CISA flags actively exploited Citrix NetScaler flaws requiring urgent patching
CISA added two critical Citrix NetScaler vulnerabilities to its KEV catalog due to active global exploitation, urging immediate patching and incident response.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has officially added two critical vulnerabilities affecting Citrix NetScaler ADC and Gateway appliances to its Known Exploited Vulnerabilities (KEV) catalog. This directive, issued on Sunday, September 28, 2026, follows confirmed reports of active exploitation by threat actors across global networks. Organizations relying on these network appliances for application delivery and secure remote access must treat this alert as a high-priority security incident.
What happened
CISA identified two specific flaws, CVE-2026-88771 and CVE-2026-88772, both carrying a severe CVSS score of 9.5. The agency stated that partner threat intelligence confirms attackers are actively leveraging these weaknesses in the wild. Because patching Citrix NetScaler appliances often involves complex procedures and potential service downtime, CISA issued this alert to help organizations assess their exposure and prioritize mitigation efforts within their risk-management frameworks.
The first vulnerability, CVE-2026-88771, is an improper input validation flaw that allows unauthenticated attackers to execute arbitrary commands on the target system. This issue affects all deployments of NetScaler ADC and NetScaler Gateway, making it a universal threat for users of these products. The second vulnerability, CVE-2026-88772, involves an improper restriction of operations within the bounds of a memory buffer. This flaw can lead to remote code execution or denial-of-service conditions. Unlike the first flaw, CVE-2026-88772 requires the DTLS configuration to be enabled on the NetScaler ADC or Gateway. This setting is turned on by default for VPN virtual servers, meaning many standard configurations are exposed without additional administrative changes.
Federal Civilian Executive Branch (FCEB) agencies have been given a strict deadline of September 30, 2026, to apply the necessary fixes. While private sector organizations do not face the same regulatory deadline, the active nature of the exploitation suggests that delay increases the likelihood of compromise. Citrix has released patches addressing both issues in specific software versions, including releases 14.1-73.37 and later, as well as 13.1-64.23 and later for the 13.1 branch. FIPS and NDcPP variants also have corresponding updated releases available.
How it works
Technical analysis provided by watchTowr Labs on September 28, 2026, reveals the mechanical root cause of CVE-2026-88771. The vulnerability resides in a Perl script named "ns_monuploadd_err.pl," which is designed to process crash and error information generated by the NetScaler system. The script constructs shell commands using input data that can be influenced by an external attacker. Specifically, the script takes data written to logs and feeds it as input to a shell command without adequate sanitization.
This design flaw enables a classic command injection attack. An unauthenticated attacker can inject arbitrary shell commands through data that the NetScaler writes to its logs. When the processing script executes, it runs these injected commands with root privileges, leading to full remote code execution. WatchTowr Labs demonstrated that this exploit can be triggered by sending a pre-authentication request to the "/nf/auth/doAuthentication.do" endpoint. By crafting a specific POST request with malicious payload data in the login parameter, an attacker can bypass authentication checks and execute system commands directly.
The second vulnerability, CVE-2026-88772, relates to memory buffer handling. While the source article does not provide the same level of script-level detail for this flaw, it identifies the condition as an improper restriction of operations within memory bounds. This type of vulnerability typically allows attackers to overwrite adjacent memory locations, potentially altering program execution flow or crashing the service. Since DTLS is enabled by default on VPN virtual servers, the attack surface for this memory corruption issue is widely present in typical deployments.
Key details
- CVE-2026-88771: Improper input validation allowing unauthenticated remote code execution via command injection in a Perl error-handling script.
- CVE-2026-88772: Memory buffer restriction flaw allowing remote code execution or denial-of-service, exploitable when DTLS is enabled.
- Default Exposure: CVE-2026-88772 affects systems with DTLS enabled, which is the default configuration for NetScaler VPN virtual servers.
- Patched Versions: Fixes are available in NetScaler ADC/Gateway 14.1-73.37+, 13.1-64.23+, and corresponding FIPS/NDcPP releases.
- Active Exploitation: CISA confirms global active exploitation, with FCEB agencies required to patch by September 30, 2026.
- Root Cause: CVE-2026-88771 is triggered via the "/nf/auth/doAuthentication.do" endpoint using crafted log data that injects shell commands.
Why it matters
For engineering teams and IT leaders, this alert highlights the persistent risk associated with complex network appliances that sit at the edge of the infrastructure. NetScaler devices often handle critical traffic routing and authentication, making them high-value targets. The fact that one of these vulnerabilities allows unauthenticated access means that attackers do not need valid credentials to initiate an attack. This bypasses many traditional perimeter defenses that rely on identity verification, exposing the internal network to immediate compromise if the appliance is internet-facing.
The complexity of patching these appliances also poses a significant operational challenge. As CISA noted, updates may require downtime and careful planning. This creates a tension between security urgency and service availability. Teams must balance the risk of active exploitation against the potential disruption of applying patches to live production environments. Furthermore, the presence of active exploitation means that waiting for a maintenance window could result in a breach. Organizations must have incident response plans ready, including the ability to isolate devices and rotate credentials quickly if compromise is suspected.
What you can do
- Verify Version: Immediately check your NetScaler ADC and Gateway instances against the patched version numbers provided by Citrix.
- Apply Patches: Schedule emergency maintenance to upgrade to 14.1-73.37, 13.1-64.23, or later releases as soon as possible.
- Check IoCs: Use NetScaler Console to review generic indicators of compromise and determine if your deployment has already been impacted.
- Isolate if Compromised: If you suspect a breach, isolate the device immediately and preserve evidence from the NetScaler ADC VPX instance.
- Rotate Credentials: Revoke all access, rotate local account passwords, Key Encryption Keys (KEK), and replace SSL certificates if restoring from backup.
- Investigate Lateral Movement: Examine all servers and systems connected to the NetScaler ADC for signs of further compromise or unauthorized access.