Back to all incidents

Citrix Systems (Cloud Software Group)

citrix.com
CONFIRMED

Cloud Software Group and federal regulators issued emergency disclosures for two actively exploited critical zero-day vulnerabilities in Citrix NetScaler ADC and Gateway (CVE-2026-88771 and CVE-2026-88772, CVSS 9.5), enabling unauthenticated remote code execution and webshell deployment across 50,000+ exposed enterprise appliances worldwide.

Observable Status CONFIRMED
Industry / Sector Enterprise Software & Cloud Infrastructure
Incident Classification Zero-Day Exploitation & Remote Code Execution
Attributed Threat Actor State-Sponsored Advanced Persistent Threat (APT)
Affected Population Scope Under Audit
First Seen 2026-09-27
Last Updated 2026-10-06
In-Memory Session Tokens & Cookies SSL/TLS Private Keys & Cryptographic Secrets Appliance Configuration & Active Directory Bind Credentials Internal Network Access & Control Plane Credentials
OPEN WEIGHTS TELEMETRY • DETERMINISTIC CONFIDENCE

Confidence & Source Corroboration

100% CONFIDENCE
1. Primary Authority CONFIRMED BY REGULATOR Base weight: 65%
2. Evidence Specificity +19% Statutory Filing Verified
3. Corroboration Curve +25% 7 independent domains
4. Timeline & Staleness +5% 13 milestones logged
Corroborated Source Domains:
cisa.gov bleepingcomputer.com thehackernews.com darkreading.com ncsc.gov.uk hipaajournal.com databreaches.net
STATUTORY REGULATORY DISCLOSURES

Official Regulatory Filings & Legal Compliance Records

3 Verified Statutory Filings
Regulatory Ground Truth Standard: The disclosures below represent formal statutory filings and enforcement records submitted to government regulatory authorities (SEC, State Attorneys General, HHS OCR, CISA). In accordance with repository principles, this data is captured exactly as filed by the reporting entity and is never modified, overridden, or synthesized by AI models.
CISA (Cybersecurity and Infrastructure Security Agency)

Binding Operational Directive BOD 22-01 (KEV Catalog)

CONFIRMED BY REGULATOR
Docket / Accession ID CVE-2026-88771 / CVE-2026-88772
Statutory Filing Date 2026-09-27
Disclosed Impact Scope Under Audit
Evidence Standard Regulatory Ground Truth
Statutory Filing Details & Summary (Preserved As Filed):

Federal statutory directive issued under 44 U.S.C. § 3553(b)(2) mandating all Federal Civilian Executive Branch (FCEB) agencies isolate or remediate internet-facing NetScaler ADC and Gateway appliances within 72 hours due to active in-the-wild zero-day exploitation.

View Official Regulatory Filing Document https://www.cisa.gov/known-exploited-vulnerabilities-catalog
UK National Cyber Security Centre (NCSC)

Emergency Cyber Incident Advisory NCSC-ALERT-2026-09

CONFIRMED BY REGULATOR
Docket / Accession ID NCSC-ALERT-2026-09
Statutory Filing Date 2026-09-28
Disclosed Impact Scope Under Audit
Evidence Standard Regulatory Ground Truth
Statutory Filing Details & Summary (Preserved As Filed):

Statutory national alert for Critical National Infrastructure (CNI) operators ordering forensic volatile memory audits for persistent webshell implants across Citrix ADC appliances.

View Official Regulatory Filing Document https://www.ncsc.gov.uk/news/exploitation-of-vulnerabilities-affecting-citrix-netscaler-adc-and-citrix-netscaler-gateway
Cloud Software Group (Vendor Advisory)

Official Security Bulletin CTX697096

CONFIRMED BY REGULATOR
Docket / Accession ID CTX697096
Statutory Filing Date 2026-09-27
Disclosed Impact Scope Under Audit
Evidence Standard Regulatory Ground Truth
Statutory Filing Details & Summary (Preserved As Filed):

Official corporate security bulletin disclosing CVSS 9.5 remote code execution vulnerabilities across 50,000+ deployed enterprise gateway appliances with hotfix RPM instructions and memory indicators of compromise.

View Official Regulatory Filing Document https://support.citrix.com/s/article/CTX697096

Technical Forensic Briefing

Incident Overview

In late September 2026, Cloud Software Group (parent company of Citrix Systems) and international cybersecurity authorities issued emergency security disclosures regarding eight vulnerabilities affecting Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway).

Forensic telemetry and threat intelligence confirmed that two vulnerabilities—CVE-2026-88771 (CVSS 9.5) and CVE-2026-88772 (CVSS 9.5)—were weaponized as zero-days under active, in-the-wild exploitation by suspected state-sponsored advanced persistent threat (APT) actors prior to public disclosure:

  1. CVE-2026-88771 (CVSS 9.5): An improper input validation flaw allowing unauthenticated remote code execution (RCE) on internet-facing management and gateway ports in default configurations.
  2. CVE-2026-88772 (CVSS 9.5): A critical memory buffer boundary violation vulnerability allowing code execution or complete appliance denial-of-service when DTLS protocol features are active.

Telemetry audits identified that threat actors systematically exploited exposed appliances to establish persistent webshells, harvest memory artifacts, and steal cryptographic materials to bypass multi-factor authentication across victim networks. Over 50,000 vulnerable NetScaler appliances were identified as reachable across global enterprise, defense, healthcare, and telecommunications networks.

Compromised Assets & Data Scope

  • Exposed Infrastructure Fleet: More than 50,000 Internet-facing NetScaler ADC and NetScaler Gateway appliances globally across commercial and government organizations.
  • In-Memory Credentials & Session Tokens: Active user and administrator session tokens, SAML authentication assertions, and corporate Kerberos/Active Directory bind credentials harvested from volatile memory (nsppe process).
  • Cryptographic Keys & Secrets: Device TLS private keys, server certificates, and VPN gateway tunnel configuration secrets.
  • Persistence Artifacts: Execution of obfuscated webshells written to /var/netscaler/bins/ and /netscaler/ns_gui/vpn/, allowing threat actors to retain interactive terminal control even through soft firmware updates.
  • Network Ingress: Unrestricted lateral traversal into backend corporate networks, domain controllers, and cloud environments.

Statutory Disclosures & Compliance

  • CISA Binding Operational Directive (BOD 22-01): On September 27, 2026, CISA formally added CVE-2026-88771 and CVE-2026-88772 to the Known Exploited Vulnerabilities (KEV) Catalog. CISA mandated that all Federal Civilian Executive Branch (FCEB) agencies apply vendor remediations or isolate vulnerable appliances from federal networks by September 30, 2026.
  • UK National Cyber Security Centre (NCSC): Issued an emergency national alert advising critical national infrastructure (CNI) operators to conduct memory-dump forensic audits for webshell indicators prior to patching.
  • Cloud Software Group (Vendor Advisory): Published Security Bulletin CTX697096 detailing mitigation steps, hotfix RPM packages, and command-line verification scripts for NetScaler ADC and Gateway versions 14.1, 13.1, and 13.0.

Milestone Timeline (13 events logged)

2026-09-27 12:00 UTC
CONFIRMED BY REGULATOR

Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway

2026-09-29 18:37 UTC
INDEPENDENT VERIFICATION

Hackers exploit Citrix NetScaler zero-day to deploy web shells

2026-09-28 07:21 UTC
INDEPENDENT VERIFICATION

CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally

2026-09-27 07:47 UTC
INDEPENDENT VERIFICATION

Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation

2026-09-29 14:19 UTC
INDEPENDENT VERIFICATION

Dual NetScaler Zero-Days Trigger Chaos for Citrix Customers

2026-09-28 12:00 UTC
CONFIRMED BY REGULATOR

Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway

2026-09-29 13:53 UTC
CONFIRMED BY REGULATOR

Citrix Patches Actively Exploited NetScaler ADC & NetScaler Gateway Vulnerabilities

2026-09-27 12:00 UTC
CONFIRMED BY REGULATOR

CISA Adds Two Known Exploited Vulnerabilities to Catalog

2026-10-01 11:55 UTC
INDEPENDENT VERIFICATION

Suspected State Hackers Exploited Citrix NetScaler for Weeks. 50,000 Devices May Still Be Exposed.

2026-10-02 16:56 UTC
INDEPENDENT VERIFICATION

Kiteworks & Citrix Incidents Show Challenges of Zero-Day Response

2026-10-04 12:00 UTC
CONFIRMED BY REGULATOR

CISA Adds One Known Exploited Vulnerability to Catalog

2026-10-05 06:40 UTC
INDEPENDENT VERIFICATION

New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline

2026-10-06 10:26 UTC
CONFIRMED BY REGULATOR

Citrix Patches Third Actively Exploited NetScaler Zero Day

Have updated information or a new verifiable source?

This incident record is a flat Markdown file tracked in Git. Propose an update or add a milestone via Pull Request.

Propose Update via GitHub