ComputerWeekly

Cyber authorities issue alerts over exploitation of Citrix vulns


Two distinct remote zero-day vulnerabilities in Citrix NetScaler Application Delivery Controller (ADC) and Gateway are coming under rapid exploitation from threat actors, prompting fresh alerts from government cyber agencies in the UK, the Netherlands, and the US.

The flaws in the frequently-targeted NetScaler product set, which run access, load balancing and authentication at the network edge, are among a tranche of fixes released by Citrix on Sunday 27 September, and should be patched immediately.

The core issues in scope are flaws tracked as CVE-2026-88771, which arises from improper input validation and enables an unauthenticated actor to execute arbitrary commands, and CVE-2026-88772, which arises from a memory overflow condition and enables both denial-of-service or remote code execution (RCE) attacks.

The issues affect versions 13.1 and 14.1 of NetScaler ADC and Gateway prior to 13.1-64.23 and 14.1-73.37 respectively, NetScaler ADC FIPS prior to version 14.1-73/37 FIPS, and NetScaler ADC FIPS and NDcPP prior to version 13.1-37.279, said Citrix.

The UK’s National Cyber Security Centre (NCSC) said: “The NCSC is working to understand the impact of these vulnerabilities on UK organisations.”

The US’ Cybersecurity and Infrastructure Security Agency (Cisa) said it had added both of the most serious flaws to its Known Exploited Vulnerabilities (Kev) catalogue – with a fix deadline of Wednesday 30 September.

“Both are critical, zero-day vulnerabilities that can independently enable remote code execution. CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally,” the agency said in a statement.

The NCSC is urging organisations to familiarise themselves with the Citrix security bulletin and further information – including indicators of compromise (IoCs) – and if possible to isolate any affected systems and replace them with a new, fully up-to-date one, although it cautioned that this may cause a significant IT outage. If compromise is suspected, organisations should also preserve forensic evidence prior to applying the updates.

“If you believe you have been compromised, and are in the UK, you should report it. You can also report the compromise to the vendor to assist their investigation,” the NCSC added.

Disclosure timeline

Citrix has subsequently faced criticism over the timeline for disclosure of the zero-days after it became apparent that Dutch NCSC had issued an alert concerning exploitation of the-day flaws in advance of the supplier’s own disclosure.

WatchTowr, which also broke cover ahead of Citrix and was among the first to communicate the existence of the zero-days prior to the weekend, described a “serious situation” that “should not be underestimated.”

As a result of this, rumours of a potential incident swirled on social media platform Reddit as IT and security teams awaited official confirmation from Citrix at the weekend.

Writing on Monday 28 September, WatchTowr researcher Sina Kheirkhah commented: “We’re sure there are many teams at this point having extremely tense conversations with their TAM [technical account manager], asking why an actively exploited RCE in a default configuration was communicated to the world through many channels, none of which included Citrix itself.

“We are yet again dealing with a situation where the entire world apparently knew about Citrix NetScaler CVEs before Citrix had woken up or bothered to acknowledge them.

“We all know that vulnerabilities exist. Code is not perfect … but communicating with your customers who pay for a solution to secure their environment feels like the bare minimum, not optional,” wrote Kheirkhah.

 



Source link