About PitScaler and its methodology
PitScaler is an independent, non-commercial technical briefing on the September 2026 Citrix NetScaler ADC and Gateway zero-day incident (CVE-2026-88771, CVE-2026-88772 and the six other CVEs in bulletin CTX697096). It is maintained by an independent security practitioner. It is not affiliated with, endorsed by or sponsored by Cloud Software Group, Citrix or NetScaler.
Quick answers
Who maintains PitScaler?
An independent security practitioner, writing as the PitScaler editorial identity. Contact and corrections: pitscaler@v1.dk.
Is PitScaler affiliated with Citrix?
No. It is not affiliated with, endorsed by or sponsored by Cloud Software Group, Citrix or NetScaler. For official guidance, use Citrix bulletin CTX697096.
What kind of source is PitScaler?
A secondary, independent compilation. It does not produce original telemetry or incident-response findings; every fact is attributed to the primary source that published it.
How are claims verified?
Each source page is read before it is cited, and quotes are checked word for word. Where a claim rests on one researcher, a press report or a community post, it is labelled as reported and not independently verified.
What counts as independently verified?
A claim marked "Validated" has been confirmed by a second, independent check, for example against the CVE record, the CISA KEV feed, a primary advisory or a first-hand observation. Claims confirmed only through non-public sources say so, and those sources are not named.
How are corrections handled?
Corrections sent to pitscaler@v1.dk are checked against the primary source and fixed in the next update. The page date changes only when the content changes.
When was this last verified?
The whole site is a snapshot as of 30 September 2026. Individual timeline entries marked "Validated" carry their own check date.
Methodology
Every statement is tied to a numbered reference. Sources are classified as:
- Official: the vendor bulletin and government or national CERT advisories. These take precedence.
- Research: technical analysis and first-hand incident response by named security firms.
- Telemetry: sensor and honeypot data (for example GreyNoise, Lupovis, Defused).
- Reported: claims by individual researchers, community posts and press. These are attributed by name and labelled as not independently verified unless corroborated.
Where a claim has been checked against a second source, it is marked Validated. Exposure counts are never presented as victim counts.
IoC policy
Only indicators that have been published openly (TLP:CLEAR or public pages without a TLP marking) are listed, each with its source, sharing marking and a caveat. Indicators received under restricted TLP are not published unless the same value later appears in a public source, which is then cited. IoCs are hunting leads, not universal indicators for every victim.
Updates and corrections
This is a dated historical snapshot, not a live feed. The as-of date and last-updated date appear at the top of every page. Send corrections to pitscaler@v1.dk.
Formats
Related pages
References
| # | Source | Type | URL |
|---|---|---|---|
| 1 | Citrix - CTX697096 security bulletin (Sep 27) | Primary official advisories | https://support.citrix.com/external/article/CTX697096/citrix-netscaler-adc-and-citrix-netscale.html |
| 2 | Citrix community blog - Security Bulletin for CVE-2026-88771 through CVE-2026-88778 (incl. IoC section) verification pending | Primary official advisories | https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/ |
| 3 | Citrix (CTX-Michael) on r/Citrix, Sep 27 - CRITICAL UPDATE announcement | Primary official advisories | https://www.reddit.com/r/Citrix/comments/1wro1yf/critical_update_citrix_netscaler_adc_and_citrix/ |
| 4 | NetScaler Console documentation - Indicators of Compromise detection (incl. Citrix disclaimer on limits) | Primary official advisories | https://docs.netscaler.com/en-us/netscaler-console-service/instance-advisory/ioc |
| 5 | CISA alert - Critical zero-day vulnerabilities exploited in Citrix NetScaler ADC/Gateway (Sep 27) | Primary official advisories | https://www.cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway |
| 6 | NCSC-NL advisory NCSC-2026-0394 (probability high, damage high; per-CVE scores and preconditions) | Primary official advisories | https://advisories.ncsc.nl/ |
| 7 | NCSC-UK - Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Gateway | Primary official advisories | https://www.ncsc.gov.uk/news/exploitation-of-vulnerabilities-affecting-citrix-netscaler-adc-and-citrix-netscaler-gateway |
| 8 | CSA Singapore - AL-2026-129 | Primary official advisories | https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-129/ |
| 9 | Canadian Centre for Cyber Security - AL26-024 | Primary official advisories | https://www.cyber.gc.ca/en/alerts-advisories/al26-024-critical-vulnerabilities-affecting-citrix-netscaler-adc-netscaler-gateway-cve-2026-88771-cve-2026-88772 |
| 10 | HKCERT - Citrix Products Multiple Vulnerabilities (Sep 28) | Primary official advisories | https://www.hkcert.org/security-bulletin/citrix-products-multiple-vulnerabilities_20260928 |
| 11 | ACSC (Australia) - Critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway | Primary official advisories | https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/critical-vulnerabilities-in-citrix-netscaler-adc-and-citrix-netscaler-gateway-products |
| 12 | CISA Known Exploited Vulnerabilities catalog (both CVEs added Sep 27, due Sep 30) | Primary official advisories | https://www.cisa.gov/known-exploited-vulnerabilities-catalog |
| 13 | CERT-EU Security Advisory 2026-014 - Critical Vulnerabilities in Citrix NetScaler ADC and Gateway (Sep 27) | Primary official advisories | https://cert.europa.eu/publications/security-advisories/2026-014/ |
| 14 | DKCERT (CERT for Danish universities and research) - To kritiske NetScaler 0-dage udnyttes aktivt før patch (Sep 29) | Primary official advisories | https://cert.dk/node/639 |
| 15 | NHS England Digital cyber alert CC-4858 (Sep 28) - Exploitation of zero-day vulnerabilities affecting Citrix NetScaler | Primary official advisories | https://digital.nhs.uk/cyber-alerts/2026/cc-4858 |
| 16 | CIRCL TR-100 - per-CVE configuration-check CLI commands | Primary official advisories | https://www.circl.lu/pub/tr-100/ |
| 17 | Dutch government letter to parliament - Kwetsbaarheden Citrix Netscaler (2026D47262, Sep 29) | Primary official advisories | https://www.tweedekamer.nl/kamerstukken/brieven_regering/detail?id=2026D47262&did=2026D47262 |
| 18 | CVE.org - CVE-2026-88771 record (reserved Sep 10 07:14 UTC by NetScaler; published Sep 27 16:02 UTC) | Primary official advisories | https://www.cve.org/CVERecord?id=CVE-2026-88771 |
| 19 | CERT-EU - Taking "execute logging" a bit too literally - CVE-2026-88771 (Sep 28) | Technical research | https://www.cert.europa.eu/blog/taking-execute-logging-a-bit-too-literally-cve-2026-88771 |
| 20 | watchTowr Labs part 1 - Oh Look, the Foot Gun Went Off Again (CVE-2026-88771) (Sep 28) | Technical research | https://labs.watchtowr.com/oh-look-the-foot-gun-went-off-again-citrix-netscaler-preauth-command-injection-cve-2026-88771/ |
| 21 | watchTowr Detection Artefact Generator - CVE-2026-88771 (GitHub) | Technical research | https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88771 |
| 22 | watchTowr Labs part 2 - Here We Go Again (CVE-2026-88772), Sina Kheirkhah (Sep 29) | Technical research | https://labs.watchtowr.com/here-we-go-again-citrix-netscaler-dtls-preauth-memory-overflow-cve-2026-88772/ |
| 23 | watchTowr Detection Artefact Generator - CVE-2026-88772 (GitHub) | Technical research | https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88772 |
| 24 | Truesec - Multiple Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway (Sep 28) | Technical research | https://www.truesec.com/hub/blog/multiple-critical-vulnerabilities-in-citrix-netscaler-adc-and-netscaler-gateway |
| 25 | Google GTIG / Mandiant - Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances (Sep 29) | Technical research | https://cloud.google.com/blog/topics/threat-intelligence/defending-against-active-exploitation-of-citrix-netscaler-adc-and-gateway-appliances |
| 26 | Nextron Systems (Florian Roth) - New THOR Detection Coverage for CVE-2026-88771 and CVE-2026-88772 (Sep 29) | Technical research | https://www.nextron-systems.com/2026/09/29/new-thor-detection-coverage-for-citrix-netscaler-cve-2026-88771-and-cve-2026-88772/ |
| 27 | Beazley Security advisory (updated Sep 29) - IoC table incl. Lupovis honeypot IPs | Technical research | https://beazley.security/alerts-advisories/critical-vulnerability-in-citrix-netscaler-zero-day-prompts-emergency-shutdowns-cve-2026-88771-cve-2026-88772 |
| 28 | Corelight - Hunting Citrix NetScaler zero-days (Zeek queries, Sep 28) | Technical research | https://corelight.com/blog/hunting-citrix-netscaler-zero-days-corelight |
| 29 | Elastic detection rule - Potential NetScaler Log Poisoning Command Injection Attempt (merged Sep 28) | Technical research | https://github.com/elastic/detection-rules/blob/main/rules/network/initial_access_netscaler_log_poisoning_command_injection.toml |
| 30 | SigmaHQ pull request #6352 - NetScaler auth endpoint shell metacharacters (open, Sep 29) | Technical research | https://github.com/SigmaHQ/sigma/pull/6352 |
| 31 | Nuclei templates pull request #17336 - CVE-2026-88771 active probe (open, Sep 28) | Technical research | https://github.com/projectdiscovery/nuclei-templates/pull/17336 |
| 32 | eSentire TRU - Update: ongoing exploitation of NetScaler CVE-2026-88771 / -88772 (first-hand IR, Sep 29) | Technical research | https://www.esentire.com/security-advisories/update-ongoing-exploitation-of-citrix-netscaler-adc-and-netscaler-gateway-vulnerabilities-cve-2026-88771-cve-2026-88772 |
| 33 | Beazley Security Labs - BSL-A1216 advisory (updates 3-4, Sep 29): consolidated IoCs and hunting commands | Technical research | https://labs.beazley.security/advisories/BSL-A1216 |
| 34 | watchTowr (@watchtowrcyber) on X, Sep 26 - "Unpatched, 0days. Exploited in-the-wild - discovered during forensics." | Technical research | https://x.com/watchtowrcyber/status/2103972792043479307 |
| 35 | CyberMaxx - Patches required: Citrix NetScaler vulns exploited in the wild (IoC notes) | Technical research | https://www.cybermaxx.com/resources/patches-required-citrix-netscaler-vulns-exploited-in-the-wild-cve-2026-88771-and-cve-2026-88772/ |
| 36 | GreyNoise - Swarming Against Citrix 0-Day Exploitation (TLP:CLEAR IoCs, Sep 28) | Telemetry and IoCs | https://greynoise.io/blog/swarming-against-citrix-0-day-exploitation |
| 37 | GreyNoise Chronicle - GNTL-20260928 CVE-2026-88771 timeline | Telemetry and IoCs | https://www.greynoise.io/chronicle/gntl-20260928-citrix-cve-2026-88771 |
| 38 | GreyNoise Visualizer - IP 149.104.78.141 | Telemetry and IoCs | https://viz.greynoise.io/ip/149.104.78.141 |
| 39 | GreyNoise tag - Citrix NetScaler CVE-2026-88771 Login Command Injection RCE Attempt | Telemetry and IoCs | https://viz.greynoise.io/tag/citrix-netscaler-cve-2026-88771-login-command-injection-rce-attempt |
| 40 | IFIN - Multiple Citrix Netscaler 0-Days Exploited (tracking thread, from Sep 26; observables "shared without restriction") | Telemetry and IoCs | https://ifin.network/t/multiple-citrix-netscaler-0-days-exploited/867 |
| 41 | Censys advisory - NetScaler exposure (42,735 hosts, Sep 28) | Telemetry and IoCs | https://censys.com/advisory/cve-2026-10747-2/ |
| 42 | Defused (@DefusedCyber) on X, Sep 29 - decoy hits across multiple CVE-2026-88771 paths | Telemetry and IoCs | https://x.com/DefusedCyber/status/2104888497693708505 |
| 43 | Lupovis (@LupovisDefence) on X, Sep 28 - decoys catch CVE-2026-88771 exploitation hours after the PoC | Telemetry and IoCs | https://x.com/lupovisdefence/status/2104595071362326680 |
| 44 | Beaumont, Sep 27 - chained CVEs, webshells all September, "Probably nation state aligned" | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117343729453093307 |
| 45 | Beaumont, Sep 27 - patches live; detection script behind NDA; patching does not remove backdoors | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117343821114841048 |
| 46 | Beaumont, Sep 27 - Console check misses attempts when logs have rotated | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117345540231975640 |
| 47 | Beaumont, Sep 28 22:49 UTC - names "PitScaler", >100 victim orgs (his claim) | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117351107654208046 |
| 48 | Beaumont, Sep 28 23:02 UTC - Citrix checker incomplete (suid /bin/sh) | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117351155381900219 |
| 49 | Beaumont, Sep 29 04:39 UTC - mass exploitation, <10% patched (his claim) | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117352481501981552 |
| 50 | Beaumont, Sep 29 06:18 UTC - public message to the NSA (his unverified claim) | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117352869498139711 |
| 51 | Beaumont, Sep 29 16:12 UTC - IR vendors publishing victim-unique webshell names | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117355208096613386 |
| 52 | Beaumont, Sep 28 15:13 UTC - GitHub "PoCs" for the new Citrix vulns are "fake AI slop" | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117349313638958333 |
| 53 | Beaumont, Sep 29 18:32 UTC - Dutch government shuts down all Citrix NetScalers (relaying @bert_hubert) | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117355758746619146 |
| 54 | BleepingComputer (Sep 29) - Hackers exploit Citrix NetScaler zero-day to deploy web shells | Press and vendor coverage | https://www.bleepingcomputer.com/news/security/hackers-exploit-citrix-netscaler-zero-day-to-deploy-web-shells/ |
| 55 | BleepingComputer (Sep 27) - Citrix admins warned to shut down NetScalers | Press and vendor coverage | https://www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/ |
| 56 | SecurityWeek (Sep 28) - Citrix confirms 2 NetScaler zero-days | Press and vendor coverage | https://www.securityweek.com/citrix-confirms-2-netscaler-zero-days-after-admins-pulled-the-plug/ |
| 57 | The Record (Sep 28) - US, UK warn of Citrix NetScaler zero-day bug | Press and vendor coverage | https://therecord.media/us-uk-warn-of-citrix-netscaler-zero-day-bug |
| 58 | CyberScoop (Sep 28) - delayed-disclosure angle | Press and vendor coverage | https://cyberscoop.com/citrix-zero-days-delayed-disclosure/ |
| 59 | Sophos CTU (Sep 28) - CVE-2026-88771 / -88772 in active exploitation | Press and vendor coverage | https://www.sophos.com/en-us/blog/citrix-netscaler-cve-2026-88771-cve-2026-88772-in-active-exploitation |
| 60 | Rapid7 ETR (Sep 28) | Press and vendor coverage | https://www.rapid7.com/blog/post/etr-zero-day-exploitation-of-citrix-netscaler-adc-and-gateway-cve-2026-88771-and-cve-2026-88772/ |
| 61 | watchTowr FAQ (Sep 27-28) | Press and vendor coverage | https://watchtowr.com/intelligence/citrix-netscaler-zero-day-vulnerabilities-faq/ |
| 62 | The Register (Sep 29) - Custom malware used in Citrix 0-day attacks targeting govt, banks, professional services | Press and vendor coverage | https://www.theregister.com/security/2026/09/29/custom-malware-used-in-citrix-0-day-attacks-targeting-govt-banks-professional-services/5299867 |
| 63 | Unit 42 (Palo Alto Networks) - NetScaler zero-days threat brief (Sep 27, updated Sep 28) | Press and vendor coverage | https://unit42.paloaltonetworks.com/netscaler-zero-days-exploited/ |
| 64 | Cybersecurity Dive (Sep 28) - Shadowserver: more than 20,000 instances exposed | Press and vendor coverage | https://www.cybersecuritydive.com/news/citrix-upgrades-netscaler-exploitation/831502/ |
| 65 | Help Net Security (Sep 29) - NetScaler zero-day exploitation escalates into mass attacks (Lupovis, Censys) | Press and vendor coverage | https://www.helpnetsecurity.com/2026/09/29/netscaler-zero-day-exploitation-escalates-into-mass-attacks-cve-2026-88771/ |
| 66 | Ingeniøren (Sep 30) - Alvorlige huller i kendt software: PET, Forsvaret og Politiet hastelukker systemer | Press and vendor coverage | https://ing.dk/artikel/alvorlige-huller-i-kendt-software-pet-forsvaret-og-politiet-hastelukker-systemer |
| 67 | SDxCentral (Sep 29) - NetScaler bugs bring critical sectors down in Europe (citing Techzine) | Press and vendor coverage | https://www.sdxcentral.com/news/netscaler-bugs-bring-critical-sectors-down-in-europe/ |
| 68 | Cybersecurity Dive (Sep 29) - Citrix NetScaler exploitation began days before public notification | Press and vendor coverage | https://www.cybersecuritydive.com/news/citrix-netscaler-exploitation-days-before-notification/831634/ |
| 69 | heise online (Sep 27) - New zero-day exploits in Citrix NetScaler | Press and vendor coverage | https://www.heise.de/en/news/Security-researchers-warn-New-zero-day-exploits-in-Citrix-Netscaler-11467269.html |
| 70 | Dark Reading (Sep 29) - Dual NetScaler Zero-Days Trigger Chaos for Citrix Customers | Press and vendor coverage | https://www.darkreading.com/vulnerabilities-threats/netscaler-zero-days-chaos-citrix |
| 71 | Omroep Brabant (Sep 27) - Storing bij ziekenhuizen door kritieke kwetsbaarheden in systeem (Amphia, ETZ, Z-CERT) | Press and vendor coverage | https://www.omroepbrabant.nl/nieuws/6028828/storing-bij-ziekenhuizen-door-kritieke-kwetsbaarheden-in-systeem |
| 72 | Maurice_Sec on X - notes from the field on NetScaler Console IoC scanner findings | Community | https://x.com/Maurice_Sec/status/2104541998858240487 |
| 73 | r/Citrix - "Netscaler leak?" thread (~Sep 26) | Community | https://www.reddit.com/r/Citrix/comments/1wqjk9a/netscaler_leak/ |