Cybereason is now LevelBlue. Proven endpoint protection, now with greater scale and expanded capabilities. Learn More

Citrix NetScaler Zero-Day Exploited Globally

On Sept 27, Citrix released patches for two critical vulnerabilities being exploited in the wild. Based on current information, we confirm there has been no exposure or impact to LevelBlue or our clients. CISA has already added these vulnerabilities to the Known Exploited Vulnerabilities (KEV) list.

"CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally," the agency said.

  • CVE-2026-88771 (CVSS score: 9.5) - An improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands.
  • CVE-2026-88772 (CVSS score: 9.5) - An improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution (RCE) or denial-of-service.

CVE-2026-88771 affects all NetScaler ADC and Gateway deployments. CVE-2026-88772 requires DTLS to be enabled on NetScaler ADC or NetScaler Gateway, an option that is enabled by default on VPN virtual servers.

 

Affected Versions

The following supported versions of Citrix NetScaler ADC and Citrix NetScaler Gateway are affected by the vulnerabilities:

  • Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 BEFORE 14.1-73.37
  • Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 BEFORE 13.1-64.23
  • Citrix NetScaler ADC FIPS BEFORE 14.1-73.37 FIPS
  • Citrix NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.279

Patches are available, and Citrix recommends affected customers upgrade as soon as possible.

Dedicated to hunting and eradicating the world's most challenging threats.

SpiderLabs

Exploit Analysis

According to an analysis by sh3llc0d3 before the patch release, the primary attack vector stems from how the NetScaler packet processing daemon handles malformed HTTP requests.

The packet processor gets tripped up when an attacker crafts an HTTP stream with overlapping block fragments. A bug in the processor fails to validate the reassembled stream size against the memory buffer assigned to it. A classic buffer overflow attack.

This vulnerability is then chained to a vulnerability in how the packet processor handles TLS traffic. This allows the attackers to overwrite the memory pointer through a fast succession of TLS handshakes. This bypasses ASLR memory protection and points to the place in the stack where the shellcode was staged with the HTTP vulnerability. This gives attackers full, arbitrary, unauthorized RCE.

Unconfirmed reports suggest exploitation in the wild may have begun as early as Sept 24th.

Citrix-exploit-analysis

 

Remediation

  • If possible, affected organizations should apply the official updates from Citrix.
  • Use regular access controls to isolate your NetScaler systems.
  • Revoke unused user accounts and reset authentication for active accounts.
  • Enable and collect all host and network logs of NetScaler and surrounding systems.

As a trusted security partner, LevelBlue is on heightened alert for our clients and partners and is monitoring for any suspicious activity. Should new information arise that alters this assessment, we will provide an update directly.

About the Author

Karl Sigler is Security Research Manager, SpiderLabs Threat Intelligence at LevelBlue. Karl is a 20-year infosec veteran responsible for research and analysis of current vulnerabilities, malware and threat trends at LevelBlue. Follow Karl on LinkedIn.

About LevelBlue

LevelBlue secures what's next with intelligence-led security delivering visibility and speed to stop threats faster. As the world’s largest and most analyst-recognized pure-play managed security services provider, our AI-powered managed services and cyber expertise across managed, advisory, and incident response services help clients operate with confidence. Learn more about us.

Discover how our specialists can tailor a security program to fit the needs of
your organization.

Request a Demo