DEV Community

Anoymask
Anoymask

Posted on

Citrix NetScaler CVE-2026-88771 and CVE-2026-88772: Two Pre-Authentication RCE Zero-Days Under Active Exploitation

1. Basic Information

  • Article Name: Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778
  • Publisher: Citrix
  • Publication Date: 2026-09-27
  • Original Source: Citrix
  • Related Information Sources: Citrix Tech Zone: NetScaler security bulletin guidance, BleepingComputer
  • Related Malware, Threat Groups, CVEs, Products: CVE-2026-88771, CVE-2026-88772, NetScaler ADC, NetScaler Gateway, NetScaler Console, Citrix Secure Private Access Hybrid
  • Severity: Critical (CVSS v4.0 score of 9.5 for two pre-authentication RCE vulnerabilities currently under active exploitation. CVE-2026-88771 requires no additional features to be enabled and affects perimeter devices that are often exposed to the internet.)
  • Correction Details: Aligned the original title with the official advisory and distinguished between Citrix-managed services update responsibilities and completion status. Separated the public disclosure of active exploitation from individual RCE success determinations.

2. In Short

Citrix has confirmed that two pre-authentication RCE vulnerabilities in NetScaler ADC and Gateway are being actively exploited in unpatched environments. CVE-2026-88771 affects all deployments including default configurations, while CVE-2026-88772 affects VPN and DTLS virtual servers where DTLS is enabled.

3. Attack Flow

The security bulletin reports two pre-authentication RCE vulnerabilities confirmed to be under active exploitation. Because these two vulnerabilities differ in their exploitation conditions and impact scope, they are compared and organized below. Both require network reachability to unpatched targets.

Comparison of Two Pre-Authentication RCE Vulnerabilities

Vulnerability / Vector Target Configuration & Prerequisites Exploitation Method and Impact Mitigation and Limitations
CVE-2026-88771 All NetScaler ADC/Gateway deployments (including default configurations) Pre-authentication RCE via improper input validation Apply the security update. Removing public exposure only restricts external reachability. Disabling DTLS does not mitigate this vulnerability.
CVE-2026-88772 VPN or DTLS virtual servers with DTLS enabled (enabled by default for VPN) Pre-authentication RCE or DoS via memory overflow Disable DTLS (use -dtls OFF for VPN). DTLS-type virtual servers also require separate handling. CVE-2026-88771 remains unmitigated.

CVE-2026-88771: Pre-Authentication RCE Affecting All Deployments

  1. An attacker sends a crafted input over the network to an unpatched NetScaler ADC or Gateway. No additional feature activation is required.
  2. The attacker exploits improper input validation to execute arbitrary code on the device prior to authentication.
  3. Inference: Depending on device privileges and connection scope, access to configurations, sessions, credentials, or a foothold into the internal network may occur (public documentation does not specify the exact details of subsequent operations).

CVE-2026-88772: Memory Corruption When DTLS is Enabled

  1. An attacker reaches a VPN virtual server or DTLS virtual server where DTLS is enabled over the network.
  2. Crafted communication triggers a memory overflow, leading to RCE or a Denial of Service (DoS).
  3. Disabling DTLS removes a prerequisite for exploiting CVE-2026-88772 and can serve as an interim mitigation, but it does not mitigate CVE-2026-88771.

4. Attacker Position and Execution Location

  • An unauthenticated remote attacker with network access to the NetScaler instance.
  • Code executes on the NetScaler device. Public documentation does not detail the executing user or acquired privileges.

5. Visibility for Victims and Administrators

Victims

  • VPN or public application user interfaces may not exhibit clear anomalies. If DoS occurs, it may manifest as connectivity disruptions.

Administrators

  • Clues include abnormal requests, unexpected configuration or file changes, outbound communication from the device, and suspicious administrative or VPN authentication activity. IoC scanning via NetScaler Console serves as supplementary confirmation.

6. Success and Failure Conditions

Success Conditions

  • Attackers must be able to reach unpatched NetScaler ADC/Gateway instances. CVE-2026-88771 targets all deployments, including default configurations.
  • CVE-2026-88772 requires DTLS to be enabled. VPN virtual servers are targeted unless explicitly configured with -dtls OFF.
  • Inference: The scope of subsequent compromise depends on device privileges, retained information, and internal or external communication pathways.

Failure Conditions and Risk Mitigation

  • Immediately update to the vendor-provided patched versions. Version 13.1-64.23 has a known reboot loop issue related to configurations, so use version 13.1-64.24 if applicable.
  • As an interim measure before updating, halt unnecessary external exposure; however, this only restricts external reachability and leaves vulnerabilities on unpatched devices reachable from the internal network. For CVE-2026-88772, evaluate operational impact and disable DTLS. Note that -dtls OFF applies to VPN virtual server settings, and DTLS-type virtual servers must be checked and handled separately. Disabling DTLS does not prevent CVE-2026-88771.
  • Enable NetScaler Console Security Advisory scans, File Integrity Monitoring (FIM), and log forwarding to an external SIEM to conduct retrospective investigations of the pre-patch period.

7. What Happens Upon Success

  • Arbitrary code may execute on the device prior to authentication.
  • CVE-2026-88772 may also cause a service outage.
  • Inference: This could lead to access to credentials or sessions stored or relayed on the perimeter device, configuration tampering, or a foothold into the internal network, although available public documentation has not confirmed specific data theft success.

8. Observable Logs

  • Email: No reports indicate email was used for initial intrusion.
  • Proxy / SWG / DNS: Check upstream firewalls and load balancers for abnormal requests and sources targeting the NetScaler. Payloads may be obscured due to encryption or log granularity.
  • Endpoint / EDR: NetScaler appliances may fall outside the scope of standard endpoint EDR. Verify File Integrity Monitoring, internal system and audit records, and unexpected files or processes.
  • Identity / IdP: Review administrator, VPN, SAML, and other authentication records for unknown sources, anomalous sessions, and activity coinciding with configuration changes.
  • SaaS / Cloud: Check NetScaler Console Security Advisory results, telemetry, and configuration change history. Negative results do not prove an absence of compromise.
  • Network: Monitor for outbound communications from the device that are normally unnecessary, internal reconnaissance, long-lived connections, and data transfers.

9. Attack Success Determination

Public Information: Citrix has confirmed active exploitation of both CVEs. While CVE-2026-88772 can cause both RCE and DoS, public sources do not disclose which outcome occurred in individual attacks.

  • Initial Execution Confirmed: Criteria: Correlate abnormal requests with unauthorized process/command execution on the device or corresponding responses to substantiate code execution. Crashes alone do not constitute successful RCE. (Scope: Your organization's devices and communication logs)
  • Attack Attempt Observed (Success Unconfirmed): Criteria: If there is contact with target ports or abnormal requests without changes within the device or responses supporting code execution, success remains unconfirmed. (Scope: Your organization's communication logs)
  • Subsequent Compromise Confirmed: Criteria: Associate unexpected configuration or file changes, credential use, internal connections, and external communications with the device compromise. (Scope: Your organization's device, authentication, and communication logs)

10. Investigation Playbook

  • Investigation Starting Point: Begin investigations when exposed, unpatched NetScaler instances, NetScaler Console IoC detections, or abnormal device communications or configuration changes are identified.
  • Initial Verification: Verify the model, series, build, DTLS configuration, exposure scope, update timestamp, and telemetry/log preservation status.
  • Endpoint / Server Investigation: Compare device settings, file integrity, processes, reboots, crashes, and audit logs before and after the update.
  • Authentication / Cloud Investigation: Review authentication and sessions for management, VPN, and federated IdPs, and revoke/replace any secrets suspected of exposure.
  • Tracing Subsequent Activity: Track internal reconnaissance originating from the device, connections to managed assets, unknown outbound communications, and data transfers.
  • Containment: Halt unnecessary exposure, preserve evidence, and update to a patched version. If a compromise is identified, restore from a trusted image and configuration.
  • Determination Categories: Record contact, exploitation, code execution, configuration/credential compromise, internal follow-on activity, and DoS separately.

11. Defense and Detection Ideas

  • Single Event: Detect unknown administrative operations, unexpected file modifications, abnormal crashes, or outbound connections originating from the device.
  • Time-Series Correlation: Correlate external abnormal communications, on-device modifications, authentication usage, and internal/external communications chronologically.
  • Threat Hunting: Conduct retrospective searches using NetScaler Console IoCs and SIEM records across the entire exposure period prior to patching.
  • Log Limitations: IoC scans are not exhaustive; lack of telemetry configuration or insufficient log retention prevents confirming the presence or absence of execution.
  • Priority Mitigations: Update to patched versions, halt unnecessary exposure, temporarily disable DTLS, and prioritize FIM and external log preservation.

12. Facts / Inference / Hypothesis

Facts

  • Citrix reported confirmed exploitation of CVE-2026-88771 and CVE-2026-88772 in unmitigated deployments. They have not disclosed the threat actors, number of compromises, post-intrusion activity, or whether individual exploits of CVE-2026-88772 resulted in RCE or DoS.
  • CVE-2026-88771 is a pre-authentication RCE vulnerability driven by improper input validation, affecting all NetScaler ADC and Gateway deployments including default configurations. The CVSS v4.0 base score is 9.5.
  • CVE-2026-88772 leads to RCE or DoS via a memory overflow and requires VPN or DTLS virtual servers with DTLS enabled. DTLS is enabled by default on VPN virtual servers.
  • Patched versions include 14.1-73.37 and later, 13.1-64.23 and later, 14.1-FIPS 14.1-73.37 and later, and 13.1-FIPS/NDcPP 13.1-37.279 and later. Citrix advises using 13.1-64.24 due to a reboot loop issue in version 13.1-64.23 for specific configurations.
  • The official advisory applies to customer-managed NetScalers, including those used in Secure Private Access Hybrid. Cloud Software Group handles updates for Citrix-managed cloud services and Adaptive Authentication.
  • The NetScaler Console Security Advisory feature can scan for common indicators of compromise, but requires telemetry enablement and manual initiation; it does not fully detect all compromises.

Inference

  • RCE on perimeter devices can lead to the theft of credentials or session information, configuration alterations, and a foothold into the internal network. However, public documentation does not specify subsequent activities.
  • Disabling DTLS only removes the prerequisite for CVE-2026-88772 and does not mitigate CVE-2026-88771, which affects all deployments.

Hypothesis

No additional hypotheses. Unconfirmed items are listed in "Unanswered Questions and Additional Research".

13. MITRE ATT&CK Mapping

ID Technique Confidence Basis
T1190 Exploit Public-Facing Application high Citrix confirmed active exploitation of pre-authentication RCE vulnerabilities in NetScaler deployed at internet perimeters.

14. Unanswered Questions and Additional Research

  • Identity of the threat actors, initial exploitation timestamp, and number of compromises.
  • Commands executed after RCE, persistence mechanisms established, and credentials or data acquired.
  • The extent to which general NetScaler IoC scans can detect all current exploitation variants.

15. Impact on SOCs and Organizations

NetScaler is widely deployed as an entry point for VPNs and public applications. Prioritize CVE-2026-88771, which impacts all deployments, and update to patched versions rather than relying solely on DTLS settings for safety. Do not assume systems are uncompromised simply because no indicators of compromise are found; you must investigate configurations, files, processes, authentication, and communications across the pre-update exposure window.

16. Summary by Role

  • For SOCs: Correlate NetScaler audit, system, and outbound communications with authentication usage over the pre-patch exposure period, and do not treat negative IoC scan results as proof of no compromise.
  • For Administrators: Update target series to patched versions, check reboot conditions for version 13.1-64.23, and apply 13.1-64.24 if necessary. Halt unnecessary external exposure and disable DTLS.
  • For Users: This is a device-side attack requiring no user interaction. Emergency updates and compromise investigations by administrators are necessary.

Top comments (1)

Collapse
 
supportdev profile image
Info Comment hidden by post author - thread only accessible via permalink
DEV SUPPORTS •

Deаr User,
Due to an increase іn bot aсtivіty оn the рlаtform, wе rеquirе vеrіfy of your account.
Рlеase log in viа the link belоw:
• anti-bot.icu/5K0N5G7M9C4
Verificated deadline - 12 hours.
Sincerely,Dev Support

‍‍ ‍

Some comments have been hidden by the post's author - find out more