only a strict pattern and runs the command without a shell.
And as with Citrix Bleed, on an edge device a patch closes the door but does not remove whoever already came in.
What to do now
- Update to 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS or 13.1-37.279 (FIPS and NDcPP), or later.
- Before updating, secure the logs and a memory dump, as the Dutch NCSC advises, so that evidence of earlier abuse survives.
- Check for compromise with Citrix’s indicators and review logs back to early September. Unknown files under /var/netscaler/logon/LogonPoint/custom/ and a modified httpd.conf are strong signals.
- If you find traces, follow Citrix’s guidance for compromised appliances: rebuild rather than just patch, rotate passwords and secrets, revoke the certificates stored on the appliance and investigate every system it connected to.
Sources
- Citrix: NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778support.citrix.com
- NVD: CVE-2026-88771nvd.nist.gov
- CERT-EU: Taking 'execute logging' a bit too literally - CVE-2026-88771cert.europa.eu
- eSentire: Ongoing Exploitation of Citrix NetScaler ADC and NetScaler Gateway Vulnerabilitiesesentire.com
- NCSC-NL: NCSC-2026-0394 Kwetsbaarheden verholpen in NetScaler ADC en NetScaler Gatewayadvisories.ncsc.nl
- BSI: Citrix NetScaler: Systeme werden über ZeroDay-Schwachstellen angegriffenbsi.bund.de
Frequently asked questions
Is patching enough?
No. The update stops new exploitation, but Germany's BSI warns that webshells and configuration changes planted earlier can stay active afterwards. The Dutch NCSC advises securing logs and a memory dump before updating, and treating any appliance that was reachable from the internet as possibly compromised.
Does it need a particular feature enabled?
No. Citrix states that every NetScaler ADC and Gateway deployment on an affected version is vulnerable in its default configuration. The companion flaw CVE-2026-88772 requires DTLS, which is enabled by default on a VPN virtual server.
How can we tell whether we were hit?
Run the indicators of compromise Citrix provides through NetScaler Console. CERT-EU also advises searching the authentication logs for the message 'PPE missed too many heartbeats', looking for base64 in User-Agent strings and checking httpd.conf for changes. Go back to at least early September 2026.
Related articles
- CVEsCWE-119A07:2021Citrix Bleed (CVE-2023-4966)Citrix Bleed explained: how attackers read session tokens out of NetScaler memory, bypassed MFA with them, and why patching alone was not enough.
- GlossaryZero-dayA zero-day is a vulnerability still unknown to the vendor, meaning no patch exists yet. Learn how zero-day exploits work and how to limit the risk they pose.
- VulnerabilitiesCWE-78A03:2021OS command injectionOS command injection explained: how shell metacharacters reach a system call, what an attacker gains, and why argument arrays without a shell fix it.
- VulnerabilitiesCWE-20A04:2021Input validation missing on the serverValidation that only happens in JavaScript can be bypassed with one direct request. Learn why the server must check every value again.