A memory-overflow flaw in Citrix NetScaler ADC and Gateway is being actively exploited and capable of leading to remote code execution or denial of service, according to the vulnerability management community and the UK's NCSC. CVE-2026-88772 carries a CVSS v4 score of 9.5 and demands urgent verification, not assumption, that patches have actually landed.
View the data behind this chart
| Phase | Starts (week) | Duration (weeks) |
|---|---|---|
| Silent exploitation begins… | 0 | 3 |
| Citrix disclosure & patch (approx.) | 3 | 1 |
| NCSC confirms active exploitation | 4 | 1 |
What Citrix disclosed and when
Citrix pushed patches for two actively exploited NetScaler issues, CVE-2026-88771 and CVE-2026-88772, in a disclosure and patch window dated 27 and 28 September 2026. Citrix itself stated that "exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed", which is about as unambiguous as vendor language gets. As of 30 September 2026, the status is settled: the flaws are publicly disclosed, patches are shipped, and exploitation is confirmed — this is no longer a theoretical or upcoming risk.
Why CVE-2026-88772 deserves priority over routine patching
The bug is a memory overflow — described in some reporting as improper restriction of operations within the bounds of a memory buffer — affecting NetScaler ADC and Gateway when DTLS is enabled. Multiple reports note DTLS is on by default for VPN virtual servers, so systems using VPN virtual servers with the default DTLS setting may be exposed unless administrators changed that configuration. Citrix describes CVE-2026-88772 as a CVSS v4 9.5 memory-overflow vulnerability that can lead to remote code execution or denial of service, and some reporting links exploitation to an unhandled termination of the NetScaler Packet Processing Engine, or NSPPE. This can lead to remote code execution or denial of service on a device that typically sits at the network perimeter, which is why UK teams should understand CVE, CVSS, and KEV scores well enough to know a 9.5 demands same-day, not same-sprint, treatment.
Post-exploitation tooling adds urgency to log review
Reporting on this campaign describes previously unreported PHP web shells, including one dubbed WHIPSHOT, used to disguise Base64-encoded command-and-control payloads inside native HTTP headers. Google researchers cited by The Register say the CVE-2026-88772 campaign has been running since at least early September 2026 — weeks before public disclosure. That gap matters commercially: organisations that only patched on or after 28 September should consider whether exploitation could have occurred before patching and review logs and incident indicators accordingly, and should develop an incident response plan that includes retrospective log review, not just forward-looking patch confirmation.

The UK regulatory signal is unusually direct
The NCSC has gone further than a routine advisory, stating plainly that "two of these, CVE-2026-88771 and CVE-2026-88772, have been confirmed as being actively exploited." Naming both CVEs specifically, rather than issuing generic guidance, signals that UK national infrastructure defenders are treating this as a live incident rather than a hygiene reminder. On the US side, federal guidance reportedly ordered agencies to patch by the following Wednesday — a timeline UK procurement and security teams should mirror internally even without a legal mandate, given the shared exposure across public sector, financial services and professional services NetScaler estates.
What UK admins should actually check this week
Confirming a patch banner in the management console is not the same as confirming remediation has held. Buyers running NetScaler ADC or Gateway should verify build numbers against Citrix's fixed releases, disable DTLS on VPN virtual servers where it is not operationally required, and pull NSPPE crash logs and gateway audit trails for the weeks since early September looking for anomalous restarts or unexplained process terminations. Any web shells matching the WHIPSHOT pattern, or unusual Base64 content in HTTP headers, should be investigated urgently and may warrant isolation under the organisation's incident-response procedures. Because this attack chain compromises the gateway itself rather than a downstream application, organisations should also review whether their wider estate would benefit from zero trust segmentation so a single perimeter appliance breach cannot cascade into full network access.
- •Verify installed NetScaler build against Citrix's confirmed fixed versions, not just an update notification
- •Audit NSPPE logs and gateway sessions for the period since early September 2026
- •Check for DTLS enabled by default on VPN virtual servers and disable where not required
- •Scan for PHP web shells and anomalous Base64 content in HTTP headers
- •Escalate any suspicious findings through a tested incident response process
Planning beyond the immediate patch
Buyers running appliances nearing end of support should weigh whether patch-and-hope is a sustainable posture or whether it's time to strengthen your network security architecture more broadly. Organisations on older, harder-to-patch hardware may want strategies for securing end-of-support hardware or to explore third-party maintenance options that extend visibility and support without waiting on vendor release cycles alone. Continuous monitoring through managed detection & response could help detect anomalous process terminations or related activity.
- 01The Hacker News — CISA says attackers are exploiting two Citrix NetScaler flaws · 28 September 2026
- 02The Hacker News — Warning: two unpatched Citrix NetScaler flaws · 27 September 2026
- 03NCSC — Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway · 29 September 2026
- 04BleepingComputer — Citrix admins warned to shut down NetScalers over 2 exploited zero-days · 28 September 2026
- 05The Register — Custom malware used in Citrix 0-day attacks targeting govt, banks, professional services · 29 September 2026
- 06thehackernews.com
