50,000 NetScaler boxes exposed as UK joins Citrix alarm

Published

Palo Alto Networks' Unit 42 says it has counted 50,277 internet-exposed Citrix NetScaler instances that are potentially vulnerable to the two zero-days Citrix disclosed on September 27, 2026. The figure, taken from Cortex Xpanse telemetry as of that date, puts a number on a problem that has been growing by the hour: both flaws are already being exploited, and the UK's National Cyber Security Centre has now joined the US in raising the alarm.

That count matters because it is the size of the hunt, not just the size of the patch job. Every one of those appliances was reachable while the bugs were zero-days.

A day on, more agencies and more detail

IntelFusions reported yesterday that CISA had added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities catalog. Both carry a CVSS v4 score of 9.5. Since then, several research teams have filled in the picture:

Public technical detail on a default-configuration, pre-authentication bug tends to widen the pool of attackers quickly. Defenders who were waiting for a quieter moment to schedule downtime should assume that moment has passed.

The UK says isolate first, then investigate

The NCSC alert says it is working to understand the impact on UK organisations and sets out an order of operations that puts containment ahead of patching. Its priority actions are to read the Citrix bulletin and its indicators of compromise in full, isolate affected systems where possible (for example by blocking access with upstream firewalls or limiting access to the organisation's own IP range), investigate for compromise using the published indicators, and only then install the update and bring the system back. UK victims are asked to report compromises to the NCSC and to Citrix. More on the UK's posture is on our United Kingdom profile.

Preserve evidence, then patch to 14.1-73.37 or 13.1-64.23

Fixed releases are NetScaler ADC and Gateway 14.1-73.37 and 13.1-64.23 or later, 14.1-73.37 FIPS, and 13.1-37.279 FIPS and NDcPP. watchTowr notes that CVE-2026-88778, one of the six flaws not reported as exploited, is fixed by enabling Enhanced ISN Generation rather than by the upgrade alone.

Unit 42's interim guidance is to confirm exposure using the preconditions section of the Citrix advisory, isolate vulnerable systems, and preserve evidence before changing anything: a VPX instance snapshot, logs held on remote syslog servers and NetScaler Console, a technical support bundle and a packet engine core dump. It suggests hunting for suspicious administrative sessions, unexpected outbound connections and unexplained gaps in logging, while stressing these are general hunting leads, not behaviour it has tied to this campaign. The NCSC adds that NetScaler Console File Integrity Monitoring can flag unexpected changes to monitored files.

The pattern is familiar from every NetScaler wave before this one. The update closes the door, but an appliance that sat exposed through the zero-day window has to be treated as a crime scene first and a maintenance ticket second.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions