```html ```
top of page

Four NetScaler Bugs Hit CISA's Exploited List in 32 Days. Our Honeypots Logged 126,873 Attacks and Not One of Them Was This. Here Is Why, and What Your Only Lever Is.

Writer: Patrick Duggan
Patrick Duggan
1 hour ago
5 min read

Citrix shipped patches on Saturday for two NetScaler bugs that attackers had already been using for weeks. CISA put both in its Known Exploited Vulnerabilities catalog the same day and gave federal agencies until Wednesday, September 30, to patch and to check for signs of compromise. That second instruction is the one that matters.


This is the fourth NetScaler entry in CISA's catalog in 32 days, and the fifth in twelve months. We have edge honeypots that have logged 126,873 attack records. None of those records is an attempt on this bug. That is not because nobody tried. It is because our honeypots do not look like a NetScaler, so nobody had a reason to try them. More on that below, after the part you need to act on.



What happened


CVE-2026-88771 is an input validation flaw that lets an unauthenticated attacker run commands on NetScaler ADC and NetScaler Gateway. It works on a default configuration. No optional feature has to be turned on.


CVE-2026-88772 is a memory overflow that leads to code execution or a crash. It needs DTLS enabled, and DTLS is on by default for VPN virtual servers. So if you run NetScaler Gateway as your remote access VPN, assume you are exposed to both.


Both score 9.5 on CVSS version 4. Both were exploited as zero-days before Citrix said anything. Help Net Security reports the attacks have been running through all of September, and that European government sources were warning organizations all last week. Palo Alto Networks' Unit 42 counts 50,277 internet-facing instances that could be vulnerable, from its Cortex Xpanse scanning as of September 27.


What the attackers did once inside, per the public reporting: custom web shells, tunneling malware, root access, credential theft, and movement into internal networks. Each compromised device reportedly got its own web shell, which is why nobody has published a hash list. There are no public IP addresses, no domains and no hashes as of this writing. There is also no public attribution. The consensus read is a well-resourced espionage operation, and history backs that up: most threat activity against NetScaler over the last seven years has come from state-backed groups.





What to do today


Patch to NetScaler ADC and Gateway 14.1-73.37 or later, or 13.1-64.23 or later on the 13.1 line. FIPS and NDcPP builds have their own fixed versions in Citrix's advisory CTX697096.


Then do the part CISA asked for, even if you are not a federal agency. Patching closes the door. It does not evict anyone who came through it during September. With no public indicators, you are hunting for behavior, not matching a list. The reporting gives three places to look. First, web requests with a Base64 string after the User-Agent field. Second, log lines containing the word pitboss followed by IFS. Third, anything on the appliance's file system that you did not put there, since the shells are unique per device. Rapid7 has published Suricata rules for CVE-2026-88771 if you run that engine.


If you find a shell, treat every credential that crossed that appliance as gone. A NetScaler Gateway sees your users' passwords and session tokens in the clear. That is the whole reason attackers want it.



What our data shows, and what it cannot show


Our edge honeypots are fake endpoints on our Cloudflare workers. They pretend to be leaked config files, WordPress logins, database dumps and admin panels, and they record whoever shows up. To date they have logged 126,873 records.


We searched all of them for NetScaler-shaped requests. Two touched a path that looks like one: /vpn/%2eenv and /saml/%2eenv, both from 185.177.72.30 on May 27. Both are generic sprays looking for a leaked .env file in every folder the scanner can guess. Neither is NetScaler exploitation. That address has been in our feed since February for unrelated scanning.


So the honest count is zero. The reason is simple. Attackers going after a NetScaler first check whether the target looks like one, and our honeypots never have. A trap only catches what it resembles. We have caught plenty of WordPress, Spring actuator, .env and git scanning because we built traps shaped like those things. We never built one shaped like one of the most exploited remote access appliances of the last three years.


There is a second limit worth naming. CVE-2026-88772 rides DTLS, which is UDP. Our honeypots live in web workers that only see HTTP. Even with a perfect NetScaler disguise, we would see the reconnaissance and the web-side bug, not the DTLS one.


We have written about this appliance line before: our June post on the CVE-2026-3055 SAML overread, which opened by admitting our feed had not warned us either, and our post on the third CitrixBleed variant. What we did not have was our own sensor on it. That is the gap, and it is ours to close.



The fix we are proposing


Add NetScaler-shaped canaries to the edge honeypots: the Gateway login page, the /vpn/ and /logon/LogonPoint/ paths, and the headers a real appliance sends back. The goal is not to catch the zero-day itself. It is to catch the fingerprinting that comes before it, so that the next time a NetScaler campaign starts, we see scanners checking for the appliance before the vendor advisory lands. That is a proposal, not something we have shipped. When it ships, we will say so with a date.





One more thing we caught on ourselves


Our automated morning sweep read this story today and marked it as covered. The match was our June post on CVE-2026-3055, which is the same product but a different bug. Running the story back through our own search index showed the mismatch before we trusted it. A post about the same appliance is not coverage of this attack, and we are not counting it as a lead.



The opinion


Four exploited NetScaler bugs in 32 days is not bad luck. It means someone with money is working through this appliance on purpose, and the edge device is where they want to live: it sits outside your EDR, it sees credentials in the clear, and most shops log it poorly. If you still run a NetScaler Gateway as your front door, you are running the device that attackers have picked out as the easiest way in. Patch it this week, hunt on it this week, and start planning the budget conversation about whether it should still be your front door next year. We hold that view with about 90 percent confidence. The other 10 percent is that Citrix's recent hardening turns the tide, and the evidence for that is not visible yet.


Was this useful? Rate this post. The widget is at the bottom of the page, and we read every response.




Every indicator in this post is in the feed. Free.

1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.



Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=four-netscaler-bugs-hit-cisa-s-exploited-list-in-32-days-our-honeypots-logged-126-873-attacks-and-n



Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page