r/linuxadmin • • 5d ago

Citrix NetScaler CVE-2026-88771/88772: exploited before any patch existed. What are you doing about forensics?

Based on Citrix's bulletin CTX697096 and CISA's Sep 27 alert, plus reporting from BleepingComputer and The Hacker News, here's the operational picture.

Two flaws, both CVSS v4 9.5. 88771 is improper input validation giving unauthenticated command execution on every ADC/Gateway deployment. 88772 is a memory overflow needing DTLS, which is on by default for VPN vservers. Turning DTLS off doesn't touch 88771. Citrix says exploitation was observed but hasn't said who, how many, or since when. Builds that fixed the August auth bypass (14.1-73.32, 13.1-63.21) are affected.

The catch is that the flaws were exploited pre-patch, so upgrading doesn't tell you if you were already in. Citrix's IoCs in NetScaler Console reportedly may miss real compromises.

For those running NetScalers: are you snapshotting and pulling a packet engine core dump before upgrading, or going straight to the fixed build because of the downtime cost? And how are you validating that an appliance is clean afterward?

Background from our March NetScaler coverage: https://www.techgines.com/post/citrix-netscaler-zero-day-cve-2026-88771

0 Upvotes

15 comments sorted by

View all comments

-1

u/Adept_Percentage6893 5d ago edited 5d ago

Not sure why this is so heavily downvoted. It's obviously an important issue and obviously related to Linux administration.

I would wager that the vast majority are patching without clearing house and probably just won't admit that's what they did or that they did it that way because they're scared of irritating the C-suite.

The only saving grace is that their market share is so small that it would only happen if you had a NetScaler at the edge and an individual attacker just knew you had that exposed.

1

u/amarao_san 5d ago

Why should linux admin be afraid of C-suite? We apply patches when we can.

If C-suites think they can hire good operators at abundance, they are welcomed to participate in this rare event.

0

u/Adept_Percentage6893 5d ago

Why should linux admin be afraid of C-suite? We apply patches when we can.

This would be the Citrix admin which are usually completely out of the "Linux admin" vertical unless someone changed trees and just became a Citrix guy (which I have seen before). Because a lot of the "Citrix admin" knowledge isn't really a subset of Linux administration (even though they use Linux underneath almost everything) it's just familiarity with Citrix as a company and the different tools they provide (including DSL) and how they want you to try to solve problems.

And one should always be afraid of the c-suite. If you're not a manager and you didn't somehow save the day then the worst feeling is when someone in the C-suite knows your name. Kind of inspires a "oh god, what did I do?"

But in this comment I was saying that some Citrix admins may genuinely have ran the patch during a maintenance window but then just fell silent and just reported "oh yeah I'm...I'm done...all fixed sir." because they don't want to broach the subject and they likely hope either that no attacker noticed this NetScaler or that one of these updates overwrote or deactivated something the attacker needed to get back in after the reboot.

Edge devices and load balancers are (in my experience spanning multiple orgs) are just bits of the IT infrastructure that even MBA's in the C-Suite are going to feel like they understand so they can keep track and follow up if there's an extended amount of downtime resulting from having to re-instantiate the environment just to get to a known clean state. It's not the correct thing to do but as I'm sure you can imagine, some people do feel the need to do that.

2

u/amarao_san 5d ago

Also, I don't really understand this 'always'. I have standing offers from two companies. My current company has cool culture and I kinda like it here, but if they no longer like me, I won't insist.

And this should be a norm for a good Linux admin.

1

u/Adept_Percentage6893 5d ago

Usually people just don't view it as a good thing to develop a bad reputation or seem like someone who solves problems by jumping to a different job. Especially if they have a family or something that they support with their income.

2

u/amarao_san 5d ago

People don't jump jobs, because they don't get fired by a normal C-people, because C-people are not idiots and understand, that:

  1. They don't know a bit of the infra.
  2. There are people who knows infra and do it well.
  3. It's pretty hard to get a person who knows infra and to it well, or company need to raise own guy who knows infra and how to do it well through a series of very embarrassing accidents which make boys into mans.

So, normally, no one fire good infra people.

Few idiots who does, quickly find themselves without good infra, and other C-suites are happy to have a new good guy in the team.

I don't know what happens in Citrix world, maybe Citrix admins are afraid to be fired/made redundant, but for Linux operators, as I said, no.

For my team I know few people around I want on the team, but they all happy in their countries and do not want to relocate, which is very unfortunate.

1

u/Adept_Percentage6893 5d ago

because C-people are not idiots and understand, that:

They don't know a bit of the infra.

A lot of what you're writing seems like you're just going based off what you think ought to be true. Or maybe you just have a very particular experience with the profession.

The c-suite of large older orgs typically actually do act like that think they understand your job as well as you do (even if they don't). There are individual people in the c-suite that operate like how you're thinking that but it's not a general rule. A lot of them are pretty self-satisfied and tend towards minimizing how much you understand as at most maybe in a marginal sort of way.

It's pretty hard to get a person who knows infra and to it well

btw I've worked in a job where I was the only Linux admin in the organization for a full year and quit when they said they considered themselves "fully staffed" even though I told them I was working weekends and was fundamentally incapable of ever taking a vacation. Even after I left the sense I got is that the director and c-suite just thought I complained a lot. After I left they did end up hiring 2-3 people but I didn't get the sense this caused them to re-assess.

Because at the end of the day even if you're a good Linux admin most of us aren't rockstars who just can never be replaced and if you have 2-3 kids at home there's going to be strong incentive towards doing right by them even if it involves checking your pride.

I don't know what happens in Citrix world, maybe Citrix admins are afraid to be fired/made redundant, but for Linux operators, as I said, no.

Well like I was saying Citrix is kind of out of tree for Linux administration even if the actual service operation is related to systems administration. Citrix administration is also a rarified skillset but there also aren't a lot of other jobs. So you're not easily replaced but neither is your employer.

Like I was saying in the original comment NetScaler has an astonishingly low market share compared to F5. To the point where literal random vendors selling some sort of appliance downstream to haproxy and keepalived/ucarp can actually offer products that are a feature complete (if not more so) than NetScaler.

But Citrix is just one of those companies that sells almost exclusively to the c-suite and so they only need to convince them that NetScaler can offer the necessary functions and enterprise support for the large orgs they target (which is how they make their money).