CVE-2026-88772
CVE-2026-88771
September 29, 2026
·
0
Minutes Read

Citrix NetScaler ADC and NetScaler Gateway Remote Code Execution Zero-Days

Advisory
Security Advisory
September 29, 2026
·
0
Minutes Read

Citrix NetScaler ADC and NetScaler Gateway Remote Code Execution Zero-Days

Advisory
Security Advisory
September 29, 2026
·
0
Minutes Read
Kudelski Security Team
Find out more
table of contents
Share on
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Summary

Citrix disclosed two critical, unauthenticated remote code execution (RCE) vulnerabilities in NetScaler ADC and NetScaler Gateway (CVE-2026-88771 and CVE-2026-88772) alongside six lower-severity flaws (CVE-2026-88773 through CVE-2026-88778) in security bulletin CTX697096. Citrix confirmed that exploits of CVE-2026-88771 and CVE-2026-88772 have been observed on unmitigated deployments, and CISA confirmed active global exploitation corroborated by partner threat intelligence and victim reporting.

Independent root-cause research by watchTowr Labs, corroborated by CERT-EU, identifies CVE-2026-88771 as a pre-authentication command injection in a Perl diagnostic script (ns_monuploadd_err.pl) that unsafely shells out on log content it later parses, and CERT-EU reports this has been exploited in the wild to deploy a persistent PHP web shell.

Affected Systems and/or Applications

  • Citrix NetScaler ADC and Citrix NetScaler Gateway, version 14.1 before 14.1-73.37
  • Citrix NetScaler ADC and Citrix NetScaler Gateway, version 13.1 before 13.1-64.23
  • Citrix NetScaler ADC 14.1-FIPS before 14.1-73.37 FIPS
  • Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP before 13.1.37.279
  • Secure Private Access Hybrid deployments built on the above versions
  • CVE-2026-88771 affects all deployments, including default configurations
  • CVE-2026-88772 affects deployments with DTLS enabled, which is on by default for VPN virtual servers

Technical Details

Vulnerability Mechanism

CVE-2026-88771 is a pre-authentication command injection vulnerability. Independent code-level analysis by watchTowr Labs attributes it more specifically to unsafe shell invocation (backticks) inside the Perl diagnostic script ns_monuploadd_err.pl, which periodically parses appliance logs to identify crashed Packet Engine (PPE) processes: the script extracts a filename fragment from log text via a grep | tail | sed | awk pipeline and interpolates that unsanitized value into a second backtick-executed find command, so shell metacharacters (e.g. a semicolon) in attacker-controlled log content break out into arbitrary command execution as root.

CVE-2026-88772 is a memory overflow vulnerability that can result in remote code execution or denial of service; it is reachable when DTLS is enabled, which is the default setting on VPN virtual servers.

Six additional vulnerabilities were disclosed in the same bulletin - CVE-2026-88773 (HTTP request smuggling, CVSS 9.3), CVE-2026-88774 (policy bypass via HTTP URL expressions, CVSS 7.0), CVE-2026-88775 (memory overflow DoS on Gateway/AAA servers, CVSS 8.8), CVE-2026-88776 (memory overflow affecting Oracle load balancers, CVSS 8.8), CVE-2026-88777 (memory overflow with non-HTTP L7 protocols, CVSS 8.8), and CVE-2026-88778 (TCP Initial Sequence Number prediction, CVSS 8.8) - none of which are reported as actively exploited.

Other observed exploitation of CVE-2026-88771/CVE-2026-88772 follows a two-step pattern: the payload is first staged by writing it into an HTTP access log (via the User-Agent header), then triggered/executed through a separate vector.

Exploitation Path

Two ways of the exploitation chain for CVE-2026-88771 exist for now:

  • watchTowr Labs' proof-of-concept: a crafted HTTP request places an attacker-controlled string in a login-related parameter (e.g. the login field on /nf/auth/doAuthentication.do) formatted to resemble an internal diagnostic message ("...pitboss PPE unexpectedly died NSPPE;:id>/var/tmp/watchTowr;# X"). When this text is later logged and parsed by ns_monuploadd_err.pl — which can run up to 24 hours later, or be triggered on demand — the embedded semicolon breaks out of the intended log-field extraction and into the script's subsequent backtick find command, executing the injected command as root.
  • CERT-EU's description of in-the-wild activity: attackers deliver a base64-encoded bash command inside the HTTP User-Agent header (containing an INDEX marker), then poison NetScaler authentication logs with an entry resembling "pitboss: PPE NSPPE missed too many heartbeats;". When ns_monuploadd_err next executes, it parses the poisoned log entry (using | tail -1, so only the most recent matching line is honored — CERT-EU notes this explains repeated log "hammering" by attackers) and runs the injected command. Observed post-compromise activity includes a dropped PHP web shell that modifies /etc/httpd.conf to enable the PHP engine for persistence.

Key Points

  • Both zero-days are unauthenticated, network-exploitable, and reachable without special configuration on CVE-2026-88771's part.
  • CVE-2026-88771's practical trigger is time-delayed/asynchronous: the injected payload must first be written to a log, then executed only when the vulnerable diagnostic script next runs (reported up to ~24 hours, or forced). It means that exploitation timing can lag initial payload delivery.
  • Citrix has issued no workaround; the only remediation is upgrading to a fixed build.
  • Citrix explicitly warns that patching closes the vulnerabilities but does not remove any persistence or artifacts an attacker may have already left on a compromised system.
  • Compromise/IOC scanning is available through NetScaler Console version 14.1-73.36 and later, though Citrix acknowledges this scanning may not provide complete coverage.

Mitigation

Limit Exposure

No vendor-published workaround exists for either CVE. Until patched, organizations should minimize exposure of management interfaces and internet-facing NetScaler ADC/Gateway virtual servers where feasible. If patches cannot be applied within hours, organizations implement interim compensating controls such as broad geo-IP restrictions on affected virtual servers.

Patch/Upgrade

Upgrade Citrix NetScaler ADC and NetScaler Gateway to 14.1-73.37 or later, or 13.1-64.23 or later (14.1-73.37 FIPS or later; 13.1.37.279 FIPS/NDcPP or later, as applicable). An unverified, community-contributed hardening suggestion (not validated by Citrix) is enabling enhanced TCP Initial Sequence Number generation (set ns tcpParam -enhancedISNgeneration ENABLED) as a general hardening measure relevant to the separate TCP ISN prediction issue tracked as CVE-2026-88778.

What the Cyber Fusion Center is Doing

The CFC is monitoring the situation and analyzing the case to identify potential threat-hunting campaigns. This advisory will be updated if required.

References

Related Post