مركز جمع المعلومات

معلومات التهديدات

Two unpatched NetScaler zero-days were already being exploited when researchers found them.

Security firm watchTowr uncovered CVE-2026-88771 and CVE-2026-88772 in Citrix NetScaler ADC and Gateway while investigating already-compromised customer environments. Citrix shipped patches on September 27, but one flaw affects every default deployment and carries a CVSS 4.0 score of 9.5.

هذا التقرير متاح بالإنجليزية فقط.

Dark, low-key rows of server hardware in a data center rack, evoking the network edge infrastructure at the center of the Citrix NetScaler zero-day story

Citrix confirmed active exploitation of two remote code execution vulnerabilities in NetScaler ADC and NetScaler Gateway on September 27. Security research firm watchTowr disclosed the flaws a day earlier, saying it identified them not through routine testing but while doing forensic work on customer environments that had already been breached. Citrix published security bulletin CTX697096 covering eight NetScaler flaws in total, with fixed builds available in 14.1-73.37, 13.1-64.23, and their FIPS/NDcPP counterparts.


NetScaler appliances sit at the network edge as VPN gateways and application delivery controllers, and they have been a recurring target for ransomware crews and state-linked intrusion sets going back to the 2023 Citrix Bleed campaign. An unauthenticated, pre-patch remote code execution flaw on that class of device gives an attacker a foothold before any monitoring tool has a signature for it. That watchTowr found these bugs by working backward from compromised customers, rather than the reverse, means some organizations were exploited before a CVE number existed to search for.


CVE-2026-88771 is an improper input validation flaw that lets an unauthenticated attacker execute arbitrary commands. It affects every NetScaler ADC and Gateway deployment running a vulnerable build, with no optional feature required to be exposed, so there is no configuration change that reduces exposure short of patching. CVE-2026-88772 is a memory overflow that can produce remote code execution or a denial of service, and it requires DTLS, the UDP-based TLS variant NetScaler enables by default on VPN virtual servers. Both carry a CVSS 4.0 score of 9.5.


Patch to build 14.1-73.37 or 13.1-64.23 (or the FIPS/NDcPP equivalents) immediately; CVE-2026-88771's default-configuration exposure means there is no interim mitigation that substitutes for the update. Where patching must be staged, disable DTLS on VPN virtual servers to remove the CVE-2026-88772 attack path in the meantime. Because both flaws were found via post-compromise forensics rather than proactive disclosure, treat any unpatched, internet-facing NetScaler appliance as a possible breach rather than a theoretical risk: review authentication logs, active sessions, and configuration files for signs of tampering, and rotate credentials and certificates exposed on the device once it is patched.

يتطلب صلاحية دخول.

سجل الأحداث المشفّر الكامل وإجراءات المعالجة متاحة بعد تسجيل الدخول.