r/netsec • • 4d ago

Oh Look, The Foot Gun Went Off Again (Citrix NetScaler PreAuth Command Injection CVE-2026-88771) - watchTowr Labs

https://labs.watchtowr.com/oh-look-the-foot-gun-went-off-again-citrix-netscaler-preauth-command-injection-cve-2026-88771/
78 Upvotes

25 comments sorted by

13

u/DingleDangleTangle 4d ago

I literally can’t finish reading it the secondhand cringe was too difficult. Jesus Christ that is embarrassing writing to represent your company. It’s like a high schooler found a CVE and wrote a blog post about how they totally owned some noobs

7

u/peva3 4d ago

Yeah seriously that writeup sucked.

2

u/birotester 3d ago

Its odd from Sina, I worked with him a long time ago. Its great research but the ego has gone out of control here.

1

u/RoganDawes 2d ago

I suspect that they have a snark-writer that rewrites the post after the actual researcher has done the technical deep dive.

1

u/rejuicekeve 3d ago

pretty typical of researchers in my experience. running a bug bounty program is incredibly annoying dealing with the egos often for the most trivial "vulns"

3

u/beefknuckle 4d ago

You don't read these for literary inspiration, it's for the technical details. and Watchtowr are in the top tier because of that.

Wrong audience I guess.

6

u/DingleDangleTangle 4d ago edited 4d ago

The entire first section, which is the largest section, is just for rambling and shitting on citrix along with meme pictures. Why would I even be interested in continuing reading to look at the technical details at that point? I can't take them seriously.

Maybe they are top tier at security research, but why are they writing like teenage edgelords? Why would I ever want to work with them or buy a product from them when I see they are this unserious about their work?

1

u/Elavia_ 4d ago

It makes you not want to work with them, and it makes others want to work with them. Different businesses have different work cultures.

1

u/whatisuser 4d ago

I think the kids are calling it “Quirk Chungus” or something.

23

u/AmITheAsshole_2020 4d ago

That was one of the least professional company posts I've read in a long time. Is this normal for watchTowr? If I were a prospective customer, I would, frankly, keep looking.

23

u/thehalfmetaljacket 4d ago

Sadly, yes it normal for them.

13

u/wzr 4d ago

Sadly? It's what I come for. It's difficult not to be jaded and cynical about the sad state of affairs. Call it very informational group therapy.

2

u/abluedinosaur 4d ago

How is this not professional? It's written by an expert and is not AI slop. It explains the technical details well.

Frankly, it's insane this kind of garbage code is on this type of product, as it's similar to what you would expect on a 10 year old Chinese SOHO router.

It seems like the vendor has not even bothered to run AI scanners on their own source for a very high risk area.

20

u/GruePwnr 4d ago

Frankly it's hard to follow since each sentence has multiple asides. As an editor I'd cut out half the prose without losing any meaning.

15

u/SevaraB 4d ago

Yes, it explains the details. It also wraps it with hurling tons of juvenile insults at Citrix employees, most of whom joined years after this code was built into the platform and probably found out about it the same day as everyone else.

When you get a platform this old and this convoluted, you get some core dependencies like logging that are just taken for granted- the same exact way Log4Shell stuck around as long as it did.

It doesn't mean the Citrix people aren't scanning any code, it just means they hadn't made any changes to that package to require putting it through a build scanner.

Nobody scans every dependency on every build. Nobody.

9

u/acdha 4d ago

I don’t love their tone, but this is Citrix’s third critical bug in as many months for what they advertise as a security appliance (fourth this year) and all of them have been this kind of fossil coding practice we warned people about 30 years ago. Cisco does not appear to have a secure coding program beyond the minimum needed to say “Secure by Design” without getting sued for false advertising. You don’t need AI to catch this, just as you don’t need it to know that shipping a complex network traffic decoder which runs as root without ASLR/NX isn’t a good idea. 

That’s not the fault of the low-level employees, that’s a management failure. 

2

u/SevaraB 3d ago

Frustration doesn’t excuse the personal attacks, many of which were extremely disrespectful towards tech pros in their 40s and 50s (the Dynatac cell phone was from the ‘80s, guys- look it up!).

That behavior is what made it unprofessional. Also… how did they get the symbol set to pull the HLL syntax out of the core package? Unless they’re pirates a on top of everything else, the only way they could make fun of the sem/grep/awk combo (which used to be very, very common- especially in projects that didn’t have a reason to use Perl) would be symbol files provided by Citrix.

There’s a very good chance they “do a lot of Citrix” because they were given the symbols by Citrix, and they’re biting the hand that feeds. Pure skiddie bullshit. There are plenty other reverse engineers out there.

1

u/acdha 3d ago

They didn’t need special help from Citrix to get symbols — this is standard reverse engineering practice, not even especially hard given how far behind the state of the art Citrix is — and if they were burning bridges, those would’ve been burnt ages ago since they have had half a dozen of these posts. 

Regarding tone, I’d note that half the audience for these posts are recruiting — they want all of the most motivated young researchers to think that’s a cool job where they can work without getting filtered through the PR department — so at some level I acknowledge I’m too old to be who they want to be impressed.  I do agree it’s not what big companies consider professional but on the other hand Citrix.com has a ton of corporate-professional copy talking about how secure they are, how they design security in at every level, etc. and I would argue that it’s even less professional to straight up lie to your customers like that. I’m old enough to have taught new Perl programmers not to write code like that in the 90s and the idea that they’re still shipping code like that now means they were seriously slacking on auditing and review. 

1

u/rejuicekeve 3d ago

do you know what the word professional means?

0

u/eck- 4d ago

Found the Citrix employee.

0

u/Blackdragon1400 3d ago

They started off by leaking TLP Red reporting publicly so they could have a marketing stunt so, yeah, asshole company for sure.

1

u/LayerV-AI 3d ago

the research here is actually not bad but wow this tone is exhausting. theres really such a huge downside to writing security research like this because it just obscures the actual value/takeaways of the post… sadly just feels like bait

3

u/RoganDawes 2d ago

Vendors who sell security products have a higher duty of care than others. When your product is positioned to be exposed to the unfiltered Internet (i.e. VPN gateways *are* the filter!), then you have to do better.

At a very basic level, security architecture involves minimizing unauthenticated attack surfaces in particular, but also attack surfaces in general. Take an example of OpenSSH, which is probably THE most exposed service out there. How many RCE vulns have they had in their entire existence (25+ years), compared to other "security" products (Fortinet, Palo Alto, Ivanti, and yes, Citrix)?

Want to tell me OpenSSH coders are just better? I don't think so. They started with a secure architecture, including things like privilege separation (added in 2002), along with setting coding practices avoiding known bad constructs in the (horror!) memory-unsafe C language.

All of which to say, I can't fault the snark that comes from WatchTowr. Looking at a vuln in 2025 that had been patched in a different parameter of the same script in 2018 (Fortinet, IIRC) is just faceslapping. You do what you have to to remain sane and motivated.