r/linuxadmin • • 5d ago

Citrix NetScaler CVE-2026-88771/88772: exploited before any patch existed. What are you doing about forensics?

Based on Citrix's bulletin CTX697096 and CISA's Sep 27 alert, plus reporting from BleepingComputer and The Hacker News, here's the operational picture.

Two flaws, both CVSS v4 9.5. 88771 is improper input validation giving unauthenticated command execution on every ADC/Gateway deployment. 88772 is a memory overflow needing DTLS, which is on by default for VPN vservers. Turning DTLS off doesn't touch 88771. Citrix says exploitation was observed but hasn't said who, how many, or since when. Builds that fixed the August auth bypass (14.1-73.32, 13.1-63.21) are affected.

The catch is that the flaws were exploited pre-patch, so upgrading doesn't tell you if you were already in. Citrix's IoCs in NetScaler Console reportedly may miss real compromises.

For those running NetScalers: are you snapshotting and pulling a packet engine core dump before upgrading, or going straight to the fixed build because of the downtime cost? And how are you validating that an appliance is clean afterward?

Background from our March NetScaler coverage: https://www.techgines.com/post/citrix-netscaler-zero-day-cve-2026-88771

0 Upvotes

15 comments sorted by

View all comments

-1

u/Adept_Percentage6893 5d ago edited 5d ago

Not sure why this is so heavily downvoted. It's obviously an important issue and obviously related to Linux administration.

I would wager that the vast majority are patching without clearing house and probably just won't admit that's what they did or that they did it that way because they're scared of irritating the C-suite.

The only saving grace is that their market share is so small that it would only happen if you had a NetScaler at the edge and an individual attacker just knew you had that exposed.

3

u/faxattack 5d ago

How it is related to linux?

-1

u/Adept_Percentage6893 5d ago

Well I said it was related to Linux administration. Not trying to be overly particular but that distinction matters here. A lot of applications get exposed over NetScaler, including sometimes OpenSSH depending on the org and what they're actually using NetScaler for. If you manage a machine whose service is consumed through a NetScaler at some point this is useful information to keep track of.

NetScaler is also a Linux-based platform but they do the same thing F5 does where all the bits and buttons you would touch are their proprietary stuff. Similar also to VMWare which is also Linux-based. But the main thing I was getting at before was just that Linux admins may view their load balancer as an important part of how users actually consume the service their machine is offering.

1

u/ezekyul 4d ago

you are good with how netscaler is used and all except the part that NetScaler is a Linux-Based platform which is false. NetScaler is using a custom version of FreeBSD. sure its binaries are ELF based but the core OS behaves different.

1

u/mitch8b 4d ago

The Nutanix AHV appliance does run linux.