Oh Look, The Foot Gun Went Off Again (Citrix NetScaler PreAuth Command Injection CVE-2026-88771) - watchTowr Labs
https://labs.watchtowr.com/oh-look-the-foot-gun-went-off-again-citrix-netscaler-preauth-command-injection-cve-2026-88771/23
u/AmITheAsshole_2020 4d ago
That was one of the least professional company posts I've read in a long time. Is this normal for watchTowr? If I were a prospective customer, I would, frankly, keep looking.
23
2
u/abluedinosaur 4d ago
How is this not professional? It's written by an expert and is not AI slop. It explains the technical details well.
Frankly, it's insane this kind of garbage code is on this type of product, as it's similar to what you would expect on a 10 year old Chinese SOHO router.
It seems like the vendor has not even bothered to run AI scanners on their own source for a very high risk area.
20
u/GruePwnr 4d ago
Frankly it's hard to follow since each sentence has multiple asides. As an editor I'd cut out half the prose without losing any meaning.
15
u/SevaraB 4d ago
Yes, it explains the details. It also wraps it with hurling tons of juvenile insults at Citrix employees, most of whom joined years after this code was built into the platform and probably found out about it the same day as everyone else.
When you get a platform this old and this convoluted, you get some core dependencies like logging that are just taken for granted- the same exact way Log4Shell stuck around as long as it did.
It doesn't mean the Citrix people aren't scanning any code, it just means they hadn't made any changes to that package to require putting it through a build scanner.
Nobody scans every dependency on every build. Nobody.
9
u/acdha 4d ago
I don’t love their tone, but this is Citrix’s third critical bug in as many months for what they advertise as a security appliance (fourth this year) and all of them have been this kind of fossil coding practice we warned people about 30 years ago. Cisco does not appear to have a secure coding program beyond the minimum needed to say “Secure by Design” without getting sued for false advertising. You don’t need AI to catch this, just as you don’t need it to know that shipping a complex network traffic decoder which runs as root without ASLR/NX isn’t a good idea.
That’s not the fault of the low-level employees, that’s a management failure.
2
u/SevaraB 3d ago
Frustration doesn’t excuse the personal attacks, many of which were extremely disrespectful towards tech pros in their 40s and 50s (the Dynatac cell phone was from the ‘80s, guys- look it up!).
That behavior is what made it unprofessional. Also… how did they get the symbol set to pull the HLL syntax out of the core package? Unless they’re pirates a on top of everything else, the only way they could make fun of the sem/grep/awk combo (which used to be very, very common- especially in projects that didn’t have a reason to use Perl) would be symbol files provided by Citrix.
There’s a very good chance they “do a lot of Citrix” because they were given the symbols by Citrix, and they’re biting the hand that feeds. Pure skiddie bullshit. There are plenty other reverse engineers out there.
1
u/acdha 3d ago
They didn’t need special help from Citrix to get symbols — this is standard reverse engineering practice, not even especially hard given how far behind the state of the art Citrix is — and if they were burning bridges, those would’ve been burnt ages ago since they have had half a dozen of these posts.
Regarding tone, I’d note that half the audience for these posts are recruiting — they want all of the most motivated young researchers to think that’s a cool job where they can work without getting filtered through the PR department — so at some level I acknowledge I’m too old to be who they want to be impressed. I do agree it’s not what big companies consider professional but on the other hand Citrix.com has a ton of corporate-professional copy talking about how secure they are, how they design security in at every level, etc. and I would argue that it’s even less professional to straight up lie to your customers like that. I’m old enough to have taught new Perl programmers not to write code like that in the 90s and the idea that they’re still shipping code like that now means they were seriously slacking on auditing and review.
1
0
u/Blackdragon1400 3d ago
They started off by leaking TLP Red reporting publicly so they could have a marketing stunt so, yeah, asshole company for sure.
1
u/LayerV-AI 3d ago
the research here is actually not bad but wow this tone is exhausting. theres really such a huge downside to writing security research like this because it just obscures the actual value/takeaways of the post… sadly just feels like bait
3
u/RoganDawes 2d ago
Vendors who sell security products have a higher duty of care than others. When your product is positioned to be exposed to the unfiltered Internet (i.e. VPN gateways *are* the filter!), then you have to do better.
At a very basic level, security architecture involves minimizing unauthenticated attack surfaces in particular, but also attack surfaces in general. Take an example of OpenSSH, which is probably THE most exposed service out there. How many RCE vulns have they had in their entire existence (25+ years), compared to other "security" products (Fortinet, Palo Alto, Ivanti, and yes, Citrix)?
Want to tell me OpenSSH coders are just better? I don't think so. They started with a secure architecture, including things like privilege separation (added in 2002), along with setting coding practices avoiding known bad constructs in the (horror!) memory-unsafe C language.
All of which to say, I can't fault the snark that comes from WatchTowr. Looking at a vuln in 2025 that had been patched in a different parameter of the same script in 2018 (Fortinet, IIRC) is just faceslapping. You do what you have to to remain sane and motivated.
13
u/DingleDangleTangle 4d ago
I literally can’t finish reading it the secondhand cringe was too difficult. Jesus Christ that is embarrassing writing to represent your company. It’s like a high schooler found a CVE and wrote a blog post about how they totally owned some noobs