INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Citrix Patches Third Actively Exploited NetScaler Zero Day Vulnerability

| 2026-10-06 10:26 CRITICAL HIGH EXPLOITED VULNERABILITY VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
On October 6, 2026, a new zero-day vulnerability was discovered in Citrix NetScaler ADC and Gateway appliances, with the latest vulnerability affecting systems prior to patch versions 14.1-73.41 and 13.1-64.28. The identified entity behind this attack is unknown at this time. This vulnerability allows an attacker to crash the system, with repeated attacks resulting in denial of service, unlike two previously patched zero-days that can lead to remote code execution. The current status indicates that Citrix has released patches for this vulnerability and urges all customers with vulnerable appliances to upgrade to the fixed version as soon as possible.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-88771, CVE-2026-88773 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
cy•••••.social
ww•••••.com
sh•••••.org
lo•••••.info
wa•••••.py
WR•••••.gz
213.209.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Salt TyphoonSalt Typhoon CVE-2026-88771CVE-2026-88771 CVE-2026-88773CVE-2026-88773 CVE-2026-88776CVE-2026-88776 CVE-2026-88772CVE-2026-88772 CVE-2026-88774CVE-2026-88774 CVE-2026-88777CVE-2026-88777 CVE-2026-88779CVE-2026-88779 CVE-2026-88778CVE-2026-88778 CVE-2026-19489CVE-2026-19489 CVE-2026-19490CVE-2026-19490 CVE-2026-88782CVE-2026-88782 CVE-2026-88775CVE-2026-88775 CVE-2026-8877CVE-2026-8877
Target & Sectors
EUROPE EUROPE BENELUX BENELUX MIDDLE_EAST MIDDLE_EAST NORTH_AMERICA NORTH_AMERICA telecommunicationstelecommunications educationeducation governmentgovernment legallegal financefinance
Incident Timeline
‎2025/09/29
Google Threat Intelligence Group reported that 48% of enterprise-related zero-days in 2025 were attributed to vulnerabilities in Citrix NetScaler devices.
attribution Google Threat Intelligence Group
tactic T1588.006 - Vulnerabilities
general_metric 48 %
‎Sept. 3
Threat actors utilized the zero-day exploit CVE-2026-88772 on September 3.
vulnerability CVE-2026-88772
organisation Mandiant
organisation CyberScoop
‎late September 2026
Mandiant and Google Threat Intelligence Group detected active exploitation of a zero-day vulnerability in Citrix NetScaler ADC and Gateway appliances.
attribution Mandiant
attribution Google Threat Intelligence Group
attribution Citrix NetScaler ADC
‎2026/09/22
Threat actors utilized zero-day exploits against Citrix NetScaler systems, but the security vendor and researchers did not confirm these attacks until late last week on September 22, 2026.
‎Sept. 24
Threat actors utilized zero-day exploits to conduct remote code execution attacks against Citrix NetScaler installations via a single US-based IP address.
tactic Remote Code Execution
target_region United States
attribution GreyNoise Intelligence
attribution IP
attribution Citrix NetScaler
‎at least Sept. 24
Attackers have exploited a second Citrix NetScaler zero-day, CVE-2026-88771, since at least September 24.
organisation NetScaler
vulnerability CVE-2026-88771
organisation GreyNoise
‎Sept. 25
Threat actors utilized zero-day exploits to trigger a malicious campaign targeting Citrix NetScaler systems, prompting the company's recommendation for customers to take their systems offline.
‎Sept. 26
Benjamin Harris urged NetScaler users to take their systems offline on September 26.
‎Sept. 27, 2026
Palo Alto Networks Cortex Xpanse has identified over 50,277 exposed instances potentially vulnerable to the specified CVEs based on its telemetry.
infrastructure 82.080.467
organisation Additional References Updated
organisation Cortex Xpanse
organisation Palo Alto Networks Cortex Xpanse
general_metric 50,277 exposed instances
organisation Palo Alto Networks Cortex Xpanse
‎September 27
Threat actors utilized newly disclosed zero-day exploits for Citrix NetScaler ADC and Gateway to conduct malicious activities.
organisation Citrix NetScaler ADC
organisation Citrix ADC
‎2026/09/28
Threat actors exploited zero-day vulnerabilities in Citrix NetScaler releases 13.1-64.23 and later, as well as 14.1-FIPS and certain other versions, to conduct malicious activities on ‎2026/09/28.
‎September 28
The Australian Signals Directorate's Australian Cyber Security Centre issued a critical alert on September 28 urging organizations to patch Citrix NetScaler systems due to a zero-day exploit campaign.
organisation The Australian Signals Directorate’s
‎September 30, 2026
Threat actors utilized a zero-day exploit in Citrix NetScaler to deploy custom web shells WHIPSHOT and SLAPSHOT for malicious activities.
organisation NetScaler
‎30 September
The US Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch by Wednesday, 30 September.
source_region United States
‎October 4, 2026
Threat actors utilized zero-day exploits to target Citrix NetScaler systems prior to the issuance of patches on October 4, 2026.
‎Oct 6, 2026
Citrix released a patch for an actively exploited zero-day vulnerability in its NetScaler product.
‎2026/10/06
Threat actors are actively exploiting two critical NetScaler zero-day vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, which can lead to remote code execution.
organisation NetScaler
organisation NetScaler de.... Citrix
organisation DTLS
organisation CWE
organisation NetScaler ADC
organisation NetScaler Gateway
organisation CVE-2026
organisation Citrix NetScaler
organisation CVSS
organisation DoS
organisation the Datagram Transport Layer Security
infrastructure 14.1
infrastructure 14.1-73
infrastructure 13.1
infrastructure 13.1-64
infrastructure 13.1-37
organisation Citrix NetScaler Gateway
organisation Citrix NetScaler ADC
organisation Citrix NetScaler ADC FIPS
infrastructure 13.1 NetScaler ADC FIPS
infrastructure 14.1 FIPS
infrastructure 73.41 FIPS
organisation NetScaler ADC /
infrastructure 73.30
infrastructure 73.37
organisation Secure Private Access Hybrid
financial 73.37 Stolen / Extorted Funds
organisation NetScaler Gateway 14.1
organisation NetScaler ADC FIPS
infrastructure 73.37 NetScaler ADC FIPS
infrastructure 14.1-FIPS
infrastructure 13.1-FIPS
infrastructure 13.1-NDcPP
organisation RCE
organisation Citrix NetScaler Application
organisation SSL
organisation DTLSv1.0
organisation Adaptive Authentication
organisation HIPAA Journal
organisation IP
organisation the European Union's
organisation NetScaler PreAuth Command
organisation NetScaler PreAuth Command Injection
organisation NetScaler Zero Days CVE-2026-88771
organisation CVE
organisation NetScaler Console
organisation CVE-2026-88778
organisation Kiteworks &
organisation RemoteThreat Bets Security Teams Need
organisation Defenses Fail
organisation Kiteworks
organisation Black Hills Information Security
organisation AI Accountability Era
organisation GreyNoise
organisation Google
organisation PHP
organisation Mandiant
organisation TCP
organisation SSH
organisation TLS
organisation SecurityAffairs
victims 443 ClientVersion
organisation Mandiant Consulting
organisation EDR
organisation @@ -my $
infrastructure 8.8
organisation Burp
organisation Content-Type
organisation NSPPE;:`id>/var
organisation Content-Security-Policy
organisation X-XSS-Protection
organisation Content-Length
organisation AuthenticateResponse
organisation NSPPE;id>/var
organisation Preemptive Exposure Management
organisation NetScalers
organisation TAM
organisation NSPPE
organisation -1
organisation PPE
organisation Perl
organisation APT
organisation Packet Engine
organisation SHELL
organisation |_\
organisation External Attack Surface Management
organisation VPX
organisation Unexpected
threat_actor Salt Typhoon
organisation the Dutch National Cyber Security Center
organisation NCSC-NL
organisation the National CSIRT
organisation NetScaler RCE
organisation NCSC
organisation BleepingComputer
organisation NFL
organisation CHANEL
Tactical Metrics
Metrics
infrastructure
‎14.1
Software Version
Metrics
infrastructure
‎14.1-73
Software Version
Metrics
infrastructure
‎13.1
Software Version
Metrics
infrastructure
‎13.1-64
Software Version
Metrics
infrastructure
‎13.1-37
Software Version
Metrics
infrastructure
13
Netscaler Adc Fips
Metrics
infrastructure
14
Fips
Metrics
infrastructure
73
Fips
Metrics
infrastructure
‎14.1-FIPS
Software Version
Metrics
infrastructure
‎13.1-FIPS
Software Version
Metrics
infrastructure
‎13.1-NDcPP
Software Version
Metrics
victims
443
Clientversion
Metrics
financial
73
Stolen / Extorted Funds
Metrics
infrastructure
‎8.8
Software Version
Metrics
infrastructure
‎73.30
Software Version
Metrics
infrastructure
‎73.37
Software Version
Metrics
infrastructure
‎82.080.467
Software Version
Metrics
infrastructure
73
Netscaler Adc Fips