York Computer logo York Computer
Managed IT & Security
Cybersecurity News

Citrix NetScaler Zero-Days Exploited in the Wild — Patch Now or Pull the Plug

York Computer •

Two critical zero-day vulnerabilities in Citrix NetScaler ADC and Gateway appliances — the gear many businesses use for employee remote access — are being actively exploited by attackers who are gaining root-level control, planting hidden web shells, and tunneling into internal networks. Citrix pushed emergency patches on September 27, and CISA added both flaws to its Known Exploited Vulnerabilities catalog the same day. If your business touches a NetScaler device (directly or through a vendor), this is a this-week problem.

What happened

On September 27, 2026, Citrix disclosed eight new vulnerabilities affecting NetScaler ADC and NetScaler Gateway, including two critical remote code execution (RCE) vulnerabilities: CVE-2026-88771 and CVE-2026-88772. Both of these RCE vulnerabilities carry a critical CVSSv4 score of 9.5, and both have been confirmed as being actively exploited in the wild as zero-days prior to the vendor disclosure.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) reports active exploitation is occurring globally, and added both CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) catalog on September 27, 2026. Mandiant and Google's Threat Intelligence Group observed organizations in North America and Europe in the government, financial services, technology, education, and legal and professional services sectors likely impacted by the exploitation campaign, which has been ongoing since at least early September.

Why this is dangerous for small businesses

NetScaler isn't just a big-enterprise product. Many small and mid-sized businesses — and the MSPs that serve them — use NetScaler Gateway as the front door for employee remote access and VPN. That makes it an edge device, directly reachable from the internet, which is exactly the kind of target attackers love.

Since at least early September 2026, attackers have taken root-level control of Citrix NetScaler appliances without a password. Mandiant and Google Threat Intelligence Group traced the break-ins to a Citrix NetScaler zero-day, CVE-2026-88772. The researchers describe custom web shells hidden behind fake image requests. Once inside, a Python tunneling tool named SLAPSHOT listens on a local loopback port and proxies arbitrary TCP traffic from the compromised NetScaler device into the internal network. This capability allows attackers to perform reconnaissance, connect to internal hosts, steal credentials, and support lateral movement.

In plain English: a vulnerable NetScaler is a wide-open door that leads straight into your file servers, email, and backups — and the attacker doesn't need a password to walk through it. For firms covered by York Computer's managed IT and cybersecurity services, edge devices like these are exactly what 24/7 monitoring is built to catch.

What your IT provider should be doing this week

If you have a NetScaler appliance anywhere in your environment, your managed-IT provider should already be doing all of the following:

1. **Inventory.** Confirm whether any NetScaler ADC or Gateway appliances are deployed — including shadow installs from an old project or an acquired company.

2. **Patch to the fixed builds immediately.** Citrix confirmed both flaws and released fixed builds on September 27, 2026 in security bulletin CTX697096. The issue affects every NetScaler ADC and NetScaler Gateway deployment on an affected version, including the default configuration. No special feature needs to be enabled.

3. **Assume compromise if the device was exposed before patching.** Public reports of possible exploitation first surfaced online on Sept. 25 in a Reddit thread, and there's additional evidence that attacks began at least a week ago. That means a patch alone isn't enough — logs, running processes, and web server configuration should be reviewed for signs of the WHIPSHOT web shell and SLAPSHOT tunneler.

4. **Rotate credentials and session tokens** that could have passed through the appliance.

5. **If you can't patch today, take it offline.** Governments and companies across Europe shut down or disconnected their NetScalers while waiting for a patch. A disconnected VPN gateway is an inconvenience; a compromised one is a business-ending event.

If you're not sure what your current IT setup includes, or you have an in-house tech who could use backup on an incident like this, that's exactly what co-managed IT support is for.

How to tell if you're exposed

Ask your IT provider three specific questions today:

- "Do we have any Citrix NetScaler ADC or NetScaler Gateway appliances in our environment, including anything a vendor manages for us?" - "If yes, were they patched to the September 27 CTX697096 fixed builds, and when?" - "Did you review logs for indicators of compromise before patching, and what did you find?"

A good answer is specific, dated, and references the CVE numbers. A vague answer — "we're on it" or "we don't think so" — is a red flag.

What York Businesses Should Do

York County small businesses that rely on an outside IT vendor for remote-access VPN should send that vendor a written question this week: are any Citrix NetScaler devices in play, and are they patched? If you'd like a second set of eyes on the answer, York Computer can review your perimeter.

Sources

Worried whether your business is exposed to this? Talk to York Computer.

Managed IT & cybersecurity for York County small businesses.

← Back to all articles