Hackers Hit NetScaler Zero-Days Before Citrix Patched | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


Incident & Breach Response
,
Security Operations

CISA Adds 2 NetScaler Flaws to KEV as Researchers Detail Root-Level Exploit

Image: Shutterstock

Hackers are exploiting two critical flaws in Citrix NetScaler, a widely used gateway that organizations rely on to let employees connect to internal systems from anywhere.

See Also: The Anatomy of a Modern Cyberattack

The U.S. Cybersecurity and Infrastructure Security Agency added the vulnerabilities to its Known Exploited Vulnerabilities catalog Sunday, the same day Citrix parent Cloud Software Group published patches for eight NetScaler ADC and NetScaler Gateway flaws. The warning comes as researchers publish technical details showing how one of the bugs lets an attacker run commands on the appliance without logging in.

CISA said threat intelligence from partners shows hackers are “actively exploiting these vulnerabilities globally.” The agency warned that attackers could use either bug on its own to take over an appliance remotely.

The more severe of the two, tracked as CVE-2026-88771, allows attackers with no credentials to run commands on a device as it fails to properly check incoming data. Citrix said in its security bulletin that any appliance running an unpatched version can be hit, even if administrators never changed the factory settings.

The second flaw, CVE-2026-88772, is a memory corruption bug that can let attackers run code or knock the device offline. Both flaws carry CVSS 4.0 scores of 9.5.

Citrix said it has seen attackers exploit both flaws on unpatched appliances and urged customers to install “the relevant updated versions as soon as possible.” Researchers at watchTowr raised the alarm Saturday, a day before Citrix disclosed the bugs, saying incident responders had come across them while investigating breaches.

CISA cautioned that patching NetScaler appliances is not always straightforward and can mean taking them offline. The agency told organizations to suspect a breach to capture forensic data first, as installing updates can wipe out evidence of an intrusion. The deadline for agencies to fix the NetScaler flaws is Sept. 30.

Australia’s Cyber Security Centre issued its own critical alert Monday, saying it had “not yet received reports of confirmed exploitation in Australia.” The agency told organizations to hunt through NetScaler logs for signs of tampering.

Organizations that patched CVE-2026-88771’s predecessor, CVE-2026-19490, which CISA added to the KEV catalog on Sept. 9, are still exposed until they move to the new builds, watchTowr said. Researchers have not tied the attacks to a specific group.

NetScaler has drawn attackers before. In 2023, ransomware groups abused a session-hijacking flaw known as Citrix Bleed to break into victims’ networks (see: Attackers Now ‘Scanning Extensively’ for Citrix Bleed 2).





Click Here For The Original Source.

——————————————————–

..........

.

.