{"id":9599,"date":"2026-09-28T10:02:08","date_gmt":"2026-09-28T10:02:08","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9599"},"modified":"2026-09-28T10:02:08","modified_gmt":"2026-09-28T10:02:08","slug":"netscaler-admins-told-to-patch-critical-zero-days-in-adc-and-gateway-now","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9599","title":{"rendered":"NetScaler admins told to patch critical zero-days in ADC and Gateway now"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">Citrix NetScaler ADC and NetScaler Gateway users should take their systems offline and patch them immediately, they were told over the weekend, as news emerged of two critical unauthenticated remote code execution <a href=\"https:\/\/www.csoonline.com\/article\/4155155\/the-zero-day-timeline-just-collapsed-heres-what-security-leaders-do-next.html\">zero-day<\/a> vulnerabilities in the products under active attack.<\/p>\n<p class=\"wp-block-paragraph\">\u201c<a href=\"https:\/\/www.linkedin.com\/feed\/update\/urn:li:activity:7509660925809819649\" target=\"_blank\" rel=\"noopener\">Monday will be too late<\/a>,\u201d watchtower CEO <a href=\"https:\/\/www.linkedin.com\/in\/benjamin-harris-sg\" target=\"_blank\" rel=\"noopener\">Benjamin Harris<\/a> wrote in a LinkedIn post on Sunday.<\/p>\n<p class=\"wp-block-paragraph\">Citrix subsequently confirmed the two remotely exploitable vulnerabilities were under attack, and released fixes for both. Affected customers should install the patched versions \u201cas soon as possible,\u201d <a href=\"https:\/\/community.citrix.com\/techzone-blogs\/110_security-updates\/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778\/\" target=\"_blank\" rel=\"noopener\">Citrix wrote in an advisory<\/a> issued later on Sunday.<\/p>\n<p class=\"wp-block-paragraph\">NetScaler appliances are an important part of many enterprise networks, providing VPN and remote access, load balancing and other application delivery services.<\/p>\n<p class=\"wp-block-paragraph\">Agnidipta Sarkar, chief evangelist at ColorTokens, said, \u201cRCE on these NetScaler deployments means an unauthenticated remote attacker can run arbitrary commands on the appliance itself, typically with high privileges. If that succeeds, attackers install persistent backdoors\/webshells, modify configurations, disable logging, create rogue virtual servers, or brick\/DOS the device.\u201d They could also pivot into the internal network and reach Active Directory or other crown jewels, he added.<\/p>\n<p class=\"wp-block-paragraph\"><a><\/a>Citrix is tracking the two exploited vulnerabilities as CVE-2026-88771 and CVE-2026-88772. It has released fixes in NetScaler ADC and Gateway 14.1-73.37 and later, 13.1-64.23 and later, with corresponding FIPS and NDcPP builds also available.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-88771\" target=\"_blank\" rel=\"noopener\">CVE-2026-88771<\/a> is a critical remote code execution (RCE) vulnerability in Netscaler ADC and Netscaler Gateway caused by improper input validation. With a CVSS rating of 9.5, it enables unauthenticated attackers to execute arbitrary commands on the appliance.<\/p>\n<p class=\"wp-block-paragraph\">Citrix said all NetScaler ADC and NetScaler Gateway deployments are affected, including default configurations, with no additional feature required to meet the vulnerability\u2019s precondition. It\u2019s barely <a href=\"https:\/\/www.csoonline.com\/article\/4212082\/citrix-issues-critical-security-updates-for-its-netscaler-devices.html\">a month since Citrix patched two other critical security holes<\/a> in the appliances<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-88772\" target=\"_blank\" rel=\"noopener\">CVE-2026-88772<\/a> also has a CVSS score of 9.5; it involves a memory overflow that can result in remote code execution or denial of service. It requires Datagram Transport Layer Security (DTLS) to be enabled, but Citrix notes that is the case by default on VPN virtual servers, making the condition relevant to many NetScaler Gateway deployments.<\/p>\n<p class=\"wp-block-paragraph\">Citrix said exploitation of both vulnerabilities had been observed on unmitigated deployments, while watchTowr reported the vulnerabilities had been <a href=\"https:\/\/watchtowr.com\/intelligence\/citrix-netscaler-adc-citrix-netscaler-gateway-remote-code-execution-cve-2026-88771\/\" target=\"_blank\" rel=\"noopener\">exploited before fixes became available<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">The US Cybersecurity and Infrastructure Security Agency (CISA) added both to its Known Exploited Vulnerabilities (KEV) catalog on Sunday.<\/p>\n<p class=\"wp-block-paragraph\">\u201cSince most attackers here will expect discovery, they might silently harvest credentials, especially VPN credentials, exfiltrate existing business data or any other data that is immediately available,\u201d Sarkar said, recommending taking systems offline and upgrading them immediately.<\/p>\n<h2 class=\"wp-block-heading\"><a><\/a>Six more Netscaler bugs<\/h2>\n<p class=\"wp-block-paragraph\">Citrix addressed six other vulnerabilities in Sunday\u2019s security update, although it said their exposure depends on specific configurations.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-88773\" target=\"_blank\" rel=\"noopener\">CVE-2026-88773<\/a>, rated 9.3, is an HTTP request-smuggling vulnerability affecting deployments using HTTP or SSL virtual servers. <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-88774\" target=\"_blank\" rel=\"noopener\">CVE-2026-88774<\/a>, rated 7.0, is a feature policy bypass related to HTTP URL handling; Citrix noted that URL normalization can prevent WAF and security rules from being bypassed.<\/p>\n<p class=\"wp-block-paragraph\">Three further memory-overflow vulnerabilities \u2014 <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-88775\" target=\"_blank\" rel=\"noopener\">CVE-2026-88775<\/a>, <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-88776\" target=\"_blank\" rel=\"noopener\">CVE-2026-88776<\/a> and <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-88777\" target=\"_blank\" rel=\"noopener\">CVE-2026-88777<\/a> \u2014 are each rated 8.8 and can cause unpredictable behavior or denial of service under their respective configurations.<\/p>\n<p class=\"wp-block-paragraph\">The final flaw, <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-88778\" target=\"_blank\" rel=\"noopener\">CVE-2026-88778<\/a>, is also rated 8.8 and involves TCP Initial Sequence Number Prediction which, Citrix said, can be handled by enabling Enhanced ISN Generation.<\/p>\n<p class=\"wp-block-paragraph\">Citrix said the advisory applies to customer-managed NetScaler appliances and recommended upgrading affected deployments immediately. The company also made generic indicators of compromise (IOCs) available through NetScaler Console to help customers assess whether their appliances may have been affected.<\/p>\n<p class=\"wp-block-paragraph\"><em>This article first appeared on <\/em><a href=\"https:\/\/www.networkworld.com\/article\/4227476\/netscaler-admins-told-to-patch-critical-zero-days-in-adc-and-gateway-now.html\">Network World<\/a><em>.<\/em><\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Citrix NetScaler ADC and NetScaler Gateway users should take their systems offline and patch them immediately, they were told over the weekend, as news emerged of two critical unauthenticated remote code execution zero-day vulnerabilities in the products under active attack. \u201cMonday will be too late,\u201d watchtower CEO Benjamin Harris wrote in a LinkedIn post on [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9595,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9599","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9599"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9599"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9599\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9595"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9599"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9599"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9599"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}