Federal statutory directive issued under 44 U.S.C. § 3553(b)(2) mandating all Federal Civilian Executive Branch (FCEB) agencies isolate or remediate internet-facing NetScaler ADC and Gateway appliances within 72 hours due to active in-the-wild zero-day exploitation.
Citrix Systems (Cloud Software Group)
citrix.comCloud Software Group and federal regulators issued emergency disclosures for two actively exploited critical zero-day vulnerabilities in Citrix NetScaler ADC and Gateway (CVE-2026-88771 and CVE-2026-88772, CVSS 9.5), enabling unauthenticated remote code execution and webshell deployment across 50,000+ exposed enterprise appliances worldwide.
Confidence & Source Corroboration
Official Regulatory Filings & Legal Compliance Records
Statutory national alert for Critical National Infrastructure (CNI) operators ordering forensic volatile memory audits for persistent webshell implants across Citrix ADC appliances.
Official corporate security bulletin disclosing CVSS 9.5 remote code execution vulnerabilities across 50,000+ deployed enterprise gateway appliances with hotfix RPM instructions and memory indicators of compromise.
Technical Forensic Briefing
Incident Overview
In late September 2026, Cloud Software Group (parent company of Citrix Systems) and international cybersecurity authorities issued emergency security disclosures regarding eight vulnerabilities affecting Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway).
Forensic telemetry and threat intelligence confirmed that two vulnerabilities—CVE-2026-88771 (CVSS 9.5) and CVE-2026-88772 (CVSS 9.5)—were weaponized as zero-days under active, in-the-wild exploitation by suspected state-sponsored advanced persistent threat (APT) actors prior to public disclosure:
- CVE-2026-88771 (CVSS 9.5): An improper input validation flaw allowing unauthenticated remote code execution (RCE) on internet-facing management and gateway ports in default configurations.
- CVE-2026-88772 (CVSS 9.5): A critical memory buffer boundary violation vulnerability allowing code execution or complete appliance denial-of-service when DTLS protocol features are active.
Telemetry audits identified that threat actors systematically exploited exposed appliances to establish persistent webshells, harvest memory artifacts, and steal cryptographic materials to bypass multi-factor authentication across victim networks. Over 50,000 vulnerable NetScaler appliances were identified as reachable across global enterprise, defense, healthcare, and telecommunications networks.
Compromised Assets & Data Scope
- Exposed Infrastructure Fleet: More than 50,000 Internet-facing NetScaler ADC and NetScaler Gateway appliances globally across commercial and government organizations.
- In-Memory Credentials & Session Tokens: Active user and administrator session tokens, SAML authentication assertions, and corporate Kerberos/Active Directory bind credentials harvested from volatile memory (
nsppeprocess). - Cryptographic Keys & Secrets: Device TLS private keys, server certificates, and VPN gateway tunnel configuration secrets.
- Persistence Artifacts: Execution of obfuscated webshells written to
/var/netscaler/bins/and/netscaler/ns_gui/vpn/, allowing threat actors to retain interactive terminal control even through soft firmware updates. - Network Ingress: Unrestricted lateral traversal into backend corporate networks, domain controllers, and cloud environments.
Statutory Disclosures & Compliance
- CISA Binding Operational Directive (BOD 22-01): On September 27, 2026, CISA formally added CVE-2026-88771 and CVE-2026-88772 to the Known Exploited Vulnerabilities (KEV) Catalog. CISA mandated that all Federal Civilian Executive Branch (FCEB) agencies apply vendor remediations or isolate vulnerable appliances from federal networks by September 30, 2026.
- UK National Cyber Security Centre (NCSC): Issued an emergency national alert advising critical national infrastructure (CNI) operators to conduct memory-dump forensic audits for webshell indicators prior to patching.
- Cloud Software Group (Vendor Advisory): Published Security Bulletin CTX697096 detailing mitigation steps, hotfix RPM packages, and command-line verification scripts for NetScaler ADC and Gateway versions 14.1, 13.1, and 13.0.
Milestone Timeline (13 events logged)
Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway
Hackers exploit Citrix NetScaler zero-day to deploy web shells
CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally
Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
Dual NetScaler Zero-Days Trigger Chaos for Citrix Customers
Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway
Citrix Patches Actively Exploited NetScaler ADC & NetScaler Gateway Vulnerabilities
CISA Adds Two Known Exploited Vulnerabilities to Catalog
Suspected State Hackers Exploited Citrix NetScaler for Weeks. 50,000 Devices May Still Be Exposed.
Kiteworks & Citrix Incidents Show Challenges of Zero-Day Response
CISA Adds One Known Exploited Vulnerability to Catalog
New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline
Citrix Patches Third Actively Exploited NetScaler Zero Day
Have updated information or a new verifiable source?
This incident record is a flat Markdown file tracked in Git. Propose an update or add a milestone via Pull Request.