Government authorities and security teams are racing to assess the fallout from a campaign aimed at critical flaws in Citrix NetScaler. Government agencies and critical infrastructure providers were targeted in a wave of attacks dating back more than a month in what may be targeted espionage.
Security teams were first alerted over the weekend in a series of direct warnings from government security agencies, IT security vendors and others urging them to immediately disable their systems.
In the days since, researchers say, the impact has been felt in dozens of organizations across multiple industries.
Critical flaws
Citrix on Sunday disclosed a total of eight vulnerabilities in NetScaler ADC and NetScaler Gateway. Two of those vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, were confirmed to be under exploitation. Both vulnerabilities have a severity score of 9.5 out of 10.
CVE-2026-88771 is a remote code execution vulnerability linked to improper input validation, according to Citrix. Successful exploitation enables an attacker to execute arbitrary commands on a system without the need to authenticate identity. The flaw affects all versions of NetScaler ADC and NetScaler Gateway, even when in a default setting.
CVE-2026-88772 is a memory overflow vulnerability, which can lead to remote code execution or denial of service, according to Citrix. However, successful exploitation requires a communications protocol, called Datagram Transport Layer Security (DTLS), to be enabled on NetScaler ADC or NetScaler gateway. On VPN virtual servers, DTLS is enabled by default.
Citrix warned that the vulnerabilities could lead to a variety of impacts, including remote code execution, denial of service, HTTP request smuggling, policy bypass and TCP initial sequence number prediction.
The Cybersecurity and Infrastructure Security Agency issued its own advisory on Sunday and added the two critical flaws to its Known Exploited Vulnerabilities catalog.
The National Cyber Security Centre in the Netherlands alerted critical infrastructure providers and other organizations to take immediate mitigation measures on Friday, including disabling systems that were not secure, according to a spokesperson.
Z-cert, the national agency for the healthcare sector, advised hospitals to either increase monitoring or temporarily disable vulnerable systems as a precautionary step.
Some Dutch hospitals, including Frisius MC and Amphia, suspended online access to patient portals after taking Citrix NetScaler-based systems offline.
Widespread impacts
Google Threat Intelligence Group (GTIG) and Mandiant Consulting, which specializes in incident response, have identified dozens of organizations across North America and Europe that were affected by the exploitation activity, according to a LinkedIn post by Charles Carmakal, CTO at Mandiant Consulting. They include multiple sectors, such as government, education, financial services, telecommunications, legal and professional services.
The exploitation has not been linked to a known threat group, but GTIG and Mandiant believe the hackers have state-nexus affiliations and said the threat activity shows advanced knowledge and sophistication.
Researchers at Arctic Wolf said the attacks targeted at least 78 organizations across the U.S., Canada and Europe. Targeted organizations range across a variety of industries, including energy, healthcare, financial, local governments, media, education and professional services.
More than 20,000 Citrix NetScaler instances are exposed and potentially vulnerable, according to data from Shadowserver Foundation.
Extended timeline
The threat activity dates back to at least Sept. 3, according to researchers at GTIG. After exploiting CVE-2026-88772, the hackers modified Apache configurations in order to let random file configurations, including .deb, .sig and .ico, to be processed as PHP files, Carmakal said.
Researchers discovered custom PHP webshells, including something called Whipshot, which allows Base64-encoded command-and-control payloads to be hidden inside native HTTP headers. In addition, a novel Python tunneler called Slapshot can be used for reconnaissance and credential theft.
Researchers at Palo Alto Networks told Cybersecurity Dive they have traced threat activity back to Aug. 21, and they are still investigating a number of cases.
Patch releases
Citrix urged customers to immediately apply security upgrades to their systems. The upgrades included the following versions:
- NetScaler ADC and NetScaler Gateway 14.1-73.37 and later releases
- NetScaler ADC and NetScaler Gateway 13.1-64.23 and later
- NetScaler ADC 14.1-FIPS and 14.1-73.37 FIPS and later releases of 14.1-FIPS
- NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.279 and later releases of 13.1 FIPS and 13.1 NDcPP
Business impacts
Citrix NetScaler is widely used across the enterprise to help ensure that applications are readily available. Companies use these tools to make sure remote workers can access computer networks in a secure manner and to balance loads to ensure traffic is properly routed.
“In healthcare IT and OT environments, NetScaler often sits at the edge of the network, providing secure remote access and application delivery,” said Errol Weiss, chief security officer at Health Information Sharing and Analysis Center. “NetScaler enables clinicians and staff to securely access essential clinical applications, like electronic health records (EHRs), from remote locations.”
Health-ISAC sent an urgent advisory on Sunday to member organizations. Weiss noted that a number of healthcare CISOs said they planned to disable their connections until permanent fixes were available.
Researchers warned that patching will not necessarily resolve infections, particularly if hackers gained access to systems before security updates were applied.
“Upgrading alone will not eradicate post-exploitation access or address stolen credentials,” Carmakal said in a LinkedIn post on Tuesday.
Mitigation measures
GTIG recommends that in the case of a suspected compromise, security teams should isolate NetScaler from the larger network. Researchers cautioned this procedure can lead to significant business disruption.
If patching is not an immediate option, steps can be taken to reduce the potential security risks; DTLS can be temporarily disabled on internet-facing NetScaler Gateway servers. Inbound UDP/443 access, which is used to speed up web traffic, can be blocked to affected servers.
Security teams should also rotate credentials and revoke active sessions. Downstream Citrix infrastructure, including Citrix StoreFront servers and Citrix Delivery Controllers, should be audited. Review Windows Event Logs for unusual logins or unexpected use of Remote Desktop Protocol.