Palo Alto Networks’ Unit 42 has reported active exploitation of two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting Citrix NetScaler devices. These vulnerabilities, which have a CVSS v4.0 base score of 9.5, allow attackers to execute remote code and potentially cause denial of service. The exploitation has been observed in the wild, with threat actors utilizing these vulnerabilities to deploy web shells, thereby establishing initial access and persistence within targeted organizations.
As of September 27, 2026, telemetry from Palo Alto Networks’ Cortex Xpanse identified over 50,000 exposed instances of NetScaler devices that could be vulnerable to these exploits. The vulnerabilities were detailed in a Citrix security advisory, which highlighted the urgent need for organizations to assess their exposure and implement necessary mitigations.
Understanding the Vulnerabilities
CVE-2026-88771 is a remote code execution (RCE) vulnerability that arises from improper input validation, allowing unauthenticated actors to execute commands on NetScaler Application Delivery Controller (ADC) and NetScaler Gateway systems. In contrast, CVE-2026-88772 is a memory overflow vulnerability that can lead to RCE or denial of service on the Datagram Transport Layer Security (DTLS) configuration of the same systems. Both vulnerabilities pose significant risks to organizations relying on these devices for application delivery and security.
Pre-Disclosure Activity and Exploitation Techniques
Unit 42’s analysis indicates that the initial exploitation activity began on August 21, 2026, with threat actors fingerprinting NetScaler devices. This reconnaissance phase involved sending specific requests to identify vulnerable systems. Following this, two distinct exploit chains were observed:
- The first involved exploiting the DTLS vulnerability to drop .deb web shell files, allowing attackers to maintain access.
- The second utilized a three-stage command injection exploit that ultimately led to the execution of PHP web shells.
In the command injection exploit, attackers crafted HTTP requests that manipulated log entries, which were later processed by a vulnerable Perl script on the NetScaler device. This technique allowed them to execute arbitrary commands, effectively compromising the device.
Post-Disclosure Activity and Recommendations
After the public disclosure of these vulnerabilities, a surge in scanning and testing activities was noted, indicating that other threat actors are now attempting to exploit the same vulnerabilities. Organizations are advised to take immediate action to mitigate risks:
- Update and Patch: Ensure that all Citrix software is updated to the latest versions to close these vulnerabilities.
- Confirm Exposure: Follow the guidelines in the Citrix security advisory to determine if your systems are vulnerable.
- Isolate Vulnerable Systems: If exposure is confirmed, isolate affected systems from the network to prevent further compromise.
- Preserve Evidence: Capture relevant logs and snapshots for forensic analysis.
- Hunt for Indicators: Look for signs of suspicious activity, such as unexpected outbound connections or unexplained gaps in logging.
While updating and patching will help prevent future exploitation, it is crucial to recognize that attackers who have already established persistence may still retain access to compromised networks.
For organizations utilizing Citrix NetScaler devices, proactive measures and vigilance are essential to safeguard against these vulnerabilities. The ongoing analysis by Palo Alto Networks will continue to provide insights into the evolving threat landscape associated with these exploits.
For further details on the vulnerabilities and protective measures, refer to the Unit 42 report.


