NetScaler admins told to patch critical zero-days in ADC and Gateway now

CSO Online ·

NetScaler admins told to patch critical zero-days in ADC and Gateway now

Citrix NetScaler ADC and NetScaler Gateway users should take their systems offline and patch them immediately, they were told over the weekend, as news emerged of two critical unauthenticated remote code execution zero-day vulnerabilities in the products under active attack. “ Monday will be too late ,” watchtower CEO Benjamin Harris wrote in a LinkedIn post on Sunday. Citrix subsequently confirmed the two remotely exploitable vulnerabilities were under attack, and released fixes for both. Affected customers should install the patched versions “as soon as possible,” Citrix wrote in an advisory issued later on Sunday. NetScaler appliances are an important part of many enterprise networks, providing VPN and remote access, load balancing and other application delivery services. Citrix is tracking the two exploited vulnerabilities as CVE-2026-88771 and CVE-2026-88772. It has released fixes in NetScaler ADC and Gateway 14.1-73.37 and later, 13.1-64.23 and later, with corresponding FIPS and NDcPP builds also available. CVE-2026-88771 is a critical remote code execution (RCE) vulnerability in Netscaler ADC and Netscaler Gateway caused by improper input validation. With a CVSS rating of 9.5, it enables unauthenticated attackers to execute arbitrary commands on the appliance. Citrix said all NetScaler ADC and NetScaler Gateway deployments are affected, including default configurations, with no additional feature required to meet the vulnerability’s precondition. It’s barely a month since Citrix patched two other critical security holes in the appliances CVE-2026-88772 also has a CVSS score of 9.5; it involves a memory overflow that can result in remote code execution or denial of service. It requires Datagram Transport Layer Security (DTLS) to be enabled, but Citrix notes that is the case by default on VPN virtual servers, making the condition relevant to many NetScaler Gateway deployments. Citrix said exploitation of both vulnerabilities had been observed on unmitigated deployments, while watchTowr reported the vulnerabilities had been exploited before fixes became available . The US Cybersecurity and Infrastructure Security Agency (CISA) added both to its Known Exploited Vulnerabilities (KEV) catalog on Sunday. Six more Netscaler bugs Citrix addressed six other vulnerabilities in Sunday’s security update, although it said their exposure depends on specific configurations. CVE-2026-88773 , rated 9.3, is an HTTP request-smuggling vulnerability affecting deployments using HTTP or SSL virtual servers. CVE-2026-88774 , rated 7.0, is a feature policy bypass related to HTTP URL handling; Citrix noted that URL normalization can prevent WAF and security rules from being bypassed. Three further memory-overflow vulnerabilities — CVE-2026-88775 , CVE-2026-88776 and CVE-2026-88777 — are each rated 8.8 and can cause unpredictable behavior or denial of service under their respective configurations. The final flaw, CVE-2026-88778 , is also rated 8.8 and involves TCP Initial Sequence Number Prediction which, Citrix said, can be handled by enabling Enhanced ISN Generation. Citrix said the advisory applies to customer-managed NetScaler appliances and recommended upgrading affected deployments immediately. The company also made generic indicators of compromise (IOCs) available through NetScaler Console to help customers assess whether their appliances may have been affected. This article first appeared on Network World .

Citrix NetScaler ADC and NetScaler Gateway users should take their systems offline and patch them immediately, they were told over the weekend, as news emerged of two critical unauthenticated remote code execution zero-day vulnerabilities in the products under active attack. “ Monday will be too late ,” watchtower CEO Benjamin Harris wrote in a LinkedIn post on Sunday. Citrix subsequently confirmed the two remotely exploitable vulnerabilities were under attack, and released fixes for both. Affected customers should install the patched versions “as soon as possible,” Citrix wrote in an advisory issued later on Sunday. NetScaler appliances are an important part of many enterprise networks, providing VPN and remote access, load balancing and other application delivery services. Citrix is tracking the two exploited vulnerabilities as CVE-2026-88771 and CVE-2026-88772. It has released fixes in NetScaler ADC and Gateway 14.1-73.37 and later, 13.1-64.23 and later, with corresponding FIPS and NDcPP builds also available. CVE-2026-88771 is a critical remote code execution (RCE) vulnerability in Netscaler ADC and Netscaler Gateway caused by improper input validation. With a CVSS rating of 9.5, it enables unauthenticated attackers to execute arbitrary commands on the appliance. Citrix said all NetScaler ADC and NetScaler Gateway deployments are affected, including default configurations, with no additional feature required to meet the vulnerability’s precondition. It’s barely a month since Citrix patched two other critical security holes in the appliances CVE-2026-88772 also has a CVSS score of 9.5; it involves a memory overflow that can result in remote code execution or denial of service. It requires Datagram Transport Layer Security (DTLS) to be enabled, but Citrix notes that is the case by default on VPN virtual servers, making the condition relevant to many NetScaler Gateway deployments. Citrix said exploitation of both vulnerabilities had been observed on unmitigated deployments, while watchTowr reported the vulnerabilities had been exploited before fixes became available . The US Cybersecurity and Infrastructure Security Agency (CISA) added both to its Known Exploited Vulnerabilities (KEV) catalog on Sunday. Six more Netscaler bugs Citrix addressed six other vulnerabilities in Sunday’s security update, although it said their exposure depends on specific configurations. CVE-2026-88773 , rated 9.3, is an HTTP request-smuggling vulnerability affecting deployments using HTTP or SSL virtual servers. CVE-2026-88774 , rated 7.0, is a feature policy bypass related to HTTP URL handling; Citrix noted that URL normalization can prevent WAF and security rules from being bypassed. Three further memory-overflow vulnerabilities — CVE-2026-88775 , CVE-2026-88776 and CVE-2026-88777 — are each rated 8.8 and can cause unpredictable behavior or denial of service under their respective configurations. The final flaw, CVE-2026-88778 , is also rated 8.8 and involves TCP Initial Sequence Number Prediction which, Citrix said, can be handled by enabling Enhanced ISN Generation. Citrix said the advisory applies to customer-managed NetScaler appliances and recommended upgrading affected deployments immediately. The company also made generic indicators of compromise (IOCs) available through NetScaler Console to help customers assess whether their appliances may have been affected. This article first appeared on Network World .

Источник: CSO Online