DEV Community

Mark0
Mark0

Posted on

Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation

Citrix has confirmed the active exploitation of two critical remote code execution (RCE) vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and NetScaler Gateway products. These flaws, including improper input validation and a memory overflow, allow unauthenticated attackers to run arbitrary commands or cause denial-of-service, particularly where DTLS is enabled. The bulletin follows reports from security firm watchTowr and concerns from administrators, indicating these vulnerabilities were exploited as zero-days before fixes were publicly available.

Urgent patching is advised for all affected versions, including those previously updated for other flaws. However, given past incidents where attackers maintained access post-patch, Citrix recommends comprehensive post-compromise actions. These include isolating affected appliances, preserving evidence, resetting credentials, revoking certificates, and ensuring management interfaces are not exposed to the internet. Additionally, six other non-exploited vulnerabilities were addressed in the same update cycle.

The historical guidance from the Netherlands' National Cyber Security Centre (NCSC) on NetScaler compromises further emphasizes the need for post-patch integrity checks using provided scripts, as patching alone might not eradicate persistent threats. This highlights the severe implications of these vulnerabilities, urging organizations to not only update promptly but also to conduct thorough forensic and remediation efforts.


Read Full Article

Top comments (0)