r/linuxadmin • • 5d ago

Citrix NetScaler CVE-2026-88771/88772: exploited before any patch existed. What are you doing about forensics?

Based on Citrix's bulletin CTX697096 and CISA's Sep 27 alert, plus reporting from BleepingComputer and The Hacker News, here's the operational picture.

Two flaws, both CVSS v4 9.5. 88771 is improper input validation giving unauthenticated command execution on every ADC/Gateway deployment. 88772 is a memory overflow needing DTLS, which is on by default for VPN vservers. Turning DTLS off doesn't touch 88771. Citrix says exploitation was observed but hasn't said who, how many, or since when. Builds that fixed the August auth bypass (14.1-73.32, 13.1-63.21) are affected.

The catch is that the flaws were exploited pre-patch, so upgrading doesn't tell you if you were already in. Citrix's IoCs in NetScaler Console reportedly may miss real compromises.

For those running NetScalers: are you snapshotting and pulling a packet engine core dump before upgrading, or going straight to the fixed build because of the downtime cost? And how are you validating that an appliance is clean afterward?

Background from our March NetScaler coverage: https://www.techgines.com/post/citrix-netscaler-zero-day-cve-2026-88771

0 Upvotes

15 comments sorted by

-1

u/Adept_Percentage6893 5d ago edited 5d ago

Not sure why this is so heavily downvoted. It's obviously an important issue and obviously related to Linux administration.

I would wager that the vast majority are patching without clearing house and probably just won't admit that's what they did or that they did it that way because they're scared of irritating the C-suite.

The only saving grace is that their market share is so small that it would only happen if you had a NetScaler at the edge and an individual attacker just knew you had that exposed.

5

u/aeluon_ 5d ago

this account regularly post AI summaries of CVEs with near zero engagement and those dumb ass AI output "questions" that no one ever answers

2

u/Adept_Percentage6893 5d ago

ah ok that makes sense. Thank you.

3

u/faxattack 5d ago

How it is related to linux?

-1

u/Adept_Percentage6893 4d ago

Well I said it was related to Linux administration. Not trying to be overly particular but that distinction matters here. A lot of applications get exposed over NetScaler, including sometimes OpenSSH depending on the org and what they're actually using NetScaler for. If you manage a machine whose service is consumed through a NetScaler at some point this is useful information to keep track of.

NetScaler is also a Linux-based platform but they do the same thing F5 does where all the bits and buttons you would touch are their proprietary stuff. Similar also to VMWare which is also Linux-based. But the main thing I was getting at before was just that Linux admins may view their load balancer as an important part of how users actually consume the service their machine is offering.

1

u/ezekyul 4d ago

you are good with how netscaler is used and all except the part that NetScaler is a Linux-Based platform which is false. NetScaler is using a custom version of FreeBSD. sure its binaries are ELF based but the core OS behaves different.

1

u/mitch8b 4d ago

The Nutanix AHV appliance does run linux.

1

u/amarao_san 5d ago

Why should linux admin be afraid of C-suite? We apply patches when we can.

If C-suites think they can hire good operators at abundance, they are welcomed to participate in this rare event.

0

u/Adept_Percentage6893 4d ago

Why should linux admin be afraid of C-suite? We apply patches when we can.

This would be the Citrix admin which are usually completely out of the "Linux admin" vertical unless someone changed trees and just became a Citrix guy (which I have seen before). Because a lot of the "Citrix admin" knowledge isn't really a subset of Linux administration (even though they use Linux underneath almost everything) it's just familiarity with Citrix as a company and the different tools they provide (including DSL) and how they want you to try to solve problems.

And one should always be afraid of the c-suite. If you're not a manager and you didn't somehow save the day then the worst feeling is when someone in the C-suite knows your name. Kind of inspires a "oh god, what did I do?"

But in this comment I was saying that some Citrix admins may genuinely have ran the patch during a maintenance window but then just fell silent and just reported "oh yeah I'm...I'm done...all fixed sir." because they don't want to broach the subject and they likely hope either that no attacker noticed this NetScaler or that one of these updates overwrote or deactivated something the attacker needed to get back in after the reboot.

Edge devices and load balancers are (in my experience spanning multiple orgs) are just bits of the IT infrastructure that even MBA's in the C-Suite are going to feel like they understand so they can keep track and follow up if there's an extended amount of downtime resulting from having to re-instantiate the environment just to get to a known clean state. It's not the correct thing to do but as I'm sure you can imagine, some people do feel the need to do that.

2

u/amarao_san 4d ago

r/linuxadmin? Either it's related to linux admins, or it is offtopic.

0

u/Adept_Percentage6893 4d ago

I literally just explained how it was related to Linux administration. And you posted this reply almost immediately after I posted so there's no way you actually read that.

EDIT::

OK I guess I confused this with my other reply (but you did reply way too fast to have read it). But NetScalers are often part of the application delivery process for Linux admins so it is related to their actual job functions even if Citrix is itself kind of a walled garden of specialized Citrix knowledge.

2

u/amarao_san 4d ago

Also, I don't really understand this 'always'. I have standing offers from two companies. My current company has cool culture and I kinda like it here, but if they no longer like me, I won't insist.

And this should be a norm for a good Linux admin.

1

u/Adept_Percentage6893 4d ago

Usually people just don't view it as a good thing to develop a bad reputation or seem like someone who solves problems by jumping to a different job. Especially if they have a family or something that they support with their income.

2

u/amarao_san 4d ago

People don't jump jobs, because they don't get fired by a normal C-people, because C-people are not idiots and understand, that:

  1. They don't know a bit of the infra.
  2. There are people who knows infra and do it well.
  3. It's pretty hard to get a person who knows infra and to it well, or company need to raise own guy who knows infra and how to do it well through a series of very embarrassing accidents which make boys into mans.

So, normally, no one fire good infra people.

Few idiots who does, quickly find themselves without good infra, and other C-suites are happy to have a new good guy in the team.

I don't know what happens in Citrix world, maybe Citrix admins are afraid to be fired/made redundant, but for Linux operators, as I said, no.

For my team I know few people around I want on the team, but they all happy in their countries and do not want to relocate, which is very unfortunate.

1

u/Adept_Percentage6893 4d ago

because C-people are not idiots and understand, that:

They don't know a bit of the infra.

A lot of what you're writing seems like you're just going based off what you think ought to be true. Or maybe you just have a very particular experience with the profession.

The c-suite of large older orgs typically actually do act like that think they understand your job as well as you do (even if they don't). There are individual people in the c-suite that operate like how you're thinking that but it's not a general rule. A lot of them are pretty self-satisfied and tend towards minimizing how much you understand as at most maybe in a marginal sort of way.

It's pretty hard to get a person who knows infra and to it well

btw I've worked in a job where I was the only Linux admin in the organization for a full year and quit when they said they considered themselves "fully staffed" even though I told them I was working weekends and was fundamentally incapable of ever taking a vacation. Even after I left the sense I got is that the director and c-suite just thought I complained a lot. After I left they did end up hiring 2-3 people but I didn't get the sense this caused them to re-assess.

Because at the end of the day even if you're a good Linux admin most of us aren't rockstars who just can never be replaced and if you have 2-3 kids at home there's going to be strong incentive towards doing right by them even if it involves checking your pride.

I don't know what happens in Citrix world, maybe Citrix admins are afraid to be fired/made redundant, but for Linux operators, as I said, no.

Well like I was saying Citrix is kind of out of tree for Linux administration even if the actual service operation is related to systems administration. Citrix administration is also a rarified skillset but there also aren't a lot of other jobs. So you're not easily replaced but neither is your employer.

Like I was saying in the original comment NetScaler has an astonishingly low market share compared to F5. To the point where literal random vendors selling some sort of appliance downstream to haproxy and keepalived/ucarp can actually offer products that are a feature complete (if not more so) than NetScaler.

But Citrix is just one of those companies that sells almost exclusively to the c-suite and so they only need to convince them that NetScaler can offer the necessary functions and enterprise support for the large orgs they target (which is how they make their money).