Citrix NetScaler Vulnerability Enables Unauthenticated Command Execution

Moyen · CISA Known Exploited Vulnerabilities ·

En bref

  • CVE-2026-88771 affects Citrix NetScaler ADC and NetScaler Gateway.
  • An unauthenticated attacker can execute arbitrary commands.
  • Apply mitigations and follow BOD 26-04.
  • Assess internet exposure; if no mitigation, discontinue use.

Citrix has disclosed a medium-severity vulnerability, tracked as CVE-2026-88771, that impacts NetScaler ADC and NetScaler Gateway. The flaw allows a threat actor who has not authenticated to run commands of their choosing on the affected appliance. This means exploitation does not require valid credentials.

Organizations running these Citrix products are at risk, particularly if the systems are reachable from the internet. In K-12 and government environments, NetScaler gateways often serve as remote access points, so a compromise could expose internal networks and student or staff data.

The ability to execute arbitrary commands without authentication is dangerous because it can lead to full system takeover, data theft, and lateral movement. Even a medium-severity rating warrants prompt attention, especially for internet-facing assets.

Binding Operational Directive 26-04 requires agencies to take specific actions. Administrators should assess whether their NetScaler instances are exposed to the internet and deploy available mitigations. If no mitigation is available, the directive calls for discontinuing use of the product.

Watch for vendor updates and signs of exploitation in logs. Prioritize remediation based on exposure and criticality. Until a fix is applied, consider restricting access or taking systems offline.

À faire maintenant

  1. Inventory all Citrix NetScaler ADC and NetScaler Gateway deployments.
  2. Determine which instances are internet-facing and prioritize them.
  3. Apply vendor-recommended mitigations as soon as possible.
  4. Comply with BOD 26-04 requirements for your organization.
  5. If no mitigation exists, disconnect or discontinue the affected product.
  6. Monitor logs and network traffic for exploitation attempts.
  7. Plan to patch once Citrix releases a permanent fix.

Source originale

CISA Known Exploited Vulnerabilities

Analyse originale assistée par IA, sources citées. Vérifiez auprès de l'avis du fournisseur avant d'agir.

← Toute la veille cyber