Full Report
On Sept 27, Citrix released patches for two critical vulnerabilities being exploited in the wild. Based on current information, we confirm there has been no exposure or impact to LevelBlue or our clients. CISA has already added these vulnerabilities to the Known Exploited Vulnerabilities (KEV) list.
Analysis Summary
# Vulnerability: Citrix NetScaler Zero-Day Vulnerabilities
## CVE Details
- **CVE ID:** CVE-2026-88771
- **CVSS Score:** 9.5 (Critical)
- **CWE:** Improper Input Validation
- **CVE ID:** CVE-2026-88772
- **CVSS Score:** 9.5 (Critical)
- **CWE:** Improper Restriction of Operations within the Bounds of a Memory Buffer
## Affected Systems
- **Products:** Citrix NetScaler ADC, Citrix NetScaler Gateway, Citrix NetScaler ADC FIPS, Citrix NetScaler ADC FIPS and NDcPP.
- **Versions:**
- NetScaler ADC and Gateway 14.1 before 14.1-73.37
- NetScaler ADC and Gateway 13.1 before 13.1-64.23
- NetScaler ADC FIPS before 14.1-73.37 FIPS
- NetScaler ADC FIPS and NDcPP before 13.1-37.279
- **Configurations:**
- CVE-2026-88771 affects all NetScaler ADC and Gateway deployments.
- CVE-2026-88772 requires Datagram Transport Layer Security (DTLS) to be enabled (this option is enabled by default on VPN virtual servers).
## Vulnerability Description
The vulnerabilities stem from how the NetScaler packet processing daemon handles malformed HTTP requests and TLS traffic.
An attacker can craft an HTTP stream containing overlapping block fragments. The packet processor fails to validate the size of the reassembled stream against its assigned memory buffer, triggering a classic buffer overflow condition (CVE-2026-88772). This flaw is chained with an improper input validation vulnerability (CVE-2026-88771) in the TLS traffic handler. By initiating a rapid succession of TLS handshakes, threat actors can overwrite the memory pointer, effectively bypassing Address Space Layout Randomization (ASLR). This redirects execution to the stack location where the initial malicious HTTP shellcode was staged, resulting in unauthenticated remote code execution (RCE) or denial-of-service (DoS).
## Exploitation
- **Status:** Exploited in the wild (Confirmed zero-day exploitation globally; added to CISA's Known Exploited Vulnerabilities catalog). Technical analysis is available, though a public standalone exploit script is not explicitly confirmed.
- **Complexity:** Medium (Requires precise chaining of HTTP fragmentation and TLS handshake timing).
- **Attack Vector:** Network
## Impact
- **Confidentiality:** High (Allows unauthorized arbitrary command execution).
- **Integrity:** High (Allows full system modification via shellcode execution).
- **Availability:** High (Can lead to complete system denial-of-service).
## Remediation
### Patches
Citrix has released official security updates. Affected organizations should upgrade to the following versions or later immediately:
- Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.37
- Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23
- Citrix NetScaler ADC FIPS 14.1-73.37 FIPS
- Citrix NetScaler ADC FIPS and NDcPP 13.1-37.279
### Workarounds
No official configuration workarounds were provided to completely mitigate the flaws without patching, but general security posture hardening includes:
- Utilizing network access controls to strictly isolate NetScaler systems.
- Revoking unused user accounts and forcing authentication resets for all active accounts.
## Detection
- Monitor network traffic for anomalous HTTP streams with overlapping block fragments.
- Audit TLS traffic logs for rapid successions of unfinished handshakes originating from single sources.
- Enable and comprehensively collect all host and network logs from NetScaler appliances and surrounding infrastructure to watch for unauthorized command execution or unexpected service crashes.
## References
- Citrix Vendor Advisory: `hxxps[://]support[.]citrix[.]com/support-home/kbsearch/article?articleNumber=CTX697096`
- CISA KEV Alert: `hxxps[://]www[.]cisa[.]gov/news-events/alerts/2026/09/27/cisa-adds-two-known-exploited-vulnerabilities-catalog`
- LevelBlue SpiderLabs Blog: `hxxps[://]www[.]levelblue[.]com/blogs/spiderlabs-blog/citrix-netscaler-zero-day-exploited-globally`