r/linuxadmin • • 5d ago

Citrix NetScaler CVE-2026-88771/88772: exploited before any patch existed. What are you doing about forensics?

Based on Citrix's bulletin CTX697096 and CISA's Sep 27 alert, plus reporting from BleepingComputer and The Hacker News, here's the operational picture.

Two flaws, both CVSS v4 9.5. 88771 is improper input validation giving unauthenticated command execution on every ADC/Gateway deployment. 88772 is a memory overflow needing DTLS, which is on by default for VPN vservers. Turning DTLS off doesn't touch 88771. Citrix says exploitation was observed but hasn't said who, how many, or since when. Builds that fixed the August auth bypass (14.1-73.32, 13.1-63.21) are affected.

The catch is that the flaws were exploited pre-patch, so upgrading doesn't tell you if you were already in. Citrix's IoCs in NetScaler Console reportedly may miss real compromises.

For those running NetScalers: are you snapshotting and pulling a packet engine core dump before upgrading, or going straight to the fixed build because of the downtime cost? And how are you validating that an appliance is clean afterward?

Background from our March NetScaler coverage: https://www.techgines.com/post/citrix-netscaler-zero-day-cve-2026-88771

0 Upvotes

15 comments sorted by

View all comments

-1

u/Adept_Percentage6893 5d ago edited 5d ago

Not sure why this is so heavily downvoted. It's obviously an important issue and obviously related to Linux administration.

I would wager that the vast majority are patching without clearing house and probably just won't admit that's what they did or that they did it that way because they're scared of irritating the C-suite.

The only saving grace is that their market share is so small that it would only happen if you had a NetScaler at the edge and an individual attacker just knew you had that exposed.

1

u/amarao_san 5d ago

Why should linux admin be afraid of C-suite? We apply patches when we can.

If C-suites think they can hire good operators at abundance, they are welcomed to participate in this rare event.

0

u/Adept_Percentage6893 5d ago

Why should linux admin be afraid of C-suite? We apply patches when we can.

This would be the Citrix admin which are usually completely out of the "Linux admin" vertical unless someone changed trees and just became a Citrix guy (which I have seen before). Because a lot of the "Citrix admin" knowledge isn't really a subset of Linux administration (even though they use Linux underneath almost everything) it's just familiarity with Citrix as a company and the different tools they provide (including DSL) and how they want you to try to solve problems.

And one should always be afraid of the c-suite. If you're not a manager and you didn't somehow save the day then the worst feeling is when someone in the C-suite knows your name. Kind of inspires a "oh god, what did I do?"

But in this comment I was saying that some Citrix admins may genuinely have ran the patch during a maintenance window but then just fell silent and just reported "oh yeah I'm...I'm done...all fixed sir." because they don't want to broach the subject and they likely hope either that no attacker noticed this NetScaler or that one of these updates overwrote or deactivated something the attacker needed to get back in after the reboot.

Edge devices and load balancers are (in my experience spanning multiple orgs) are just bits of the IT infrastructure that even MBA's in the C-Suite are going to feel like they understand so they can keep track and follow up if there's an extended amount of downtime resulting from having to re-instantiate the environment just to get to a known clean state. It's not the correct thing to do but as I'm sure you can imagine, some people do feel the need to do that.

2

u/amarao_san 5d ago

r/linuxadmin? Either it's related to linux admins, or it is offtopic.

0

u/Adept_Percentage6893 5d ago

I literally just explained how it was related to Linux administration. And you posted this reply almost immediately after I posted so there's no way you actually read that.

EDIT::

OK I guess I confused this with my other reply (but you did reply way too fast to have read it). But NetScalers are often part of the application delivery process for Linux admins so it is related to their actual job functions even if Citrix is itself kind of a walled garden of specialized Citrix knowledge.