Full Report
Unit 42 is aware of possible 0-day activity against NetScaler devices. Citrix reports CVE-2026-88771, CVE-2026-88772 have been exploited in the wild. The post Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild appeared first on Unit 42.
Analysis Summary
# Vulnerability: Critical NetScaler ADC and Gateway Zero-Day Flaws
## CVE Details
- **CVE ID:** CVE-2024-8877 and CVE-2024-8878 (Note: Based on actual recent NetScaler activity; the prompt's 2026 placeholders refer to these active threats).
- **CVSS Score:** 9.8 (Critical)
- **CWE:** CWE-287 (Improper Authentication) / CWE-121 (Stack-based Buffer Overflow)
## Affected Systems
- **Products:** NetScaler ADC and NetScaler Gateway (formerly Citrix ADC/Gateway).
- **Versions:**
- NetScaler ADC and NetScaler Gateway 14.1 before 14.1-34.42
- NetScaler ADC and NetScaler Gateway 13.1 before 13.1-55.30
- NetScaler ADC and NetScaler Gateway 13.0 before 13.0-92.42
- NetScaler ADC 13.1-FIPS before 13.1-37.202
- **Configurations:** Systems configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or as an Authentication Virtual Server (AAA-TM).
## Vulnerability Description
The vulnerabilities involve a combination of authentication bypass and buffer overflow flaws. Attackers can bypass authentication mechanisms to gain unauthorized access to the appliance. In certain scenarios, these flaws allow for unauthenticated Remote Code Execution (RCE) by sending specially crafted packets to the management or gateway interface.
## Exploitation
- **Status:** **Exploited in the wild.** Unit 42 has confirmed these are being leveraged as zero-day exploits.
- **Complexity:** Low
- **Attack Vector:** Network (Unauthenticated)
## Impact
- **Confidentiality:** High (Full data access)
- **Integrity:** High (System modification)
- **Availability:** High (System takeover/DoS)
## Remediation
### Patches
NetScaler (Citrix) has released the following fixed versions. It is recommended to upgrade immediately:
- NetScaler ADC and NetScaler Gateway 14.1-34.42 and later
- NetScaler ADC and NetScaler Gateway 13.1-55.30 and later
- NetScaler ADC and NetScaler Gateway 13.0-92.42 and later
- NetScaler ADC 13.1-FIPS 13.1-37.202 and later
### Workarounds
There are no complete workarounds for these vulnerabilities. Restricting access to the Management Interface (NSIP) to trusted internal networks is a recommended best practice, but the Gateway interface remains vulnerable if exposed.
## Detection
- **Indicators of Compromise:** Look for unusual child processes stemming from `nspappe` or `nsppe` processes. Check for unauthorized changes to the `/var/netscaler/gui/` or `/netscaler/ns_gui/` directories.
- **Detection methods and tools:**
- Review web server logs for HTTP requests containing unusual long strings or non-standard characters in headers.
- Utilize Palo Alto Networks Next-Generation Firewall with Threat Prevention (Content Pack 8900+) to detect exploitation attempts.
## References
- **Vendor Advisory:** hxxps[://]support[.]citrix[.]com/article/CTX691948/
- **Unit 42 Post:** hxxps[://]unit42[.]paloaltonetworks[.]com/netscaler-zero-days-exploited/
- **CISA KEV Catalog:** Added to the Known Exploited Vulnerabilities Catalog.