Citrix NetScaler Zero-Days: The Front Door Was Open for Weeks

Citrix NetScaler Zero-Days: The Front Door Was Open for Weeks

Your VPN gateway is supposed to be the bouncer at the club: checks IDs, keeps the riffraff out. This month, it turns out the bouncer at thousands of organizations had been quietly letting strangers into the back room for weeks before anyone noticed.

Two Bugs, Zero Passwords Required

Citrix confirmed two NetScaler ADC and NetScaler Gateway zero-days exploited in the wild. CVE-2026-88771 allows unauthenticated attackers to execute arbitrary commands on devices running default configurations, while CVE-2026-88772 is a memory overflow in DTLS handling that enables remote code execution when DTLS is enabled, which it is by default on VPN virtual servers. Either can be exploited on its own.

According to Help Net Security, exploitation began in early September and continued globally for weeks, with attackers deploying web shells, gaining root access, stealing credentials and moving into internal networks. Affected versions include 14.1 before 14.1-73.37 and 13.1 before 13.1-64.23, and Palo Alto Networks counted more than 50,000 exposed instances as of 27 September. The Dutch NCSC-NL warned that the flaw "gives attackers full control of the gateway, providing direct access to the internal corporate network behind it."

Patching Is Step One, Not the Finish Line

When the exploitation window is measured in weeks, installing the update is like changing the locks after the burglar has already copied your keys. Guidance accompanying the disclosure urges organizations to preserve device memory and logs going back at least a month, hunt for web shells, and bring in forensic help, because the attackers reportedly use anti-forensics techniques. NCSC-NL and researcher Kevin Beaumont suggest a sophisticated, likely nation-state-aligned actor is behind it.

The bigger lesson is about edge devices in general. Gateways, VPNs and load balancers sit on the internet by design, rarely get the same scrutiny as your main applications, and hold the keys to everything behind them. If your security plan focuses only on the website and ignores the box in front of it, attackers have already noticed the gap.

Patch today, investigate like you were already breached, and stop treating the perimeter as somebody else's problem.

Edge appliances and the web apps behind them are one attack surface, so if this story made you realize nobody owns that whole picture at your organization, I'm happy to help you review it end to end.

Source: Help Net Security