threat_intelligence2575 wordsRead on Huntaegis

Frequently asked questions about reported Citrix NetScaler zero

Frequently asked questions about reported Citrix NetScaler zero-day vulnerabilities CVE-2026-88771 and CVE-2026-88772, two zero-day vulnerabilities in Citrix NetScaler, have been confirmed as exploited in the wild. Citrix released patches on September 27, 2026. On October 3, Citrix disclosed CVE-2026-88779, an exploited denial of service flaw affecting SAML deployments. Fixing it requires newer builds. Change log Update October 4: On October 3, Citrix published security bulletin CTX697174 with fixed versions for CVE-2026-88779, an exploited denial of service vulnerability affecting NetScaler deployments configured for SAML. Post updated with details on CVE-2026-88779, findings from Mandiant and Google Threat Intelligence Group (GTIG) on the exploitation of CVE-2026-88772, CISA KEV additions, public proof-of-concept tooling, and expanded mitigation and hunting guidance. Click here to review the change log history Update October 4: On October 3, Citrix published security bulletin CTX697174 with fixed versions for CVE-2026-88779, an exploited denial of service vulnerability affecting NetScaler deployments configured for SAML. Post updated with details on CVE-2026-88779, findings from Mandiant and Google Threat Intelligence Group (GTIG) on the exploitation of CVE-2026-88772, CISA KEV additions, public proof-of-concept tooling, and expanded mitigation and hunting guidance. Update September 27: Citrix published security bulletin CTX697096, confirming CVE-2026-88771 and CVE-2026-88772 as the two zero-day RCE vulnerabilities and releasing patches. Post updated with CVE IDs, CVSS scores, patch versions, and IoC guidance. September 27: Original publication based on limited public information ahead of Citrix's official advisory. Key takeaways - Citrix has confirmed two critical zero-day vulnerabilities in NetScaler ADC and NetScaler Gateway, both capable of remote code execution and actively exploited in the wild. A third vulnerability, CVE-2026-88779, can cause denial of service on SAML-enabled deployments and has also been exploited. - Citrix released patches on September 27, 2026, and newer builds on October 3, 2026. Organizations that use SAML and already upgraded to the September 27 builds need to upgrade again. Citrix recommends that every customer move to the newest builds. - According to Mandiant and Google Threat Intelligence Group (GTIG), exploitation of CVE-2026-88772 began no later than early September. Organizations should check for signs of compromise and preserve evidence before patching. Background Tenable's Research Special Operations (RSO) team has compiled this blog to answer Frequently Asked Questions (FAQ) regarding zero-day vulnerabilities in Citrix NetScaler that have been exploited in the wild. The following FAQ was originally based on limited public information and has been updated as Citrix and security researchers published details. This post was last updated on October 4, 2026 following publication of the Citrix security bulletin for CVE-2026-88779. Security researcher Kevin Beaumont dubbed this incident “PitScaler” on September 28, and the name has since appeared in press coverage of CVE-2026-88771 and CVE-2026-88772. An independent website, PitScaler, tracks the incident and collects government advisories and published research in one place. FAQ What is the source of the NetScaler vulnerabilities? On September 25, 2026, reports surfaced through a reddit post on r/Citrix regarding advice to shut down “Netscalers.” This included a report from a user that said this information came from the “Dutch national cyber security center” and further details included a note about two zero-day vulnerabilities. On September 26, 2026, additional reports confirming the existence of these flaws became public, including social posts from researchers at watchTowr on X, as well as Kevin Beaumont on Mastodon. What is the context surrounding the Dutch National Cyber Security Centre (NCSC-NL) alert? The Reddit post on r/Citrix cited details from an NCSC-NL pre-notification that had not yet been made public. Community members in that thread said the pre-notification was distributed under Traffic Light Protocol (TLP):AMBER+STRICT restrictions. Tenable's RSO has not independently obtained or reviewed the contents of this notification. Has Citrix confirmed the presence of zero-day vulnerabilities? Yes. Citrix published a security bulletin (CTX697096) on September 27, 2026, confirming two zero-day vulnerabilities and noting that both CVEs have been observed being exploited against customer deployments. What are these zero-day vulnerabilities? Citrix has confirmed two zero-day vulnerabilities in NetScaler ADC and NetScaler Gateway. CVE-2026-88771 affects all deployments, including default configurations. CVE-2026-88772 only affects appliances with Datagram Transport Layer Security (DTLS) turned on, which VPN virtual servers have out of the box. | CVE | Description | CVSSv4 | |---|---|---| | CVE-2026-88771 | Citrix NetScaler ADC and NetScaler Gateway Improper Input Validation vulnerability | 9.5 | | CVE-2026-88772 | Citrix NetScaler ADC and NetScaler Gateway Memory Overflow vulnerability | 9.5 | Analysis by Mandiant and GTIG suggests attackers exploit CVE-2026-88772 by sending malformed DTLS traffic to the appliance, which gives them root-level access. Citrix also addressed six additional vulnerabilities affecting various configurations: | CVE | Description | CVSSv4 | |---|---|---| | CVE-2026-88773 | Citrix NetScaler ADC and NetScaler Gateway HTTP Request Smuggling vulnerability | 9.3 | | CVE-2026-88774 | Citrix NetScaler ADC and NetScaler Gateway Feature Policy Bypass vulnerability | 7.0 | | CVE-2026-88775 | Citrix NetScaler ADC and NetScaler Gateway Memory Overflow vulnerability | 8.8 | | CVE-2026-88776 | Citrix NetScaler ADC and NetScaler Gateway Memory Overflow vulnerability | 8.8 | | CVE-2026-88777 | Citrix NetScaler ADC and NetScaler Gateway Memory Overflow vulnerability | 8.8 | | CVE-2026-88778 | Citrix NetScaler ADC and NetScaler Gateway TCP ISN Prediction vulnerability | 8.8 | watchTowr originally confirmed details for the zero-days on September 26, 2026: We have been made aware of further info, which we are sharing. We had no idea Citrix sysadmins were like GTA6 fans - so friendly 🤗 Please, direct further questions to Citrix. We are not Citrix PSIRT (despite it occasionally looking that way). Citrix comms & patches are… https://t.co/OemTXwG8PB— watchTowr (@watchtowrcyber) September 26, 2026 What is CVE-2026-88779? CVE-2026-88779 is a memory overflow vulnerability in NetScaler ADC and NetScaler Gateway. Exploiting it can cause a denial of service. It received a CVSSv4 score of 8.7. Citrix disclosed it on October 3 in security bulletin CTX697174 and credited Bishop Fox and watchTowr in the bulletin. | CVE | Description | CVSSv4 | |---|---|---| | CVE-2026-88779 | Citrix NetScaler ADC and NetScaler Gateway Memory Overflow vulnerability | 8.7 | Citrix says it has “observed targeted attacks on unmitigated NetScaler deployments.” CISA added CVE-2026-88779 to its KEV catalog on October 4. Only appliances configured as a SAML service provider (SP) or SAML identity provider (IdP) are affected. Administrators can check their NetScaler configuration for either of the following entries: add authentication samlAction (SAML SP)add authentication samlIdPProfile (SAML IdP) According to Citrix, the flaw affects service availability, and so far it has found no impact on customer data integrity. In its October 3 update on the SAML issue, the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) says an attacker targeting this flaw “may induce system crashes, denial of service and potential exploitation,” and that Australian organizations have been affected. Are these zero-day vulnerabilities related to CVE-2026-19490 and CVE-2026-19489? No. Neither CVE-2026-19490 nor CVE-2026-19489 appears to be related. Both are previously disclosed NetScaler ADC and NetScaler Gateway flaws that already have patches. CVE-2026-19490 was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on September 9, 2026. Reports say these vulnerabilities were exploited. How widespread are the attacks? Mandiant and GTIG published findings on September 29 showing that CVE-2026-88772 has been exploited since at least early September. They observed evidence that organizations across government, education, technology, financial services, and legal and professional services in North America and Europe were likely affected. On September 30, ASD’s ACSC said it had received reports from Australian organizations confirming exploitation, and it recommends that organizations look for evidence of compromise dating back to at least September 4. On September 26, before patches were available, Kevin Beaumont stated: “The Netscaler zero day thing is real, being used in active attacks. No patch yet, if sensitive to Netscaler vulns switch it off.” How many Citrix NetScaler vulnerabilities have been exploited in the wild in the past? Citrix NetScaler devices have historically been a popular target for attackers. As of October 4, 2026, CISA’s KEV catalog had 18 entries for NetScaler ADC and NetScaler Gateway (including those listed under the former Citrix ADC name) and 27 entries for Citrix products overall, including CVE-2026-88771, CVE-2026-88772 and CVE-2026-88779. The RSO team has covered several notable incidents: | CVE | Description | KEV added | Ransomware | Tenable blogs | |---|---|---|---|---| | CVE-2026-88779 | Citrix NetScaler ADC and NetScaler Gateway Memory Overflow vulnerability | 2026-10-04 | Unknown | Frequently asked questions about reported Citrix NetScaler zero-day vulnerabilities | | CVE-2026-88772 | Citrix NetScaler ADC and NetScaler Gateway Memory Overflow vulnerability | 2026-09-27 | Unknown | Frequently asked questions about reported Citrix NetScaler zero-day vulnerabilities | | CVE-2026-88771 | Citrix NetScaler ADC and NetScaler Gateway Improper Input Validation vulnerability | 2026-09-27 | Unknown | Frequently asked questions about reported Citrix NetScaler zero-day vulnerabilities | | CVE-2026-8452 | Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow vulnerability | 2026-08-26 | Unknown | - | | CVE-2026-3055 | Citrix NetScaler Out-of-Bounds Read vulnerability | 2026-03-30 | Unknown | - | | CVE-2025-7775 | Citrix NetScaler Memory Overflow vulnerability | 2025-08-26 | Unknown | CVE-2025-7775: Citrix NetScaler ADC and NetScaler Gateway Zero-Day Remote Code Execution Vulnerability Exploited in the Wild | | CVE-2025-5777 | Citrix NetScaler ADC and Gateway Out-of-Bounds Read vulnerability (“CitrixBleed 2”) | 2025-07-10 | Known | CVE-2025-5777, CVE-2025-6543: Frequently Asked Questions About CitrixBleed 2 and Citrix NetScaler Exploitation | | CVE-2025-6543 | Citrix NetScaler ADC and Gateway Buffer Overflow vulnerability | 2025-06-30 | Unknown | CVE-2025-5777, CVE-2025-6543: Frequently Asked Questions About CitrixBleed 2 and Citrix NetScaler Exploitation | | CVE-2023-6549 | Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow vulnerability | 2024-01-17 | Unknown | CVE-2023-6548, CVE-2023-6549: Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC and NetScaler Gateway | | CVE-2023-6548 | Citrix NetScaler ADC and NetScaler Gateway Code Injection vulnerability | 2024-01-17 | Unknown | CVE-2023-6548, CVE-2023-6549: Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC and NetScaler Gateway | | CVE-2023-4966 | Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow vulnerability (“CitrixBleed”) | 2023-10-18 | Known | [1] [2] [3] | | CVE-2023-3519 | Citrix NetScaler ADC and NetScaler Gateway Code Injection vulnerability | 2023-07-19 | Known | CVE-2023-3519: Critical RCE in Netscaler ADC (Citrix ADC) and Netscaler Gateway (Citrix Gateway) | | CVE-2020-8193 | Citrix ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass vulnerability | 2021-11-03 | Unknown | Government Agencies Warn of State-Sponsored Actors Exploiting Publicly Known Vulnerabilities | | CVE-2019-19781 | Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution vulnerability | 2021-11-03 | Known | [1] [2] | Which threat actors are exploiting these vulnerabilities? No threat actor has been publicly named. In attacks exploiting CVE-2026-88772, Mandiant and GTIG identified two new malware families, WHIPSHOT and SLAPSHOT. For context, based on our research, roughly two-thirds of threat actor activity targeting Citrix NetScaler over the last seven years involved advanced persistent threat (APT) groups, while one-third involved ransomware groups and their affiliates. Is there a proof-of-concept (PoC) available for these vulnerabilities? Yes. watchTowr published technical analyses of CVE-2026-88771 and CVE-2026-88772, along with tools that demonstrate code execution for each. watchTowr released them to help defenders, but they also work as public PoCs, with some limitations. As of October 4, 2026, we are not aware of a public PoC for CVE-2026-88779. Are patches or mitigations available? Yes. Citrix urges customers running affected versions to install one of the updated versions. Organizations whose NetScaler appliances are configured for SAML need the newer builds released on October 3 to address CVE-2026-88779. | Product Branch | Fixed Versions for CVE-2026-88771 through CVE-2026-88778 | Fixed Versions for CVE-2026-88779 | |---|---|---| | NetScaler ADC and NetScaler Gateway 14.1 | 14.1-73.37 and later | 14.1-73.41 and later | | NetScaler ADC and NetScaler Gateway 13.1 | 13.1-64.23 and later | 13.1-64.28 and later | | NetScaler ADC 14.1-FIPS | 14.1-73.37 FIPS and later | 14.1-73.41 FIPS and later | | NetScaler ADC 13.1-FIPS and 13.1-NDcPP | 13.1-37.279 and later | 13.1-37.282 and later | Citrix says deployments affected by CVE-2026-88778 also need to turn on Enhanced ISN Generation in their TCP settings. Until organizations can install the newer builds, Citrix has released Global Deny List signatures that can help mitigate CVE-2026-88779 on standard (non-FIPS) 14.1 and 13.1 appliances that are already running the September 27 builds and managed through NetScaler Console. Citrix’s blog lists the requirements. For CVE-2026-88772, Mandiant suggests blocking inbound UDP port 443 at an upstream firewall and turning off DTLS on gateways that don’t use it. These steps do not address CVE-2026-88771, so installing a fixed build is still required. Citrix’s bulletins list fixes only for the 14.1 and 13.1 branches. NetScaler ADC and NetScaler Gateway versions 12.1 and 13.0 have reached end-of-life (EOL) and no longer receive security updates, and Citrix has not said whether they are affected by these vulnerabilities. Organizations still running these versions should move to a supported, fixed build. Are there any indicators of compromise for these vulnerabilities? Citrix has made generic indicators of compromise (IoCs) available through NetScaler Console, which requires product usage telemetry to be enabled. Customers who do not use NetScaler Console, or cannot access the feature, can contact Citrix Support to request the IoCs. Citrix notes that the IoC information may not cover all threat actor tactics, techniques and procedures (TTPs) and recommends engaging forensic investigators for a comprehensive assessment. Mandiant and GTIG also published hunting guidance, along with IoCs and YARA rules. Because patching does not remove an attacker who already has access, organizations should check their appliances for signs of compromise. Mandiant also recommends revoking active sessions and rotating credentials used by the appliance after patching. Has Tenable Research classified these vulnerabilities as part of Vulnerability Watch? Yes. CVE-2026-88771, CVE-2026-88772 and CVE-2026-88779 have been classified as “Vulnerability of Interest” as part of Vulnerability Watch. Has Tenable released any product coverage for these vulnerabilities? A list of Tenable plugins for these vulnerabilities can be found on the individual CVE pages for CVE-2026-88771, CVE-2026-88772 and CVE-2026-88779 as they’re released. These links display all available plugins for these vulnerabilities, including upcoming plugins in our Plugins Pipeline. Additionally, customers can utilize Tenable Attack Surface Management to identify public-facing NetScaler assets by using the following query: Server Contains Netscaler OR Document Title contains Citrix Gateway Get more information - Citrix Security Bulletin CTX697096: NetScaler ADC and NetScaler Gateway Security Bulletin - Citrix Community: NetScaler ADC and NetScaler Gateway Security Bulletin (CVE-2026-88771 through CVE-2026-88778) - Reddit r/Citrix thread: “Netscaler leak?” - watchTowr post on X: Citrix NetScaler RCE confirmation - Kevin Beaumont on Mastodon: Zero-day confirmation - Citrix Security Bulletin CTX697174: NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-88779 - Citrix Community: Understanding and Addressing CVE-2026-88779 in Citrix NetScaler ADC and Citrix NetScaler Gateway - Mandiant and Google Threat Intelligence Group: Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances - ASD’s ACSC: Critical vulnerabilities in Citrix NetScaler ADC and Citrix NetScaler Gateway products - watchTowr Labs: CVE-2026-88771 analysis - watchTowr Labs: CVE-2026-88772 analysis - Kevin Beaumont on Mastodon: PitScaler - PitScaler: Citrix NetScaler Zero-Day Crisis tracker Join Tenable's Research Special Operations (RSO) Team on Tenable Connect for further discussions on the latest cyber threats. Learn more about Tenable One, the Exposure Management Platform for the modern attack surface. Learn more - Exposure Management - Vulnerability Management Tenable One Request a demo The world’s leading AI-powered exposure management platform. Thank You Thank you for your interest in Tenable One. A representative will be in touch soon. Form ID: 7469 Form Name: one-eval Form Class: c-form form-panel__global-form c-form--mkto js-mkto-no-css js-form-hanging-label c-form--hide-comments Form Wrapper ID: one-eval-form-wrapper Confirmation Class: one-eval-confirmform-modal Simulate Success

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.