NetScaler Web Shells Confirmed: KEV Deadline Is Today
Cybersecurity firms document the CVE-2026-88772 attack chain: web shells, tunneling malware, root access, and lateral movement. CISA KEV deadline expires today.

The memory buffer boundary violation in Citrix NetScaler ADC and Gateway, tracked as CVE-2026-88772 (CVSS 8.1), was exploited before Citrix confirmed the flaw or released a patch. Multiple cybersecurity firms have now documented the attack chain in detail, according to BleepingComputer: attackers used the vulnerability to deploy custom web shells for persistent access, install tunneling malware, gain root privileges, harvest credentials, and spread into internal networks.
The federal remediation deadline for this CVE is today.
The patch and the deadline
Citrix released patches for CVE-2026-88772 and its companion flaw CVE-2026-88771 on September 28. CVE-2026-88771 is an improper input validation flaw in the same products enabling unauthenticated remote code execution. CISA added both to the Known Exploited Vulnerabilities catalog on September 27, with a remediation deadline of September 30 for federal agencies.
Coverage from when the patches dropped noted that exploitation predated CVE assignment. The newly reported attack chain confirms what attackers did during that window.
Patching is not sufficient on its own
Applying the patch closes the initial access vector. It does not remove web shells or tunneling processes installed before the patch was applied. An appliance compromised before September 28 may retain persistent access regardless of its current patch state.
The initial advisory analysis identified forensic markers to check: unusual administrative sessions, unexpected configuration changes, and web shell indicators in appliance management interfaces. Checking those alongside patching is the complete remediation path, not patching alone.
What to do now
Apply Citrix’s patches for both CVE-2026-88771 and CVE-2026-88772. Consult the Citrix security advisory for specific patched build versions before applying; the advisory is the authoritative source for build numbers, not press coverage.
Run a forensic check of each appliance: look for unexpected web-accessible files, outbound tunnel connections from the appliance, and configuration changes outside your change management record. If your team lacks that capacity, engage outside IR support before declaring the appliance clean.
If you are also running CVE-2026-19490 unpatched, the NetScaler auth bypass from August, resolve all three at the same time.
- [ HIGH ]CVE-2026-88772Citrix NetScaler ADC/Gateway RCE via Memory Buffer Mishandling
- [ HIGH ]CVE-2026-88771Citrix NetScaler ADC/Gateway Unauthenticated RCE via Input Validation Flaw
Found this useful? Share it.


