CISA Flags Exploited Citrix NetScaler Flaws, Urges Patching
Imazh i krijuar nga IA

CISA Flags Exploited Citrix NetScaler Flaws, Urges Patching

CISA added two critical Citrix NetScaler flaws to its known exploited list following global attacks. Federal agencies must patch by Sept 30, 2026.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has raised the alarm over two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway that attackers are actively exploiting worldwide. The agency added the flaws, tracked as CVE-2026-88771 and CVE-2026-88772, to its Known Exploited Vulnerabilities (KEV) catalog on September 29, 2026, after receiving threat intelligence and partner reports confirming ongoing attacks.

Both security holes carry the highest possible severity rating of 9.5 on the Common Vulnerability Scoring System (CVSS). CVE-2026-88771 stems from improper input validation and can allow an unauthenticated user to execute arbitrary commands on the affected device. The second vulnerability, CVE-2026-88772, is a memory buffer boundary restriction flaw that can lead to remote code execution or a denial-of-service. While the first flaw affects all NetScaler ADC and NetScaler Gateway installations, the second one is only exploitable when the Datagram Transport Layer Security (DTLS) protocol is active. Crucially, DTLS is enabled by default on VPN virtual servers, which means a large number of deployments are susceptible unless administrators have deliberately turned it off.

Citrix has released software updates to resolve both issues. The patched versions include NetScaler ADC and NetScaler Gateway 14.1-73.37 and later releases, version 13.1-64.23 and later of the 13.1 branch, NetScaler ADC 14.1-FIPS in release 14.1-73.37 FIPS and later, and NetScaler ADC 13.1-FIPS plus 13.1-NDcPP in version 13.1.37.279 and subsequent updates. Recognizing that applying firmware updates to networking appliances can involve complexity and planned downtime, CISA published the alert to help organizations assess their exposure and prioritize mitigation efforts.

Independent researchers at watchTowr Labs swiftly dissected CVE-2026-88771 and confirmed that the vulnerability is rooted in a Perl script named "ns_monuploadd_err.pl." This script handles crash and error reports on the NetScaler appliance. It constructs a shell command using input that comes from data written to the appliance’s log files. An attacker can send a specially crafted HTTP POST request to the "/nf/auth/doAuthentication.do" endpoint – a pre-authentication page – where the login field contains a payload that forces the script to run system commands. Because the injected data ends up in a log entry later processed by the vulnerable Perl script, the attacker’s commands execute with root privileges, granting full control over the device. The researchers demonstrated this by sending a request that wrote a harmless file to /var/tmp, confirming code execution. This trivial exploitation means that simply leaving an unpatched NetScaler exposed to the internet can lead to a full compromise without any prior credentials.

Given the active global exploitation, CISA has given U.S. federal civilian agencies a deadline of September 30, 2026, to apply the fixes. The agency also pointed to generic indicators of compromise (IoCs) that Citrix has distributed through the NetScaler Console to help administrators check whether their appliances have already been compromised. If a compromise is suspected, the recommended response includes preserving forensic evidence, isolating the affected appliance from the network, revoking all associated credentials and access rights, investigating any connected systems for signs of lateral movement, rebuilding and updating the firmware to the latest version, rotating all local account passwords and Key Encryption Keys, replacing any restored SSL certificates, and hardening the device according to Citrix’s security guidelines.

For website operators and businesses that depend on Citrix NetScaler for load balancing or secure remote access, the message is clear: verify the installed version immediately and apply the patch. Failure to do so exposes not only the appliance itself but also the web applications, sensitive data, and internal networks that sit behind it. Organizations that rely on managed hosting providers can offload some of this risk. AEU Hosting, for instance, secures managed WordPress environments end to end, ensuring that underlying infrastructure components are continuously monitored and patched by experts, which can shield site owners from having to chase down appliance-level vulnerabilities themselves.

Si të Mbroheni

  1. If your organization uses Citrix NetScaler for remote access or load balancing, ask your IT department to update the appliance right away.
  2. If you cannot apply the patch immediately, disconnect the device from the network to block any ongoing exploitation until you can fix it.
  3. After updating, change all passwords and secret keys associated with the NetScaler device, because attackers might have stolen them before the fix.
  4. Check the device logs for unusual error messages or commands, and if anything looks suspicious, get help from a security expert.
  5. Keep a current list of all hardware and software your website relies on so you can respond quickly when a critical security alert appears.
  6. Consider a managed hosting provider that handles server and network equipment updates for you, so you do not have to track every urgent patch yourself.

Dobësitë & Zgjidhjet

  • CVE-2026-88771 An improper input validation vulnerability in Citrix NetScaler ADC and Gateway that allows an unauthenticated attacker to execute arbitrary commands; fixed in versions 14.1-73.37 and later, 13.1-64.23 and later, and corresponding FIPS/NDcPP releases. Shiko zgjidhjen & detajet →
  • CVE-2026-88772 An improper restriction of operations within a memory buffer vulnerability in Citrix NetScaler ADC and Gateway that can lead to remote code execution or denial-of-service when DTLS is enabled; fixed in the same software versions as CVE-2026-88771. Shiko zgjidhjen & detajet →

Termat e Shpjeguar

  • CVE (Common Vulnerabilities and Exposures) A public list that assigns a unique identification number to each known software security flaw.
  • CVSS (Common Vulnerability Scoring System) A scale from 0 to 10 that rates how serious a security vulnerability is, where 10 is the most critical.
  • KEV (Known Exploited Vulnerabilities) A catalog maintained by CISA of software weaknesses that attackers are actively using right now.
  • NetScaler ADC (Application Delivery Controller) A piece of hardware or software that manages and speeds up the flow of data to websites and applications.
  • NetScaler Gateway A product that lets employees securely connect to work applications and desktops from outside the office.
  • DTLS (Datagram Transport Layer Security) A protocol that scrambles data sent over fast, lightweight internet connections so hackers cannot read it.
  • Command injection An attack where a hacker sneaks operating system instructions into a website or program to make the server run dangerous commands.

Shërbime AEU të lidhura

  • AEU-I Konsulencë IT dhe sigurie