INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Citrix Patches Third Actively Exploited NetScaler Zero Day Vulnerability
| 2026-10-06 10:26 CRITICAL HIGH EXPLOITED VULNERABILITY VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
On October 6, 2026, a new zero-day vulnerability was discovered in Citrix NetScaler ADC and Gateway appliances, with the latest vulnerability affecting systems prior to patch versions 14.1-73.41 and 13.1-64.28. The identified entity behind this attack is unknown at this time. This vulnerability allows an attacker to crash the system, with repeated attacks resulting in denial of service, unlike two previously patched zero-days that can lead to remote code execution. The current status indicates that Citrix has released patches for this vulnerability and urges all customers with vulnerable appliances to upgrade to the fixed version as soon as possible.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-88771, CVE-2026-88773 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
cy•••••.social
ww•••••.com
sh•••••.org
lo•••••.info
wa•••••.py
WR•••••.gz
213.209.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Salt TyphoonSalt Typhoon
CVE-2026-88771CVE-2026-88771
CVE-2026-88773CVE-2026-88773
CVE-2026-88776CVE-2026-88776
CVE-2026-88772CVE-2026-88772
CVE-2026-88774CVE-2026-88774
CVE-2026-88777CVE-2026-88777
CVE-2026-88779CVE-2026-88779
CVE-2026-88778CVE-2026-88778
CVE-2026-19489CVE-2026-19489
CVE-2026-19490CVE-2026-19490
CVE-2026-88782CVE-2026-88782
CVE-2026-88775CVE-2026-88775
CVE-2026-8877CVE-2026-8877
Target & Sectors
EUROPE
EUROPE
BENELUX
BENELUX
MIDDLE_EAST
MIDDLE_EAST
NORTH_AMERICA
NORTH_AMERICA
telecommunicationstelecommunications
educationeducation
governmentgovernment
legallegal
financefinance
Incident Timeline
2025/09/29
Google Threat Intelligence Group reported that 48% of enterprise-related zero-days in 2025 were attributed to vulnerabilities in Citrix NetScaler devices.
Click on any entity below to view its context and source!
attribution
Google Threat Intelligence Group
Vulnerabilities in these devices accounted for
48% of the enterprise-related zero-days last year
, according to Google Threat Intelligence Group.
tactic
T1588.006 - Vulnerabilities
Vulnerabilities in these devices accounted for
48% of the enterprise-related zero-days last year
, according to Google Threat Intelligence Group.
general_metric
48 %
Vulnerabilities in these devices accounted for
48% of the enterprise-related zero-days last year
, according to Google Threat Intelligence Group.
Sept. 3
Threat actors utilized the zero-day exploit CVE-2026-88772 on September 3.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-88772
The earliest known instance of
CVE-2026-88772
exploitation occurred Sept. 3, Mandiant researchers told CyberScoop Tuesday.
organisation
Mandiant
The earliest known instance of
CVE-2026-88772
exploitation occurred Sept. 3, Mandiant researchers told CyberScoop Tuesday.
organisation
CyberScoop
The earliest known instance of
CVE-2026-88772
exploitation occurred Sept. 3, Mandiant researchers told CyberScoop Tuesday.
late September 2026
Mandiant and Google Threat Intelligence Group detected active exploitation of a zero-day vulnerability in Citrix NetScaler ADC and Gateway appliances.
Click on any entity below to view its context and source!
attribution
Mandiant
Mandiant and Google Threat Intelligence Group caught active exploitation of a zero-day in Citrix NetScaler ADC and Gateway appliances in late September 2026.
attribution
Google Threat Intelligence Group
Mandiant and Google Threat Intelligence Group caught active exploitation of a zero-day in Citrix NetScaler ADC and Gateway appliances in late September 2026.
attribution
Citrix NetScaler ADC
Mandiant and Google Threat Intelligence Group caught active exploitation of a zero-day in Citrix NetScaler ADC and Gateway appliances in late September 2026.
2026/09/22
Threat actors utilized zero-day exploits against Citrix NetScaler systems, but the security vendor and researchers did not confirm these attacks until late last week on September 22, 2026.
Sept. 24
Threat actors utilized zero-day exploits to conduct remote code execution attacks against Citrix NetScaler installations via a single US-based IP address.
Click on any entity below to view its context and source!
tactic
Remote Code Execution
On Sept. 24, threat detection firm GreyNoise Intelligence observed a single US-based IP address scanning for Citrix NetScaler installations and conducting remote code execution (RCE) attacks.
target_region
United States
On Sept. 24, threat detection firm GreyNoise Intelligence observed a single US-based IP address scanning for Citrix NetScaler installations and conducting remote code execution (RCE) attacks.
attribution
GreyNoise Intelligence
On Sept. 24, threat detection firm GreyNoise Intelligence observed a single US-based IP address scanning for Citrix NetScaler installations and conducting remote code execution (RCE) attacks.
attribution
IP
On Sept. 24, threat detection firm GreyNoise Intelligence observed a single US-based IP address scanning for Citrix NetScaler installations and conducting remote code execution (RCE) attacks.
attribution
Citrix NetScaler
On Sept. 24, threat detection firm GreyNoise Intelligence observed a single US-based IP address scanning for Citrix NetScaler installations and conducting remote code execution (RCE) attacks.
at least Sept. 24
Attackers have exploited a second Citrix NetScaler zero-day, CVE-2026-88771, since at least September 24.
Click on any entity below to view its context and source!
organisation
NetScaler
Attackers have also exploited a second Citrix NetScaler zero-day —
CVE-2026-88771
— since at least Sept. 24, according to GreyNoise, but researchers said that campaign likely started earlier as well.
vulnerability
CVE-2026-88771
Attackers have also exploited a second Citrix NetScaler zero-day —
CVE-2026-88771
— since at least Sept. 24, according to GreyNoise, but researchers said that campaign likely started earlier as well.
organisation
GreyNoise
Attackers have also exploited a second Citrix NetScaler zero-day —
CVE-2026-88771
— since at least Sept. 24, according to GreyNoise, but researchers said that campaign likely started earlier as well.
Sept. 25
Threat actors utilized zero-day exploits to trigger a malicious campaign targeting Citrix NetScaler systems, prompting the company's recommendation for customers to take their systems offline.
Sept. 26
Benjamin Harris urged NetScaler users to take their systems offline on September 26.
Sept. 27, 2026
Palo Alto Networks Cortex Xpanse has identified over 50,277 exposed instances potentially vulnerable to the specified CVEs based on its telemetry.
Click on any entity below to view its context and source!
infrastructure
82.080.467
+82.080.467.8774
Additional References
Updated Sept. 27, 2026 at 4:15 p.m. PT to add information about
Cortex Xpanse
telemetry.
organisation
Additional References
Updated
+82.080.467.8774
Additional References
Updated Sept. 27, 2026 at 4:15 p.m. PT to add information about
Cortex Xpanse
telemetry.
organisation
Cortex Xpanse
+82.080.467.8774
Additional References
Updated Sept. 27, 2026 at 4:15 p.m. PT to add information about
Cortex Xpanse
telemetry.
organisation
Palo Alto Networks Cortex Xpanse
As of Sept. 27, 2026, Palo Alto Networks Cortex Xpanse has identified 50,277 exposed instances that could potentially be vulnerable to these CVEs based on our telemetry.
general_metric
50,277 exposed instances
As of Sept. 27, 2026, Palo Alto Networks Cortex Xpanse has identified 50,277 exposed instances that could potentially be vulnerable to these CVEs based on our telemetry.
As of Sept. 27, 2026, Palo Alto Networks
Cortex Xpanse
has identified the presence of over 50,277 exposed instances potentially vulnerable to these CVEs based on our telemetry.
organisation
Palo Alto Networks
Cortex Xpanse
As of Sept. 27, 2026, Palo Alto Networks
Cortex Xpanse
has identified the presence of over 50,277 exposed instances potentially vulnerable to these CVEs based on our telemetry.
September 27
Threat actors utilized newly disclosed zero-day exploits for Citrix NetScaler ADC and Gateway to conduct malicious activities.
Click on any entity below to view its context and source!
organisation
Citrix NetScaler ADC
In a bulletin on September 27 the vendor confirmed eight new flaws in Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway).
organisation
Citrix ADC
In a bulletin on September 27 the vendor confirmed eight new flaws in Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway).
2026/09/28
Threat actors exploited zero-day vulnerabilities in Citrix NetScaler releases 13.1-64.23 and later, as well as 14.1-FIPS and certain other versions, to conduct malicious activities on 2026/09/28.
September 28
The Australian Signals Directorate's Australian Cyber Security Centre issued a critical alert on September 28 urging organizations to patch Citrix NetScaler systems due to a zero-day exploit campaign.
Click on any entity below to view its context and source!
organisation
The Australian Signals Directorate’s
The Australian Signals Directorate’s Australian Cyber Security Centre (ACSC) issued a critical alert on September 28 urging organizations to patch.
September 30, 2026
Threat actors utilized a zero-day exploit in Citrix NetScaler to deploy custom web shells WHIPSHOT and SLAPSHOT for malicious activities.
Click on any entity below to view its context and source!
organisation
NetScaler
WHIPSHOT and SLAPSHOT: the tools behind an active Citrix NetScaler campaign
Pierluigi Paganini
September 30, 2026
Mandiant and GTIG detail active exploitation of a Citrix NetScaler zero-day, deploying custom web shells WHIPSHOT and SLAPSHOT for root access.
30 September
The US Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch by Wednesday, 30 September.
Click on any entity below to view its context and source!
source_region
United States
The US Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch by Wednesday, 30 September.
October 4, 2026
Threat actors utilized zero-day exploits to target Citrix NetScaler systems prior to the issuance of patches on October 4, 2026.
Oct 6, 2026
Citrix released a patch for an actively exploited zero-day vulnerability in its NetScaler product.
2026/10/06
Threat actors are actively exploiting two critical NetScaler zero-day vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, which can lead to remote code execution.
Click on any entity below to view its context and source!
organisation
NetScaler
Citrix has released emergency updates for a new NetScaler de....
Citrix has released emergency updates for a new NetScaler denial-of-service vulnerability tracked as CVE-2026-88779 that has been exploited in zero-day attacks, with researchers investigating whether it can also be exploited for remote code execution.
Citrix explained that it has observed targeted attacks on unmitigated NetScaler systems and has yet to determine the impact on the integrity of customer data.
Over the next two days, reports of potential zero-day attacks on NetScaler installations emerged on social media, and cybersecurity professionals debated whether
the rumored attacks
were true — some argued the activity targeted vulnerabilities already patched in August.
Citrix NetScaler (rebranded, then un-rebranded, in the way that only enterprise networking vendors can truly pull off) is a family of application delivery controllers and VPN gateway appliances found in virtually every large enterprise network on the planet.
Executive Summary
Unit 42 is aware of possible zero-day activity against NetScaler devices.
“Exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments has been observed,” Citrix said in a blog post.
Citrix confirms two NetScaler RCE zero-days exploited in attacks.
organisation
NetScaler de....
Citrix
Citrix has released emergency updates for a new NetScaler de....
Citrix has released emergency updates for a new NetScaler denial-of-service vulnerability tracked as CVE-2026-88779 that has been exploited in zero-day attacks, with researchers investigating whether it can also be exploited for remote code execution.
organisation
DTLS
CVE-2026-88772 is a memory overflow that can lead to remote code execution or denial of service, and it affects appliances with DTLS enabled.
9.5 Critical
Yes
CVE-2026-88772
Memory overflow that can lead to remote code execution or denial of service when DTLS is enabled (the default for VPN virtual servers).
…d allows an unauthenticated actor to run commands against NetScaler ADC and NetScaler Gateway systems
CVE-2026-88772 is a memory overflow vulnerability that can lead to a remote code execution (RCE) or denial of service (DoS) on the Datagram Transport Layer Security (DTLS) configuration on NetScaler ADC and NetScaler Gateway systems
Both vulnerabilities have a CVSS v4.0 base score of 9.5.
It affects any deployment with DTLS configuration enabled (which it is by default on VPN vServers)
This vulnerability can be exploited when DTLS is enabled on a NetScaler ADC or NetScaler Gateway.
organisation
CWE
We have had our fair share of reverse engineering the
nsppe
binary over the years, and the CWE in the Citrix advisory looked like more “intended NetScaler functionality”, yet somehow different to normal:
A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands.
organisation
NetScaler ADC
CVE-2026-88771 is a remote code execution (RCE) vulnerability that fails to properly validate input and allows an unauthenticated actor to run commands against NetScaler ADC and NetScaler Gateway systems
CVE-2026-88772 is a memory overflow vulnerability that can lead to a remote code execution (RCE) or denial of service (DoS) on the Datagram Transport Layer Security (DTLS) configuration on Ne…
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 prior to 14.1-73.41
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 prior to 13.1-64.28
Citrix NetScaler ADC FIPS prior to 14.1-73.41 FIPS
Citrix NetScaler ADC FIPS and NDcPP prior to 13.1-37.282
Patched versions:
9.3 Critical
Not reported
CVE-2026-88774
NetScaler ADC and NetScaler Gateway vulnerability.
It affects all NetScaler ADC and NetScaler Gateway deployments with default configuration
CVE-2026-88772: a memory overflow vulnerability leading to RCE or denial of service.
Citrix confirms active exploitation
Citrix has now
published security bulletin CTX697096
, confirming the vulnerabilities and releasing patches for affected NetScaler ADC and NetScaler Gateway appliances.
organisation
NetScaler Gateway
CVE-2026-88771 is a remote code execution (RCE) vulnerability that fails to properly validate input and allows an unauthenticated actor to run commands against NetScaler ADC and NetScaler Gateway systems
CVE-2026-88772 is a memory overflow vulnerability that can lead to a remote code execution (RCE) or denial of service (DoS) on the Datagram Transport Layer Security (DTLS) configuration on Ne…
It affects all NetScaler ADC and NetScaler Gateway deployments with default configuration
CVE-2026-88772: a memory overflow vulnerability leading to RCE or denial of service.
Citrix confirms active exploitation
Citrix has now
published security bulletin CTX697096
, confirming the vulnerabilities and releasing patches for affected NetScaler ADC and NetScaler Gateway appliances.
Like the previous two zero day flaws, the latest vulnerability affects Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway appliances.
That’s particularly relevant for NetScaler Gateway because DTLS is enabled by default for VPN virtual servers unless an administrator has explicitly disabled it.
NetScaler handles load balancing, SSL offloading, authentication, and remote access - and NetScaler Gateway specifically serves as the front door for thousands of organizations' remote access infrastructure.
organisation
CVE-2026
Citrix has confirmed that two critical NetScaler remote code execution vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks and that it has released security updates to fix the flaws.
By Sunday, Citrix seemingly agreed, posting
an update
that patched eight vulnerabilities (CVE-2026-88771 through CVE-2026-88778), including two zero-days that had been exploited in the wild.
Citrix reports
that CVE-2026-88771 and CVE-2026-88772 have been exploited in the wild.
a memory overflow vulnerability leading to unpredictable or erroneous behavior or denial of service (CVSS 8.8)
CVE-2026-88776: a memory overflow vulnerability leading to unpredictable or erroneous behavior or denial of service (CVSS 8.8)
CVE-2026-88777: a memory overflow vulnerability leading to unpredictable or erroneous behavior or denial of service (CVSS 8.8)
CVE-2026-88778: a…
organisation
Citrix NetScaler
Cybersecurity firm watchTowr later publicly warned that it was "rapidly reacting to rumors" that multiple unpatched Citrix NetScaler remote code execution vulnerabilities were being exploited in the wild after verifying the information with "authoratitive sources.
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later releases of 13.1-FIPS and 13.1-NDcPP
Setting The Scene
To fuel today's analysis, we…
Unfortunately, security professionals had less information on the attacks on Citrix NetScaler:
WHIPSHOT and SLAPSHOT: the tools behind an active Citrix NetScaler campaign.
Attackers remained undetected for more than three weeks as they exploited a critical zero-day vulnerability affecting Citrix NetScaler appliances en masse.
organisation
CVSS
The vulnerability is tracked as CVE-2026-88779 and is rated high severity, with a CVSS v4.0 severity score of 8.7.
…d allows an unauthenticated actor to run commands against NetScaler ADC and NetScaler Gateway systems
CVE-2026-88772 is a memory overflow vulnerability that can lead to a remote code execution (RCE) or denial of service (DoS) on the Datagram Transport Layer Security (DTLS) configuration on NetScaler ADC and NetScaler Gateway systems
Both vulnerabilities have a CVSS v4.0 base score of 9.5.
They have CVSS scores ranging from 7 to 9.5.
organisation
DoS
…d allows an unauthenticated actor to run commands against NetScaler ADC and NetScaler Gateway systems
CVE-2026-88772 is a memory overflow vulnerability that can lead to a remote code execution (RCE) or denial of service (DoS) on the Datagram Transport Layer Security (DTLS) configuration on NetScaler ADC and NetScaler Gateway systems
Both vulnerabilities have a CVSS v4.0 base score of 9.5.
organisation
the Datagram Transport Layer Security
…d allows an unauthenticated actor to run commands against NetScaler ADC and NetScaler Gateway systems
CVE-2026-88772 is a memory overflow vulnerability that can lead to a remote code execution (RCE) or denial of service (DoS) on the Datagram Transport Layer Security (DTLS) configuration on NetScaler ADC and NetScaler Gateway systems
Both vulnerabilities have a CVSS v4.0 base score of 9.5.
infrastructure
14.1
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 prior to 14.1-73.41
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 prior to 13.1-64.28
Citrix NetScaler ADC FIPS prior to 14.1-73.41 FIPS
Citrix NetScaler ADC FIPS and NDcPP prior to 13.1-37.282
Patched versions:
NetScaler ADC / NetScaler Gateway versions 14.1-73.41 and later 14.1 releases
NetScaler ADC /
Vulnerable: NetScaler 14.1 build 73.30
Different
: NetScaler 14.1 build 73.37
Citrix says the following versions are affected:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
NetScaler ADC FIPS before 14.1-73.37 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.279
Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds.
infrastructure
14.1-73
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 prior to 14.1-73.41
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 prior to 13.1-64.28
Citrix NetScaler ADC FIPS prior to 14.1-73.41 FIPS
Citrix NetScaler ADC FIPS and NDcPP prior to 13.1-37.282
Patched versions:
NetScaler ADC / NetScaler Gateway versions 14.1-73.41 and later 14.1 releases
NetScaler ADC /
Citrix says the following versions are affected:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
NetScaler ADC FIPS before 14.1-73.37 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.279
Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds.
NetScaler Gateway versions 13.1-64.28 and later 13.1 releases
NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later 14.1-FIPS releases
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later 13.1-FIPS and 13.1-NDcPP releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later releases of 13.1-FIPS and 13.1-NDcPP
Setting The Scene
To fuel today's analysis, we…
infrastructure
13.1
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 prior to 14.1-73.41
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 prior to 13.1-64.28
Citrix NetScaler ADC FIPS prior to 14.1-73.41 FIPS
Citrix NetScaler ADC FIPS and NDcPP prior to 13.1-37.282
Patched versions:
Citrix says the following versions are affected:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
NetScaler ADC FIPS before 14.1-73.37 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.279
Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds.
NetScaler Gateway versions 13.1-64.28 and later 13.1 releases
NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later 14.1-FIPS releases
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later 13.1-FIPS and 13.1-NDcPP releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later releases of 13.1-FIPS and 13.1-NDcPP
Setting The Scene
To fuel today's analysis, we…
infrastructure
13.1-64
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 prior to 14.1-73.41
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 prior to 13.1-64.28
Citrix NetScaler ADC FIPS prior to 14.1-73.41 FIPS
Citrix NetScaler ADC FIPS and NDcPP prior to 13.1-37.282
Patched versions:
Citrix says the following versions are affected:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
NetScaler ADC FIPS before 14.1-73.37 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.279
Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds.
NetScaler Gateway versions 13.1-64.28 and later 13.1 releases
NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later 14.1-FIPS releases
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later 13.1-FIPS and 13.1-NDcPP releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later releases of 13.1-FIPS and 13.1-NDcPP
Setting The Scene
To fuel today's analysis, we…
infrastructure
13.1-37
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 prior to 14.1-73.41
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 prior to 13.1-64.28
Citrix NetScaler ADC FIPS prior to 14.1-73.41 FIPS
Citrix NetScaler ADC FIPS and NDcPP prior to 13.1-37.282
Patched versions:
Citrix says the following versions are affected:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
NetScaler ADC FIPS before 14.1-73.37 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.279
Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds.
NetScaler Gateway versions 13.1-64.28 and later 13.1 releases
NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later 14.1-FIPS releases
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later 13.1-FIPS and 13.1-NDcPP releases
…er ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later releases of 13.1-FIPS and 13.1-NDcPP
Setting The Scene
To fuel today's analysis, we set up a Citrix NetScaler appliance and compared two versions using our normal "what the hell…
organisation
Citrix NetScaler Gateway
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 prior to 14.1-73.41
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 prior to 13.1-64.28
Citrix NetScaler ADC FIPS prior to 14.1-73.41 FIPS
Citrix NetScaler ADC FIPS and NDcPP prior to 13.1-37.282
Patched versions:
…oneous behavior or denial of service (CVSS 8.8)
CVE-2026-88777: a memory overflow vulnerability leading to unpredictable or erroneous behavior or denial of service (CVSS 8.8)
CVE-2026-88778: a TCP Initial Sequence Number (ISN) prediction flaw with a (CVSS 8.8)
“This bulletin only applies to customer-managed Citrix NetScaler ADC and Citrix NetScaler Gateway,” the vendor confirmed.
organisation
Citrix NetScaler ADC
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 prior to 14.1-73.41
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 prior to 13.1-64.28
Citrix NetScaler ADC FIPS prior to 14.1-73.41 FIPS
Citrix NetScaler ADC FIPS and NDcPP prior to 13.1-37.282
Patched versions:
Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway.
organisation
Citrix NetScaler ADC FIPS
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 prior to 14.1-73.41
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 prior to 13.1-64.28
Citrix NetScaler ADC FIPS prior to 14.1-73.41 FIPS
Citrix NetScaler ADC FIPS and NDcPP prior to 13.1-37.282
Patched versions:
infrastructure
13.1 NetScaler ADC FIPS
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 prior to 14.1-73.41
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 prior to 13.1-64.28
Citrix NetScaler ADC FIPS prior to 14.1-73.41 FIPS
Citrix NetScaler ADC FIPS and NDcPP prior to 13.1-37.282
Patched versions:
Citrix says the following versions are affected:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
NetScaler ADC FIPS before 14.1-73.37 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.279
Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds.
NetScaler Gateway versions 13.1-64.28 and later 13.1 releases
NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later 14.1-FIPS releases
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later 13.1-FIPS and 13.1-NDcPP releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later releases of 13.1-FIPS and 13.1-NDcPP
Setting The Scene
To fuel today's analysis, we…
infrastructure
14.1 FIPS
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 prior to 14.1-73.41
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 prior to 13.1-64.28
Citrix NetScaler ADC FIPS prior to 14.1-73.41 FIPS
Citrix NetScaler ADC FIPS and NDcPP prior to 13.1-37.282
Patched versions:
Citrix says the following versions are affected:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
NetScaler ADC FIPS before 14.1-73.37 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.279
Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds.
NetScaler Gateway versions 13.1-64.28 and later 13.1 releases
NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later 14.1-FIPS releases
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later 13.1-FIPS and 13.1-NDcPP releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later releases of 13.1-FIPS and 13.1-NDcPP
Setting The Scene
To fuel today's analysis, we…
infrastructure
73.41 FIPS
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 prior to 14.1-73.41
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 prior to 13.1-64.28
Citrix NetScaler ADC FIPS prior to 14.1-73.41 FIPS
Citrix NetScaler ADC FIPS and NDcPP prior to 13.1-37.282
Patched versions:
organisation
NetScaler ADC /
NetScaler ADC / NetScaler Gateway versions 14.1-73.41 and later 14.1 releases
NetScaler ADC /
infrastructure
73.30
Vulnerable: NetScaler 14.1 build 73.30
Different
: NetScaler 14.1 build 73.37
infrastructure
73.37
Vulnerable: NetScaler 14.1 build 73.30
Different
: NetScaler 14.1 build 73.37
organisation
Secure Private Access Hybrid
Citrix says the following versions are affected:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
NetScaler ADC FIPS before 14.1-73.37 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.279
Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds.
Citrix also warned that Secure Private Access Hybrid deployments using NetScaler instances are also affected by the vulnerability.
financial
73.37 Stolen / Extorted Funds
Citrix says the following versions are affected:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
NetScaler ADC FIPS before 14.1-73.37 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.279
Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds.
Diffing it gave us the following exciting output:
diff --git a/netscaler/ns_monuploadd_err.pl b/netscaler/ns_monuploadd_err.pl
--- a/netscaler/ns_monuploadd_err.pl # 14.1-73.30
+++ b/netscaler/ns_monuploadd_err.pl # 14.1-73.37
@@
-my $WR_PPE_COREFILE_NAME = `grep -E -i "pitboss.*PPE.*missed too many heartbeats|pitboss.*PPE.*unexpectedly died" @WR_FILES |\
-tail -1 | sed -e 's!.*NSPPE!NSPPE!…
organisation
NetScaler Gateway 14.1
Citrix says the following versions are affected:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
NetScaler ADC FIPS before 14.1-73.37 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.279
Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds.
organisation
NetScaler ADC FIPS
Citrix says the following versions are affected:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
NetScaler ADC FIPS before 14.1-73.37 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.279
Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds.
infrastructure
73.37 NetScaler ADC FIPS
Citrix says the following versions are affected:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
NetScaler ADC FIPS before 14.1-73.37 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.279
Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds.
infrastructure
14.1-FIPS
NetScaler Gateway versions 13.1-64.28 and later 13.1 releases
NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later 14.1-FIPS releases
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later 13.1-FIPS and 13.1-NDcPP releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later releases of 13.1-FIPS and 13.1-NDcPP
Setting The Scene
To fuel today's analysis, we…
infrastructure
13.1-FIPS
NetScaler Gateway versions 13.1-64.28 and later 13.1 releases
NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later 14.1-FIPS releases
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later 13.1-FIPS and 13.1-NDcPP releases
…r releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later releases of 13.1-FIPS and 13.1-NDcPP
Setting The Scene
To fuel today's analysis, we set up a Citrix NetScaler appliance and compared two versions using…
infrastructure
13.1-NDcPP
NetScaler Gateway versions 13.1-64.28 and later 13.1 releases
NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later 14.1-FIPS releases
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later 13.1-FIPS and 13.1-NDcPP releases
…rix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later releases of 13.1-FIPS and 13.1-NDcPP
Setting The Scene
To fuel today's analysis, we set up a Citrix NetScaler appliance and compared two versions using our normal "wh…
organisation
RCE
It affects all NetScaler ADC and NetScaler Gateway deployments with default configuration
CVE-2026-88772: a memory overflow vulnerability leading to RCE or denial of service.
We're sure there are many teams at this point having extremely tense conversations with their TAM, asking why an actively exploited RCE in a default configuration was communicated to the world through many channels, none of which included Citrix itself.
organisation
Citrix NetScaler Application
Like the previous two zero day flaws, the latest vulnerability affects Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway appliances.
organisation
SSL
NetScaler handles load balancing, SSL offloading, authentication, and remote access - and NetScaler Gateway specifically serves as the front door for thousands of organizations' remote access infrastructure.
The former is often used to provide cloud applications to employees, while the latter is commonly used as an SSL VPN to provide single sign-on to remote workers.
You may see an SSL handshake failure using DTLSv1.0 with the message “Handshake failure-Internal Error.”
organisation
DTLSv1.0
You may see an SSL handshake failure using DTLSv1.0 with the message “Handshake failure-Internal Error.”
organisation
Adaptive Authentication
Citrix-managed cloud services and Citrix-managed Adaptive Authentication have been automatically updated with the fixed version.
“Cloud Software Group upgrades the Citrix-managed cloud services and Citrix-managed Adaptive Authentication with the necessary software updates.”
Cloud Software Group is upgrading Citrix-managed cloud services and Citrix-managed Adaptive Authentication.
organisation
HIPAA Journal
Get The FREE
HIPAA Compliance Checklist
Immediate Delivery of Checklist Link To Your Email Address
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal
Privacy Policy
Vulnerable versions:
organisation
IP
"
Kiteworks exposed IP addresses affect countries worldwide but are concentrated in the United States and Europe.
organisation
the European Union's
It also said Citrix submitted a notification under the European Union's Cyber Resilience Act after discovering the attacks.
organisation
NetScaler PreAuth Command
Oh Look, The Foot Gun Went Off Again (Citrix NetScaler PreAuth Command Injection CVE-2026-88771).
organisation
NetScaler PreAuth Command Injection
/ \/\_/ |__|
\/ \/ \/
watchTowr-vs-Citrix-Netscaler-CVE-2026-88771.py
(*) Citrix NetScaler PreAuth Command Injection to RCE Detection Artifact Generator
- Sina Kheirkhah (@SinSinology) of watchTowr (@watchTowrcyber)
CVEs: [CVE-2026-88771]
[+] connected to
[*] payload built: pitboss PPE unexpectedly died NSPPE;id>/var…
organisation
NetScaler Zero Days CVE-2026-88771
Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild.
organisation
CVE
Vulnerabilities Discussed
CVE-2026-88771, CVE-2026-88772
Interim Guidance
Unit 42 recommends that customers update their Citrix software to the latest versions as soon as possible, as well as following the recommendations:
Confirm exposure
following the “Steps to determine if an appliance meets the CVE preconditions” section of the
Citrix Security Advisory
for these vulnerabil…
organisation
NetScaler Console
Citrix has made indicators of compromise available through NetScaler Console and published additional guidance in their recent publication,
Security Bulletin for CVE-2026-88771 through CVE-2026-88778
, to support organizations in assessing potential compromise.
…these vulnerabilities
Isolate the vulnerable systems
from the network
Preserve evidence
by capturing the following:
A
NetScaler
VPX instance snapshot
Logs on remote syslog servers and NetScaler Console
A technical support bundle
A packet engine core dump
Hunt
for the following:
Signs of suspicious administrative sessions
Unexpected outbound connections
Unexpl…
organisation
CVE-2026-88778
…ictable or erroneous behavior or denial of service (CVSS 8.8)
CVE-2026-88777: a memory overflow vulnerability leading to unpredictable or erroneous behavior or denial of service (CVSS 8.8)
CVE-2026-88778: a TCP Initial Sequence Number (ISN) prediction flaw with a (CVSS 8.8)
“This bulletin only applies to customer-managed Citrix NetScaler ADC and Citrix NetScaler Gateway,” the ven…
organisation
Kiteworks &
Kiteworks & Citrix Incidents Show Challenges of Zero-Day Response.
organisation
RemoteThreat Bets Security Teams Need
Related:
RemoteThreat Bets Security Teams Need to Test What Happens After Defenses Fail
One Weekend, Two Disclosure Strategies
The same weekend, data protection provider Kiteworks took a different road.
organisation
Defenses Fail
Related:
RemoteThreat Bets Security Teams Need to Test What Happens After Defenses Fail
One Weekend, Two Disclosure Strategies
The same weekend, data protection provider Kiteworks took a different road.
organisation
Kiteworks
On Monday, Kiteworks published an advisory identifying the vulnerability with an update to patch it.
organisation
Black Hills Information Security
The decision to call for customers to shut down their systems was "wild," according to John Strand, owner of Black Hills Information Security, a cybersecurity-training and penetration-testing firm.
organisation
AI Accountability Era
That is the standard we intend to keep."
Related:
Is Your Organization Ready for 2027's AI Accountability Era?
organisation
GreyNoise
No Easy Decisions for Vendors — or Customers
If another weekend brings the same decision, there is still no clear answer as to the right strategy, says Andrew Thompson, senior vice president of adversary operations at GreyNoise.
organisation
Google
reads
Google’s report
.
organisation
PHP
In some intrusions, the attacker edited the appliance’s Apache config to treat .deb files as executable PHP scripts, then dropped a web shell wearing that fake extension.
organisation
Mandiant
The two custom tools doing the real work are called WHIPSHOT and SLAPSHOT, and Mandiant hadn’t seen either before.
organisation
TCP
It creates a simple Python proxy that opens a local port and forwards TCP traffic into the internal network.
organisation
SSH
This includes admin accounts, SSH keys, TLS certificates, LDAP and RADIUS credentials, and other secrets used to access internal systems.
organisation
TLS
This includes admin accounts, SSH keys, TLS certificates, LDAP and RADIUS credentials, and other secrets used to access internal systems.
organisation
SecurityAffairs
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, Citrix NetScaler)
victims
443 ClientVersion
“Successful exploitation attempts generated two log artifacts:
0-PPE-0 : default SSLLOG SSL_HANDSHAKE_FAILURE 0 : SPCBId - ClientIP - ClientPort - VserverServiceIP - VserverServicePort 443 - ClientVersion DTLSv1.0 - CipherSuite "TLS1-AES-256-CBC-SHA" - Session New - Reason "Handshake failure-Internal Error""
Once inside, the attacker’s first move is installing a web shell, and the installatio…
organisation
Mandiant Consulting
“We are aware of dozens of impacted organizations,” Charles Carmakal, chief technology officer at Mandiant Consulting, wrote in a
LinkedIn post
.
organisation
EDR
“Because most edge devices do not support endpoint detection and response (EDR) monitoring, targeting them, particularly through exploiting zero-day vulnerabilities, provides threat actors with an infection vector that is difficult to detect and prevent, and the opportunity to scale a campaign as long as the exploit remains undiscovered,” the researchers added.
organisation
@@
-my $
…xciting output:
diff --git a/netscaler/ns_monuploadd_err.pl b/netscaler/ns_monuploadd_err.pl
--- a/netscaler/ns_monuploadd_err.pl # 14.1-73.30
+++ b/netscaler/ns_monuploadd_err.pl # 14.1-73.37
@@
-my $WR_PPE_COREFILE_NAME = `grep -E -i "pitboss.*PPE.*missed too many heartbeats|pitboss.*PPE.*unexpectedly died" @WR_FILES |\
-tail -1 | sed -e 's!.*NSPPE!NSPPE!g' -e 's!(!!g' -e 's!)!!g' | awk…
infrastructure
8.8
8.8 High
Not reported
The Citrix
advisory
recommends updating to the following fixed versions:
organisation
Burp
Sadly, a simple pre-auth request like this can trigger the vulnerability (you need Hackvertor installed to encode the login field (if you’re using Burp or similar)):
POST /nf/auth/doAuthentication.do HTTP/1.1
Host: netscaler-aaa-server
Content-Type: application/x-www-form-urlencoded
login=<@urlencode_all>pitboss PPE unexpectedly died NSPPE;:`id>/var/tmp/watchTowr`;# X</@urlencode_all>&passwd=x&…
organisation
Content-Type
…this can trigger the vulnerability (you need Hackvertor installed to encode the login field (if you’re using Burp or similar)):
POST /nf/auth/doAuthentication.do HTTP/1.1
Host: netscaler-aaa-server
Content-Type: application/x-www-form-urlencoded
login=<@urlencode_all>pitboss PPE unexpectedly died NSPPE;:`id>/var/tmp/watchTowr`;# X</@urlencode_all>&passwd=x&savecredentials=false&nsg-x1-logon-bu…
organisation
NSPPE;:`id>/var
…re using Burp or similar)):
POST /nf/auth/doAuthentication.do HTTP/1.1
Host: netscaler-aaa-server
Content-Type: application/x-www-form-urlencoded
login=<@urlencode_all>pitboss PPE unexpectedly died NSPPE;:`id>/var/tmp/watchTowr`;# X</@urlencode_all>&passwd=x&savecredentials=false&nsg-x1-logon-button=Log+On
Response:
HTTP/1.1 200 OK
Content-Security-Policy: default-src 'self'; script-src 'self'…
organisation
Content-Security-Policy
…lencoded
login=<@urlencode_all>pitboss PPE unexpectedly died NSPPE;:`id>/var/tmp/watchTowr`;# X</@urlencode_all>&passwd=x&savecredentials=false&nsg-x1-logon-button=Log+On
Response:
HTTP/1.1 200 OK
Content-Security-Policy: default-src 'self'; script-src 'self'; connect-src 'self'; img-src < 'self' data:; style-src 'self' 'unsafe-inline'; font-src 'self' data:; frame-src 'self'; child-src 'self'…
organisation
X-XSS-Protection
…a application://*; form-action 'self'; object-src 'none'; base-uri 'self'; report-uri /nscsp_violation/report_uri
Set-Cookie: NSC_DLGE=yyyyyyy;Secure;HttpOnly;Path=/
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Content-Length: 2253
Cache-control: no-cache, no-store, must-revalidate
Pragma: no-cache
Content-Type: application/vnd.citrix.authenticateresponse-1+xml; charset=utf-8…
organisation
Content-Length
…'self'; object-src 'none'; base-uri 'self'; report-uri /nscsp_violation/report_uri
Set-Cookie: NSC_DLGE=yyyyyyy;Secure;HttpOnly;Path=/
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Content-Length: 2253
Cache-control: no-cache, no-store, must-revalidate
Pragma: no-cache
Content-Type: application/vnd.citrix.authenticateresponse-1+xml; charset=utf-8
X-Citrix-Application: Receiver…
organisation
AuthenticateResponse
…y;Path=/
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Content-Length: 2253
Cache-control: no-cache, no-store, must-revalidate
Pragma: no-cache
Content-Type: application/vnd.citrix.authenticateresponse-1+xml; charset=utf-8
X-Citrix-Application: Receiver for Web
<AuthenticateResponse xmlns="< PPE unexpectedly died NSPPE;:`id>/var/tmp/helloxxxx`;# X</InitialValue></Text></Input>…
organisation
NSPPE;id>/var
…\/ \/
watchTowr-vs-Citrix-Netscaler-CVE-2026-88771.py
(*) Citrix NetScaler PreAuth Command Injection to RCE Detection Artifact Generator
- Sina Kheirkhah (@SinSinology) of watchTowr (@watchTowrcyber)
CVEs: [CVE-2026-88771]
[+] connected to
[*] payload built: pitboss PPE unexpectedly died NSPPE;id>/var/tmp/watchTowr;# X
[+] poisoning the logs...
organisation
Preemptive Exposure Management
This research is a glimpse into the capability powering the watchTowr Platform, a
Preemptive Exposure Management
solution.
organisation
NetScalers
We made the call that our language needed to be clear: given active exploitation in the wild and the critical nature of many of the organizations that run NetScalers, appliances should be taken offline, and that this was "going to be bad.
organisation
TAM
We're sure there are many teams at this point having extremely tense conversations with their TAM, asking why an actively exploited RCE in a default configuration was communicated to the world through many channels, none of which included Citrix itself.
organisation
NSPPE
Being the well-traveled Citrix reverse engineers that we are, we initially thought maybe NSPPE would be the culprit here: our good old friend, where almost all of the vulnerabilities from the past decade in Citrix NetScaler have existed.
organisation
-1
| tail -1`;
organisation
PPE
The command-chain then does the following:
grep
searches the log files for a Pitboss PPE failure message.
organisation
Perl
At this point, the semicolons are only characters inside a Perl string.
organisation
APT
This is how APT groups have presumably been ravaging your networks in secret while Citrix kept its mouth shut.
organisation
Packet Engine
It reads each log line and applies this regular expression:
qr/pitboss.*(NSPPE-\d{2})\s*\((\d+)\).*(missed too many heartbeats|unexpectedly died)/
The two captured values are deliberately narrow:
(NSPPE-\d{2})
accepts a Packet Engine name such as
NSPPE-00
.
organisation
SHELL
BL1NG BL1NG GIVE ME A SHELL.
organisation
|_\
| |_\__ ____\____
organisation
External Attack Surface Management
The
watchTowr Platform
combines
External Attack Surface Management
and
Continuous Automated Red Teaming
to test your defenses against the vulnerabilities and techniques that matter: the ones real attackers are actually exploiting.
organisation
VPX
…econditions” section of the
Citrix Security Advisory
for these vulnerabilities
Isolate the vulnerable systems
from the network
Preserve evidence
by capturing the following:
A
NetScaler
VPX instance snapshot
Logs on remote syslog servers and NetScaler Console
A technical support bundle
A packet engine core dump
Hunt
for the following:
Signs of suspicious administr…
organisation
Unexpected
…napshot
Logs on remote syslog servers and NetScaler Console
A technical support bundle
A packet engine core dump
Hunt
for the following:
Signs of suspicious administrative sessions
Unexpected outbound connections
Unexplained gaps in logging
Note: These are not tactics, techniques and procedures (TTPs) we have observed specifically related to these vulnerabilities.
threat_actor
Salt Typhoon
It’s not clear who is behind the exploitation attempts but in 2025, a cyber intrusion linked to
China-based group Salt Typhoon
targeted a Citrix zero day.
organisation
the Dutch National Cyber Security Center
Reports online also suggested the Dutch National Cyber Security Center (NCSC-NL) had issued alerts to local organizations in the country.
NCSC warned organizations before disclosure
Before Citrix publicly disclosed the vulnerabilities, the Dutch National Cyber Security Center (NCSC-NL) reportedly sent a pre-notification to organizations in the Netherlands warning about two critical NetScaler zero-days.
organisation
NCSC-NL
Reports online also suggested the Dutch National Cyber Security Center (NCSC-NL) had issued alerts to local organizations in the country.
NCSC warned organizations before disclosure
Before Citrix publicly disclosed the vulnerabilities, the Dutch National Cyber Security Center (NCSC-NL) reportedly sent a pre-notification to organizations in the Netherlands warning about two critical NetScaler zero-days.
organisation
the National CSIRT
"As part of our role as the National CSIRT and sectoral CSIRT for designated organizations, the NCSC-NL monitors relevant developments and cyber threats affecting the Netherlands 24/7," the NCSC-NL told BleepingComputer.
organisation
NetScaler RCE
"
"We are currently rapidly reacting to rumors that multiple unpatched Citrix NetScaler RCE vulnerabilities are circulating in the wild.
organisation
NCSC
The NCSC said exploitation had been identified at multiple Citrix customers worldwide, although it did not know whether the attacks were widespread.
organisation
BleepingComputer
BleepingComputer contacted the Dutch NCSC to confirm whether the advisory circulating online was legitimate.
organisation
NFL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
CHANEL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Tactical Metrics
Metrics
infrastructure
14.1
Software Version
Click for context!
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 prior to 14.1-73.41
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 prior to 13.1-64.28
Citrix NetScaler ADC FIPS prior to 14.1-73.41 FIPS
Citrix NetScaler ADC FIPS and NDcPP prior to 13.1-37.282
Patched versions:
NetScaler ADC / NetScaler Gateway versions 14.1-73.41 and later 14.1 releases
NetScaler ADC /
Vulnerable: NetScaler 14.1 build 73.30
Different
: NetScaler 14.1 build 73.37
Citrix says the following versions are affected:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
NetScaler ADC FIPS before 14.1-73.37 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.279
Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds.
Metrics
infrastructure
14.1-73
Software Version
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 prior to 14.1-73.41
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 prior to 13.1-64.28
Citrix NetScaler ADC FIPS prior to 14.1-73.41 FIPS
Citrix NetScaler ADC FIPS and NDcPP prior to 13.1-37.282
Patched versions:
NetScaler ADC / NetScaler Gateway versions 14.1-73.41 and later 14.1 releases
NetScaler ADC /
NetScaler Gateway versions 13.1-64.28 and later 13.1 releases
NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later 14.1-FIPS releases
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later 13.1-FIPS and 13.1-NDcPP releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later releases of 13.1-FIPS and 13.1-NDcPP
Setting The Scene
To fuel today's analysis, we…
Citrix says the following versions are affected:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
NetScaler ADC FIPS before 14.1-73.37 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.279
Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds.
Metrics
infrastructure
13.1
Software Version
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 prior to 14.1-73.41
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 prior to 13.1-64.28
Citrix NetScaler ADC FIPS prior to 14.1-73.41 FIPS
Citrix NetScaler ADC FIPS and NDcPP prior to 13.1-37.282
Patched versions:
NetScaler Gateway versions 13.1-64.28 and later 13.1 releases
NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later 14.1-FIPS releases
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later 13.1-FIPS and 13.1-NDcPP releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later releases of 13.1-FIPS and 13.1-NDcPP
Setting The Scene
To fuel today's analysis, we…
Citrix says the following versions are affected:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
NetScaler ADC FIPS before 14.1-73.37 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.279
Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds.
Metrics
infrastructure
13.1-64
Software Version
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 prior to 14.1-73.41
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 prior to 13.1-64.28
Citrix NetScaler ADC FIPS prior to 14.1-73.41 FIPS
Citrix NetScaler ADC FIPS and NDcPP prior to 13.1-37.282
Patched versions:
NetScaler Gateway versions 13.1-64.28 and later 13.1 releases
NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later 14.1-FIPS releases
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later 13.1-FIPS and 13.1-NDcPP releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later releases of 13.1-FIPS and 13.1-NDcPP
Setting The Scene
To fuel today's analysis, we…
Citrix says the following versions are affected:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
NetScaler ADC FIPS before 14.1-73.37 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.279
Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds.
Metrics
infrastructure
13.1-37
Software Version
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 prior to 14.1-73.41
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 prior to 13.1-64.28
Citrix NetScaler ADC FIPS prior to 14.1-73.41 FIPS
Citrix NetScaler ADC FIPS and NDcPP prior to 13.1-37.282
Patched versions:
NetScaler Gateway versions 13.1-64.28 and later 13.1 releases
NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later 14.1-FIPS releases
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later 13.1-FIPS and 13.1-NDcPP releases
…er ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later releases of 13.1-FIPS and 13.1-NDcPP
Setting The Scene
To fuel today's analysis, we set up a Citrix NetScaler appliance and compared two versions using our normal "what the hell…
Citrix says the following versions are affected:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
NetScaler ADC FIPS before 14.1-73.37 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.279
Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds.
Metrics
infrastructure
13
Netscaler Adc Fips
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 prior to 14.1-73.41
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 prior to 13.1-64.28
Citrix NetScaler ADC FIPS prior to 14.1-73.41 FIPS
Citrix NetScaler ADC FIPS and NDcPP prior to 13.1-37.282
Patched versions:
NetScaler Gateway versions 13.1-64.28 and later 13.1 releases
NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later 14.1-FIPS releases
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later 13.1-FIPS and 13.1-NDcPP releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later releases of 13.1-FIPS and 13.1-NDcPP
Setting The Scene
To fuel today's analysis, we…
Citrix says the following versions are affected:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
NetScaler ADC FIPS before 14.1-73.37 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.279
Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds.
Metrics
infrastructure
14
Fips
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 prior to 14.1-73.41
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 prior to 13.1-64.28
Citrix NetScaler ADC FIPS prior to 14.1-73.41 FIPS
Citrix NetScaler ADC FIPS and NDcPP prior to 13.1-37.282
Patched versions:
NetScaler Gateway versions 13.1-64.28 and later 13.1 releases
NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later 14.1-FIPS releases
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later 13.1-FIPS and 13.1-NDcPP releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later releases of 13.1-FIPS and 13.1-NDcPP
Setting The Scene
To fuel today's analysis, we…
Citrix says the following versions are affected:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
NetScaler ADC FIPS before 14.1-73.37 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.279
Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds.
Metrics
infrastructure
73
Fips
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 prior to 14.1-73.41
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 prior to 13.1-64.28
Citrix NetScaler ADC FIPS prior to 14.1-73.41 FIPS
Citrix NetScaler ADC FIPS and NDcPP prior to 13.1-37.282
Patched versions:
Metrics
infrastructure
14.1-FIPS
Software Version
NetScaler Gateway versions 13.1-64.28 and later 13.1 releases
NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later 14.1-FIPS releases
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later 13.1-FIPS and 13.1-NDcPP releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later releases of 13.1-FIPS and 13.1-NDcPP
Setting The Scene
To fuel today's analysis, we…
Metrics
infrastructure
13.1-FIPS
Software Version
NetScaler Gateway versions 13.1-64.28 and later 13.1 releases
NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later 14.1-FIPS releases
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later 13.1-FIPS and 13.1-NDcPP releases
…r releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later releases of 13.1-FIPS and 13.1-NDcPP
Setting The Scene
To fuel today's analysis, we set up a Citrix NetScaler appliance and compared two versions using…
Metrics
infrastructure
13.1-NDcPP
Software Version
NetScaler Gateway versions 13.1-64.28 and later 13.1 releases
NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later 14.1-FIPS releases
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later 13.1-FIPS and 13.1-NDcPP releases
…rix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later releases of 13.1-FIPS and 13.1-NDcPP
Setting The Scene
To fuel today's analysis, we set up a Citrix NetScaler appliance and compared two versions using our normal "wh…
Metrics
victims
443
Clientversion
“Successful exploitation attempts generated two log artifacts:
0-PPE-0 : default SSLLOG SSL_HANDSHAKE_FAILURE 0 : SPCBId - ClientIP - ClientPort - VserverServiceIP - VserverServicePort 443 - ClientVersion DTLSv1.0 - CipherSuite "TLS1-AES-256-CBC-SHA" - Session New - Reason "Handshake failure-Internal Error""
Once inside, the attacker’s first move is installing a web shell, and the installatio…
Metrics
financial
73
Stolen / Extorted Funds
Diffing it gave us the following exciting output:
diff --git a/netscaler/ns_monuploadd_err.pl b/netscaler/ns_monuploadd_err.pl
--- a/netscaler/ns_monuploadd_err.pl # 14.1-73.30
+++ b/netscaler/ns_monuploadd_err.pl # 14.1-73.37
@@
-my $WR_PPE_COREFILE_NAME = `grep -E -i "pitboss.*PPE.*missed too many heartbeats|pitboss.*PPE.*unexpectedly died" @WR_FILES |\
-tail -1 | sed -e 's!.*NSPPE!NSPPE!…
Citrix says the following versions are affected:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
NetScaler ADC FIPS before 14.1-73.37 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.279
Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds.
Metrics
infrastructure
8.8
Software Version
8.8 High
Not reported
The Citrix
advisory
recommends updating to the following fixed versions:
Metrics
infrastructure
73.30
Software Version
Vulnerable: NetScaler 14.1 build 73.30
Different
: NetScaler 14.1 build 73.37
Metrics
infrastructure
73.37
Software Version
Vulnerable: NetScaler 14.1 build 73.30
Different
: NetScaler 14.1 build 73.37
Metrics
infrastructure
82.080.467
Software Version
+82.080.467.8774
Additional References
Updated Sept. 27, 2026 at 4:15 p.m. PT to add information about
Cortex Xpanse
telemetry.
Metrics
infrastructure
73
Netscaler Adc Fips
Citrix says the following versions are affected:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
NetScaler ADC FIPS before 14.1-73.37 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.279
Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds.
Intelligence Sources
Palo Alto
2026-09-28
BleepingComputer
2026-09-27
Citrix confirms two NetScaler RCE zero-days exploited in attacks
BleepingComputer
CISA
2026-09-27
CyberScoop
2026-09-29
Security Affairs
2026-09-30
Infosecurity-Magazine
2026-09-28
Citrix Patches Critical Zero Days Under Active Exploitation
Infosecurity-Magazine
Zero Day Fans
2026-09-28
Mastodon Catalin Cimpanu
2026-09-29
RE: https:// cyberplace.social/@GossiTheDog /11735248150198...
Mastodon Catalin Cimpanu
Dark Reading
2026-10-02
Mastodon BleepingComputer
2026-10-04
Citrix has released emergency updates for a new NetScaler de...
Mastodon BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T06:41
Comprehensive Tactical Telemetry
Highly Correlated Entities
86x
organisation
Identified Entity
CVSS
entity
23x
timeline
Temporal Reference
Oct 6, 2026
date
13x
vulnerability
Exploited CVE
CVE-2026-8877
cve
13x
attribution
Attributing Entity
GreyNoise Intelligence
authority
12x
infrastructure
Software Version
14.1
version
7x
target region
Target Country
United States
country
6x
industry
Targeted Sector
Media
sector
4x
vulnerability
CVSS Score
10
score
4x
tactic
MITRE ATT&CK Technique
T1059.006 - Python
technique
3x
tactic
Cyber Operation Type
Remote Code Execution
tactic
3x
target region
Target Region
EUROPE
region
2x
infrastructure
Netscaler Adc Fips
13
netscaler adc fips
2x
infrastructure
Fips
14
fips
2x
general metric
%
1
%
2x
general metric
Minutes
15
minutes
2x
general metric
High
7
high
2x
general metric
Cve-2026
88,771
cve-2026
2x
general metric
+1
866
+1
2x
source region
Origin Country
United States
country
Contextual Telemetry
Context Block
25 METRICS
general metric
Netscaler Gateway
14
netscaler gateway
general metric
Citrix
13
citrix
general metric
Https://
4,595,071,362,326,680
https://
general metric
Days
88,772
days
general metric
Default Ssllog Ssl_Handshake_Failure
0
default ssllog ssl_handshake_failure
victims
Clientversion
443
clientversion
general metric
Looking Error
404
looking error
general metric
Ns_Monuploadd_Err.Pl #
73
ns_monuploadd_err.pl #
financial
Stolen / Extorted Funds
73
@@
general metric
Hours
24
hours
general metric
Memory Overflow
10
memory overflow
general metric
Critical
9
critical
general metric
Netscaler
73
netscaler
general metric
Ok Self
200
ok self
general metric
Message
675
message
general metric
Local1.Info
1,350
local1.info
general metric
Aaatm Message
678
aaatm message
general metric
Old Code
12,345
old code
general metric
Field
2
field
general metric
R-- Root Wheel
41
r-- root wheel
general metric
Sep
28
sep
general metric
Incident
42
incident
general metric
+65.6983.8730
50
+65.6983.8730
general metric
Exposed Instances
50,277
exposed instances
threat actor
APT Group
Salt Typhoon
actor
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.