Threat Overview
Citrix published bulletin CTX697096 on September 27, 2026 and confirmed exploitation of two critical NetScaler zero-days. CVE-2026-88771 is a CVSS 9.5 unauthenticated command-execution flaw affecting every customer-managed NetScaler ADC and NetScaler Gateway deployment, including default configurations. CVE-2026-88772 is a CVSS 9.5 memory-overflow flaw capable of remote code execution or denial of service when DTLS is enabled; DTLS is enabled by default on VPN virtual servers. Fixed builds are 14.1-73.37, 13.1-64.23, 14.1-FIPS 14.1-73.37, and 13.1-FIPS/NDcPP 13.1.37.279 or later. On September 29, Google Threat Intelligence Group and Mandiant published observed exploitation details for CVE-2026-88772. The actor used malformed or fragmented DTLS records over UDP/443 to crash the NetScaler Packet Processing Engine and obtain initial root access. Post-exploitation activity included modified Apache handlers, .deb and .sig PHP web shells, icon-to-web-shell aliasing, setting the SUID bit on /bin/sh, appliance or HTTP-service restarts, WHIPSHOT web-shell tunneling, and the SLAPSHOT Python proxy for internal reconnaissance and credential theft. This is a material technical update to the earlier pre-advisory NetScaler warning because fixed builds, CVE identifiers, confirmed exploitation mechanics, IOCs, and post-exploitation artifacts are now available.
References
- Citrix CTX697096 — NetScaler ADC and Gateway security bulletin — September 27, 2026.
- Google Threat Intelligence Group / Mandiant — Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances — September 29, 2026.
- CISA — Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway — September 27, revised September 28, 2026.
Impacted Systems
- Vendor/product: Customer-managed Citrix NetScaler ADC and NetScaler Gateway, including hardware and VPX deployments.
- CVE-2026-88771: All deployments; default configuration is affected and no additional feature is required.
- CVE-2026-88772: Deployments with DTLS enabled; enabled by default on VPN virtual servers and applicable to DTLS virtual servers.
- Affected versions: All supported 14.1 and 13.1 builds below the fixed versions; Citrix ADC/NetScaler 12.1 and 13.0 are end of life and must be moved to a supported fixed release.
- Fixed versions: 14.1-73.37+, 13.1-64.23+, 14.1-FIPS 14.1-73.37+, and 13.1-FIPS/NDcPP 13.1.37.279+.
- Platform/service role: Internet-facing ADC, VPN gateway, authentication gateway, or application-delivery edge appliance; CVE-2026-88772 exploitation observed over UDP/443.
- Deployment model: Customer-managed appliances are in scope. Citrix-managed cloud services are not claimed affected by this customer-managed appliance bulletin.
Why this matters
NetScaler appliances terminate authentication and application traffic at the enterprise edge, often lack EDR coverage, and can reach identity and internal systems. The observed campaign achieved root access, installed stealth web shells and a tunnel, and used the appliance for internal reconnaissance and credential theft. Patching does not remove persistence already installed before the update.
Exploitation Status
Citrix confirms exploitation of both CVEs on unmitigated deployments. GTIG/Mandiant directly observed CVE-2026-88772 exploitation beginning by early September across North American and European government, financial, technology, education, legal, and professional-services organizations. The published web-shell artifacts, headers, URI paths, IP addresses, and process behaviors are confirmed observations; GTIG states it does not possess exploit code and describes the DTLS packet mechanics as an assessment based on frontline telemetry.
What this hunt looks for
DTLS handshake failures correlated with NSPPE crashes, pitboss restart failures, malicious Apache handler or alias changes, disguised .deb and .sig web shells, WHIPSHOT and SLAPSHOT artifacts, deceptive 404 responses, unexpected appliance egress, internal fan-out, and published staging IPs.
Required logs
NetScaler ns.log and FreeBSD /var/log/messages through Syslog; NetScaler web access and error logs, AppFlow, or CommonSecurityLog; firewall or flow data for appliance ingress and egress; and endpoint network telemetry for downstream IOC correlation. Standard ns.log forwarding alone is insufficient for several confirmed artifacts.
Hunt 1 — DTLS internal-error handshake followed by NSPPE termination
let Handshakes=Syslog
| where TimeGenerated > ago(30d)
| where SyslogMessage has_all ("SSL_HANDSHAKE_FAILURE","DTLSv1.0") and SyslogMessage has "Handshake failure-Internal Error"
| project Computer,HandshakeTime=TimeGenerated,HandshakeMessage=SyslogMessage;
let Crashes=Syslog
| where TimeGenerated > ago(30d)
| where SyslogMessage has_any ("NSPPE","pitboss") and SyslogMessage has_any ("exit with orphan rings","NOT restarting","terminated","core")
| project Computer,CrashTime=TimeGenerated,CrashMessage=SyslogMessage;
Handshakes
| join kind=inner Crashes on Computer
| where CrashTime between (HandshakeTime..HandshakeTime+5m)
| project Computer,HandshakeTime,CrashTime,HandshakeMessage,CrashMessage
| order by HandshakeTime desc
Hunt 2 — CVE-2026-88772 DTLS handshake-failure clusters
Syslog
| where TimeGenerated > ago(30d)
| where SyslogMessage has_all ("SSL_HANDSHAKE_FAILURE","DTLSv1.0") and SyslogMessage has "Handshake failure-Internal Error"
| summarize Events=count(),FirstSeen=min(TimeGenerated),LastSeen=max(TimeGenerated),Samples=make_set(SyslogMessage,10) by Computer,bin(TimeGenerated,10m)
| order by Events desc
Hunt 3 — NSPPE crash, pitboss failure, or appliance restart evidence
Syslog
| where TimeGenerated > ago(30d)
| where SyslogMessage has_any ("NSPPE","pitboss","nsshutdown")
| where SyslogMessage has_any ("exit with orphan rings","NOT restarting","segfault","terminated","core","-R","restart")
| project TimeGenerated,Computer,Facility,SeverityLevel,ProcessName,SyslogMessage
| order by TimeGenerated desc
Hunt 4 — Unauthorized PHP handlers, aliasing, or SUID shell changes
Syslog
| where TimeGenerated > ago(30d)
| where SyslogMessage has_any ("/etc/httpd.conf","/nsconfig/httpd.conf","/flash/nsconfig/httpd.conf","chmod u+s /bin/sh","AddHandler application/x-httpd-php","AliasMatch","php_flag engine on")
| project TimeGenerated,Computer,ProcessName,SeverityLevel,SyslogMessage
| order by TimeGenerated desc
Hunt 5 — Disguised web-shell and SLAPSHOT artifacts in appliance logs
Syslog
| where TimeGenerated > ago(30d)
| where SyslogMessage has_any ("/vpn/scripts/linux/","/vpn/media/","nsginstaller","nsgclient",".uxdport",".uxdlock","HTTP_X_UX","HTTP_NSC_LDAP","HTTP_NSC_CLIENTTYPE")
| where SyslogMessage has_any (".deb",".sig",".php",".ico",".uxdport",".uxdlock","HTTP_")
| project TimeGenerated,Computer,ProcessName,SeverityLevel,SyslogMessage
| order by TimeGenerated desc
Hunt 6 — Malicious command headers or masquerading URI paths in normalized security logs
union isfuzzy=true
(CommonSecurityLog | where TimeGenerated > ago(30d) | extend RawEvent=strcat(RequestURL," ",AdditionalExtensions," ",Message) | project TimeGenerated,DeviceName,SourceIP,DestinationIP,RawEvent),
(Syslog | where TimeGenerated > ago(30d) | extend RawEvent=SyslogMessage | project TimeGenerated,DeviceName=Computer,SourceIP="",DestinationIP="",RawEvent)
| where RawEvent has_any ("HTTP_NSC_LDAP","HTTP_NSC_CLIENTTYPE","HTTP_X_UX","/vpn/media/nsgclient.ico","/vpn/scripts/linux/nsginstaller","/vpn/scripts/linux/nsgclient")
| order by TimeGenerated desc
Hunt 7 — NetScaler web requests returning deceptive 404 responses with large payloads
CommonSecurityLog
| where TimeGenerated > ago(30d)
| extend Url=tostring(RequestURL),ResponseCode=tostring(DeviceResponseClassID),Bytes=tolong(column_ifexists("ReceivedBytes",0))
| where Url has_any ("/vpn/media/","/vpn/scripts/","/vpn/theme/")
| where Url matches regex @"(?i)\.(ico|sig|deb|php|rpm|tgz|dat|html)(\?|$)"
| where ResponseCode == "404" or DeviceAction has "404"
| where Bytes > 5000 or isnull(Bytes)
| project TimeGenerated,DeviceName,SourceIP,DestinationIP,RequestMethod,Url,ResponseCode,Bytes,DeviceAction,AdditionalExtensions
| order by TimeGenerated desc
Hunt 8 — Rare outbound destinations and internal fan-out from NetScaler appliances
let Baseline=CommonSecurityLog
| where TimeGenerated between (ago(30d)..ago(1d))
| where DeviceVendor has_any ("Citrix","NetScaler") or DeviceProduct has "NetScaler"
| summarize by SourceIP,DestinationIP,DestinationPort;
CommonSecurityLog
| where TimeGenerated > ago(1d)
| where DeviceVendor has_any ("Citrix","NetScaler") or DeviceProduct has "NetScaler"
| join kind=leftanti Baseline on SourceIP,DestinationIP,DestinationPort
| summarize FirstSeen=min(TimeGenerated),LastSeen=max(TimeGenerated),Connections=count(),Ports=make_set(DestinationPort,30) by SourceIP,DestinationIP
| order by Connections desc
Hunt 9 — Published exploitation and staging IP addresses
let IOCs=dynamic(["143.198.7.94","157.254.167.12"]);
union isfuzzy=true
(CommonSecurityLog | where TimeGenerated > ago(90d) and (SourceIP in (IOCs) or DestinationIP in (IOCs)) | project TimeGenerated,DeviceName,Evidence="Firewall",SourceIP,DestinationIP,DestinationPort,Detail=Message),
(DeviceNetworkEvents | where TimeGenerated > ago(90d) and (RemoteIP in (IOCs) or LocalIP in (IOCs)) | project TimeGenerated,DeviceName,Evidence="EndpointNetwork",SourceIP=LocalIP,DestinationIP=RemoteIP,DestinationPort=RemotePort,Detail=InitiatingProcessCommandLine)
| order by TimeGenerated desc
Detection Notes
- Hunt 1 is the highest-signal exploitation sequence because GTIG observed the DTLS error followed by NSPPE termination. Either event should still be reviewed independently because collection gaps can break the join.
- Standard NetScaler Syslog forwarding may omit
/var/log/messages, web logs, and file-integrity events. Missing those sources prevents detection of several confirmed behaviors. - Upstream firewalls generally cannot inspect malicious HTTP headers or decrypted URI paths because TLS terminates on the appliance.
- A 404 response is not inherently malicious. Prioritize
.ico,.sig, or.debrequests with large responses, command headers, configuration changes, or nearby appliance crashes. - Endpoint
Device*coverage is usually absent on NetScaler appliances. Network and Syslog telemetry are therefore primary. - The two IP indicators are not exhaustive and may later be reused or retired. Behavioral persistence and crash correlation carry more durable value.