MalwareTips News Actively exploited NetScaler flaws put internet-facing gateways at risk

Security News
0 Replies 100 Views

Do you use NetScaler ADC or NetScaler Gateway at work?

  • Yes, and it has been checked

    Votes: 1 50.0%
  • Yes, but I am not sure of its status

    Votes: 0 0.0%
  • No, we do not use it

    Votes: 1 50.0%
  • I do not know

    Votes: 0 0.0%

  • Total voters
    2

News Now

Happening Now
Verified
MalwareTips-news-129.jpg

Image: Palo Alto Networks Unit 42

Organizations running Citrix NetScaler ADC or NetScaler Gateway should update and investigate their appliances now. Citrix reports that two critical flaws, CVE-2026-88771 and CVE-2026-88772, are being exploited, although details of the attacks are not yet available.

What administrators should do now​

Palo Alto Networks Unit 42 recommends installing the latest Citrix software and checking whether each appliance meets the exposure conditions in Citrix’s security advisory.

  • Isolate vulnerable NetScaler systems from the network while they are assessed.
  • Preserve a NetScaler VPX snapshot, remote syslog and NetScaler Console logs, a technical support bundle and a packet engine core dump.
  • Look for suspicious administrator sessions, unexpected outbound connections and unexplained gaps in logging.

Why the flaws are serious​

CVE-2026-88771 is an input-validation flaw that can let an unauthenticated attacker run commands remotely on affected NetScaler ADC and Gateway systems. Remote code execution means an attacker can execute instructions on the device without being physically present.

CVE-2026-88772 is a memory-overflow flaw affecting Datagram Transport Layer Security configurations. It can cause remote code execution or denial of service, which may make the appliance unavailable.

Both vulnerabilities carry a CVSS v4.0 severity score of 9.5 out of 10.

Exposure is widespread, but attack details remain limited​

As of September 27, 2026, Cortex Xpanse telemetry identified more than 50,277 exposed instances that could be vulnerable. This is a count of potentially affected internet-facing systems, not confirmed compromises.

Unit 42 says its suggested warning signs are general hunting guidance rather than behavior it has specifically linked to these attacks. Administrators should preserve evidence before cleanup because Citrix has not yet disclosed further details about the exploitation.
 
Back
Top