Skip to main content
Emerging Threats

NetScaler Zero-Days Exploited in Wild, 50,277 Instances Exposed

Rows of computer servers and networking equipment on racks in a well-lit data center environment.

50,277 exposed instances appear potentially vulnerable to two newly exploited NetScaler flaws, Palo Alto Networks’ Cortex Xpanse telemetry shows — a tally that Unit 42 highlighted in its Sept. 27, 2026 threat brief.

Citrix, Unit 42, and Cortex Xpanse: the central claims

Unit 42 reported that Citrix has disclosed exploitation in the wild of two NetScaler vulnerabilities identified as CVE-2026-88771 and CVE-2026-88772. The brief notes that, as of Sept. 27, 2026, Palo Alto Networks’ Cortex Xpanse telemetry has identified 50,277 exposed instances that could potentially be vulnerable to these CVEs. Unit 42 framed the activity as “possible zero-day activity” against NetScaler devices and updated the advisory on Sept. 27, 2026 at 4:15 p.m. PT to add the Cortex Xpanse telemetry detail.

CVE-2026-88771 and CVE-2026-88772: the technical core

The two vulnerabilities present severe remote risks to NetScaler ADC and NetScaler Gateway deployments. CVE-2026-88771 is described as a remote code execution (RCE) vulnerability that “fails to properly validate input and allows an unauthenticated actor to run commands” against NetScaler ADC and NetScaler Gateway systems. CVE-2026-88772 is a memory overflow vulnerability affecting the Datagram Transport Layer Security (DTLS) configuration on the same products; it can lead to either RCE or a denial of service (DoS). Both vulnerabilities carry a CVSS v4.0 base score of 9.5.

Immediate mitigation and patching guidance from Unit 42

Unit 42 recommends updating Citrix software to the latest versions “as soon as possible.” The brief also directs administrators to confirm exposure by following the “Steps to determine if an appliance meets the CVE preconditions” section of the Citrix Security Advisory for these vulnerabilities. Beyond patching, Unit 42 advises isolating vulnerable systems from the network to limit further exposure.

Evidence preservation and hunting guidance for incident response

For teams investigating potential compromise, Unit 42 lists specific artifacts to preserve: a NetScaler VPX instance snapshot, logs stored on remote syslog servers and the NetScaler Console, a technical support bundle, and a packet engine core dump. Unit 42 further recommends hunting for signs of suspicious administrative sessions, unexpected outbound connections, and unexplained gaps in logging. The brief cautions that these items are “not tactics, techniques and procedures (TTPs) we have observed specifically related to these vulnerabilities” and should be treated as general hunting guidance until more is known about the exploitation Citrix identified.

What this means for technologists and security teams, affected enterprises, and incident responders

  • Technologists and security teams: Confirm exposure using the Citrix advisory steps, prioritize patching to the latest Citrix software versions, and be prepared to isolate affected appliances. Preserve the specified artifacts (VPX snapshot, support bundle, core dump, and logs) to support investigation and remediation.
  • Affected enterprises and procurement leaders: The Cortex Xpanse figure of 50,277 exposed instances underscores the scale of potential exposure; organizations should inventory NetScaler ADC and NetScaler Gateway deployments, apply updates promptly, and expect to coordinate evidence preservation if they suspect compromise. Be aware that Unit 42 notes updating and patching “will not remove access for attackers that have already established persistence within a compromised network.”
  • Incident responders: Unit 42’s Incident Response team is available for engagements to help with compromises or provide proactive assessments. Region-specific contact numbers are provided in the brief, including a North America toll-free number (+1 (866) 486-4842) and local numbers for the UK, Europe and Middle East, Asia, Japan, Australia, India, and South Korea.

The combination of high-severity CVSS scores, confirmed exploitation by Citrix, and a six-figure count of potentially exposed instances in Cortex Xpanse telemetry yields a clear operational imperative: prioritize verification, isolation, artifact preservation, and patching now, and engage incident response resources where compromise is suspected. For administrators and responders who need help, Unit 42 lists regional contact numbers and stands ready to assist.

Source and full advisory: https://unit42.paloaltonetworks.com/netscaler-zero-days-exploited/