Select your language

WHAT ARE YOU LOOKING FOR?

Popular Tags

Raleigh, NC

32°F
Clear Sky Humidity: 60%
Wind: 1.54 M/S

Global Exploitation of Two High-Severity Citrix NetScaler Flaws Prompts CISA Advisory

Global Exploitation of Two High-Severity Citrix NetScaler Flaws Prompts CISA Advisory

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway appliances to its Known Exploited Vulnerabilities (KEV) catalog after confirming that threat actors are actively exploiting the flaws in real-world attacks.

The vulnerabilities include:

  • CVE-2026-88771 (CVSS 9.5): An improper input validation flaw that could enable an unauthenticated attacker to execute arbitrary commands on vulnerable systems.
  • CVE-2026-88772 (CVSS 9.5): A memory buffer handling vulnerability that may allow attackers to achieve remote code execution (RCE) or trigger a denial-of-service (DoS) condition.

While CVE-2026-88771 impacts all deployments of Citrix NetScaler ADC and NetScaler Gateway, CVE-2026-88772 only affects systems with Datagram Transport Layer Security (DTLS) enabled, a setting that is activated by default on VPN virtual servers.

Example configuration:

 ( add vpn vserver vpn1 SSL 10.0.0.0 443 -Listenpolicy NONE)

Patched Versions

Citrix has released fixes for both vulnerabilities in the following versions:

  • Citrix NetScaler ADC and Gateway 14.1-73.37 and later
  • Citrix NetScaler ADC and Gateway 13.1-64.23 and later
  • Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later
  • Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.279 and later releases

According to CISA, intelligence from partners and incident reports confirms that attackers are exploiting these vulnerabilities globally.

The agency noted that patching NetScaler appliances can be operationally challenging and may require service interruptions. As a result, the alert was issued to help organizations quickly evaluate their exposure, prioritize remediation efforts, and incorporate the risks into their ongoing security management programs.

Recommended Response Actions

Citrix has published generic indicators of compromise (IoCs) through the NetScaler Console to assist customers in identifying potentially impacted systems. Organizations that suspect compromise should immediately:

  1. Preserve forensic evidence from affected NetScaler ADC VPX instances.
  2. Isolate impacted devices from the network.
  3. Revoke potentially compromised credentials and access privileges.
  4. Investigate connected servers and systems for signs of lateral movement or additional compromise.
  5. Rebuild affected appliances and upgrade to the latest firmware versions.
  6. Rotate all local account passwords and Key Encryption Keys (KEKs).
  7. Replace restored SSL certificates when recovering from backups.
  8. Harden systems according to Citrix security best practices.

Due to the active exploitation of these vulnerabilities, Federal Civilian Executive Branch (FCEB) agencies have been directed to apply the necessary updates no later than September 30, 2026.

Technical Analysis of CVE-2026-88771

Researchers at watchTowr Labs disclosed additional details on September 28, 2026, revealing that CVE-2026-88771 originates from a Perl script called ns_monuploadd_err.pl, which is responsible for processing NetScaler crash and error data.

The researchers discovered that the script builds shell commands using input that can be manipulated by an attacker. By injecting specially crafted data into NetScaler logs, an unauthenticated threat actor can cause malicious commands to be executed with root privileges, resulting in full remote code execution.

The attack chain relies on triggering the vulnerable code path through a pre-authentication request sent to the following endpoint:

  (/nf/auth/doAuthentication.do)

Because the flaw can be exploited before authentication and potentially grants root-level access, it represents a significant threat to internet-facing NetScaler deployments and should be prioritized for immediate remediation.

Found this article interesting? Follow us on X(Twitter) ,Threads and FaceBook to read more exclusive content we post. 

Cybersecurity Insight delivers timely updates on global cybersecurity developments, including recent system breaches, cyber-attacks, advancements in artificial intelligence (AI), and emerging technology innovations. Our goal is to keep viewers well-informed about the latest trends in technology and system security, and how these changes impact our lives and the broader ecosystem

Please fill the required field.