Ethical Hacking News
Critrix has confirmed two new NetScaler zero-day flaws that were exploited before patches were available, allowing hackers to remotely execute code and potentially gain control of affected appliances. The company has released updates and patches for the vulnerabilities and is providing Indicators of Compromise to help customers assess their deployments.
Two critical zero-day vulnerabilities in NetScaler ADC and Gateway appliances were exploited before patches were available. The first vulnerability, CVE-2026-88771, allows unauthenticated arbitrary code execution due to improper input validation. The second vulnerability, CVE-2026-88772, is a memory overflow that can lead to remote code execution or denial of service. NetScaler appliances are vulnerable due to their position in corporate networks, providing VPN and remote access, load balancing, and authentication. Citrix has released updates for the two exploited vulnerabilities and other security issues, with patches available in NetScaler ADC and Gateway 14.1-73.37 and later. Organizations are urged to install the relevant updated versions as soon as possible and prioritize their network security and regular patching.
Citrix has recently confirmed that two critical zero-day vulnerabilities in their NetScaler ADC and NetScaler Gateway appliances were exploited before patches were available. The flaws allow remote code execution, meaning attackers can potentially take control of affected appliances.
The first vulnerability, CVE-2026-88771, involves improper input validation and allows an unauthenticated attacker to execute arbitrary commands. This vulnerability affects all NetScaler ADC and NetScaler Gateway deployments in the affected versions without requiring an additional feature to be enabled.
The second flaw, CVE-2026-88772, is a memory overflow that can lead to remote code execution or denial of service. This vulnerability affects appliances with DTLS enabled, which is enabled by default for VPN virtual servers unless an administrator has explicitly disabled it.
NetScaler sits at a particularly sensitive point in many corporate networks, providing VPN and remote access, load balancing, and authentication. Compromising one of these appliances can give an attacker a useful position at the edge of an organization.
Citrix has released updates for the two exploited vulnerabilities, as well as patches for six other security issues. The company is also providing generic Indicators of Compromise (IoCs) through NetScaler Console to help customers quickly assess whether their NetScaler deployments may have been compromised.
The fixes are available in NetScaler ADC and Gateway 14.1-73.37 and later, as well as in the 13.1-64.23 and later releases. However, organizations that patched NetScaler last month using builds 14.1-73.32 and 13.1-63.21 should be aware that these earlier builds do not address the newly disclosed vulnerabilities.
Citrix strongly urges affected customers to install the relevant updated versions as soon as possible. The company warns that the IoCs do not cover all attacker techniques and may miss compromises, so experienced forensic investigators should be involved when needed.
In light of this recent incident, it is essential for organizations to prioritize their network security and ensure that their appliances are patched regularly. This includes keeping up-to-date with the latest security patches and vulnerability advisories, as well as implementing robust security measures to prevent and detect attacks.
Related Information:
https://www.ethicalhackingnews.com/articles/Citrix-NetScaler-Zero-Day-Flaws-Exploited-by-Hackers-ehn.shtml
https://securityaffairs.com/199873/security/citrix-confirmed-two-new-netscaler-flaws-exploited-as-zero-day.html
https://www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/
https://nvd.nist.gov/vuln/detail/CVE-2026-88771
https://www.cvedetails.com/cve/CVE-2026-88771/
https://nvd.nist.gov/vuln/detail/CVE-2026-88772
https://www.cvedetails.com/cve/CVE-2026-88772/
Published: Sun Sep 27 13:36:49 2026 by llama3.2 3B Q4_K_M