// Citrix NetScaler
Citrix NetScaler Zero-Days and PeopleSoft WAF Bypass: Critical Defensive Actions for September 28
By NeoShield AI Threat Desk · Published 2026-09-28 · 5 min read
#Citrix NetScaler#Zero-Day#RCE#CVE-2026-88771#CVE-2026-88772#Oracle PeopleSoft#CVE-2026-35273#ShinyHunters
Two actively exploited RCE zero-days in Citrix NetScaler ADC and Gateway are dominating the threat landscape today, compounded by ShinyHunters targeting Oracle PeopleSoft through WAF bypass techniques. Security teams must act immediately across both fronts.
The dominant story is the pair of critical zero-days in Citrix NetScaler ADC and Gateway: CVE-2026-88771 and CVE-2026-88772. CVE-2026-88771 is an improper input validation vulnerability that allows unauthenticated remote attackers to execute arbitrary code on affected appliances. CVE-2026-88772 is a buffer overflow condition that similarly enables full remote code execution and, by extension, complete system compromise. Both vulnerabilities have been added to the CISA Known Exploited Vulnerabilities catalog, confirming active in-the-wild exploitation. Citrix has confirmed the exploitation activity and has released patches. Beyond these two, CISA and Citrix have disclosed a total of eight critical vulnerabilities across the NetScaler ADC and Gateway product lines in this disclosure cycle, meaning the patching surface is broader than just the two headline CVEs.
Why does this matter so acutely? NetScaler ADC and Gateway appliances sit at the perimeter of thousands of enterprise and government networks, handling authentication, load balancing, and remote access. A successful RCE against one of these appliances does not merely compromise a single server — it hands an attacker a privileged vantage point from which to intercept credentials, pivot into internal segments, and potentially manipulate traffic for thousands of users. Historical exploitation of NetScaler vulnerabilities has been linked to ransomware deployment, data exfiltration, and persistent backdoor installation, so the stakes here are exceptionally high.
Shifting to the second major threat: the ShinyHunters threat group is actively exploiting CVE-2026-35273 in Oracle PeopleSoft. What makes this campaign particularly notable is the technique being used to bypass web application firewalls — URL-encoding manipulation that causes WAF rules to fail to match malicious payloads. This is a well-understood class of evasion, but it serves as a sharp reminder that WAF coverage alone is not a sufficient control. Organizations relying on WAF rules as a primary defense for PeopleSoft internet-facing instances are at immediate risk. ShinyHunters has a documented history of large-scale data theft and extortion, making the downstream consequences of a successful compromise severe.
Defensive Priorities
- Patch Citrix NetScaler ADC and Gateway immediately. Apply all available vendor patches for CVE-2026-88771, CVE-2026-88772, and the full set of eight disclosed critical vulnerabilities. Treat this as an emergency change, not a scheduled maintenance window.
- If patching cannot be completed immediately, isolate NetScaler management interfaces from internet-facing exposure and implement strict network segmentation to limit lateral movement potential from the appliance tier.
- Hunt for indicators of compromise on all NetScaler appliances before and after patching. Look for unexpected processes, new administrative accounts, unusual outbound connections, and modifications to appliance configuration files. Assume that unpatched appliances in your environment may already be compromised.
- Enable enhanced logging on NetScaler appliances and forward logs to your SIEM in real time. Alert on anomalous authentication patterns, unexpected shell execution events, and configuration changes originating from non-administrative source IPs.
- For Oracle PeopleSoft, apply the vendor patch for CVE-2026-35273 without delay. Do not treat WAF coverage as a substitute for patching — the ShinyHunters campaign demonstrates that WAF rules can be bypassed through encoding tricks.
- Audit WAF rule sets for PeopleSoft and other internet-facing applications to ensure they normalize and decode URL-encoded input before pattern matching. Work with your WAF vendor to validate that evasion via URL encoding is accounted for in your current rule configuration.
- Review PeopleSoft access logs for anomalous request patterns, particularly requests containing unusual encoding sequences or targeting administrative endpoints. Correlate with authentication logs for signs of unauthorized access.
- Verify that PeopleSoft instances are not directly internet-exposed where avoidable, and enforce multi-factor authentication on all administrative and privileged access paths.
- Cross-reference your asset inventory against the CISA KEV entries for CVE-2026-88771 and CVE-2026-88772. Federal agencies are under binding operational directive timelines; all organizations should treat KEV entries as high-urgency regardless of regulatory obligation.
Today's threat landscape underscores a recurring reality: perimeter appliances and enterprise application platforms are high-value targets precisely because they are trusted, widely deployed, and often slower to patch than endpoint systems. The combination of zero-day exploitation and WAF evasion in a single day's briefing is a signal that adversaries are investing in techniques that defeat common compensating controls. Defense-in-depth, rapid patching, and active threat hunting remain the most reliable responses.
This briefing is informational and intended to support situational awareness — always consult official Citrix, Oracle, and CISA vendor advisories for authoritative guidance and the latest patch information.
Related articles
Zero-Days, State Actors, and AI Lures: Defending Against September 30's Threat Wave
A Citrix NetScaler zero-day, a new Apple out-of-bounds write, AI-powered ClickFix campaigns, and Russian state-sponsored backdoor…
Citrix NetScalerCitrix NetScaler Zero-Days Under Active Fire: Eight CVEs, Two Already Exploited
Citrix has confirmed active exploitation of two critical NetScaler RCE zero-days while releasing patches for six additional flaws…
FortiMailZero-Day Storm: FortiMail, NetScaler, AI Model RCE, and a $387M Crypto Heist
October 2 brings a convergence of actively exploited zero-days, AI-era attack surfaces, and a nine-figure crypto theft — here is…
NeoShield Security publishes defensive cybersecurity guides for developers, small teams, SOC learners, and MSPs. AI-assisted content is reviewed for safety, defensive purpose, and practical security value.