You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Improper Restriction of Operations within the Bounds of a Memory Buffer
2026-09-27
9.5 Critical
Memory overflow → RCE or DoS
DTLS enabled (default on VPN virtual servers)
Both are zero-days: the exploitation was found in forensic investigations before any CVE existed, surfaced publicly 2026-09-26 (NCSC-NL private pre-notification, watchTowr Rapid Reaction warning), and Citrix published the bulletin CTX697096 on 2026-09-27. Each is independently sufficient for RCE. Six further CVEs ship in the same bulletin (88773 HTTP request smuggling 9.3, 88774 7.0, 88775/88776/88777/88778 8.8) — configuration-dependent, not reported exploited. 88778 is fixed by enabling Enhanced ISN Generation, not by the upgrade alone.
Fixed builds: 14.1-73.37, 13.1-64.23 (13.1-64.24 if show ns variable returns anything — 13.1 has a reboot loop), 13.1-37.279 for the FIPS/NDcPP branch. No workaround published. Appliances already patched for CVE-2026-19490 remain vulnerable to this pair.
The vendor explicitly warns the IOC scan is incomplete ("a clean result is not proof"). That argument for external decoys gets stronger, not weaker — this is exactly the case where an internal appliance tells you "clean" and an internet-facing decoy tells you what the probe actually looks like.
88772 is the one to watch on our side. DTLS is a UDP transport our surface does not currently exercise. A NetScaler that probes for DTLS before it probes HTTP is fingerprinting the appliance, not using it. Classifying that as an ordered-recon event — rather than as scan noise — is cheap now and expensive later.
88773 (request smuggling, same bulletin, 9.3) is a classifier, not a firewall rule. It is directly in scope for the existing HTTP payload-classification work (see main.go is a merge hotspot: split http-honeypot CVE classifiers into one file per CVE #3464, which notes main.go is a merge hotspot for the per-CVE classifiers) — a conflicting-Content-Length/Transfer-Encoding request against the citrix surface is exactly the input it needs.
Proposed detection
Signal A — pre-auth request-shape match (primary). No public PoC detail is reproduced here on purpose; instead, classify on shape:
Any citrix-honeypot request that reaches a management/config path with no preceding session-establishment request. Our decoy does not serve management paths, so a probe there is a fingerprint, not a user.
Requests with contradictory framing headers (Content-Length alongside Transfer-Encoding, duplicate CL with differing values) against the citrix surface → route to the 88773 smuggling class.
Any request carrying a shell metacharacter burst (;, `, $(, |) in a path or query against the citrix surface → 88771 class. This is coarse but it is the only signature available before a PoC stabilises, and the decoy costs nothing when it misfires.
Signal B — transport-ordering recon. Flag source IPs that probe UDP/DTLS on the citrix address before any TCP connection, and any source that re-probes within a short window after a rejected management-path request. Attacker tooling for an edge appliance normally walks transports before payloads.
Signal C — device fingerprint divergence. Log TLS/HTTP fingerprint (JA3/JA4, ALPN, offered cipher order, cookie/netscale branding in responses) per source so a probe claiming to be a browser but presenting a non-browser TLS shape is queryable. No credential material is involved in either CVE — pure fingerprint divergence is the honest tell.
Proposed Kibana query shape (field names to be mapped to the real schema; do not take this literally):
sensor: citrix-honeypot
AND ( path_preauth_management: true
OR framing_conflict: true
OR shell_metachars_in_path: true )
then group by source.ip over a 15m window and surface the count of distinct decoys touched.
Severity
Critical — CVSS 4.0 9.5 on both, unauthenticated, default configuration, remote, KEV-listed with confirmed global exploitation.
This issue is detection coverage only. It does not propose emulating the vulnerable code paths, and it does not ask for a working exploit reproduction on the decoy.
Finding
CVE-2026-88771 + CVE-2026-88772 — Citrix NetScaler ADC / NetScaler Gateway zero-day RCE pair, actively exploited, added to CISA KEV on 2026-09-27.
Verified this run against the live CISA KEV feed (catalog version 2026.09.27, released 2026-09-27T21:30:35Z, 1728 entries):
Both are zero-days: the exploitation was found in forensic investigations before any CVE existed, surfaced publicly 2026-09-26 (NCSC-NL private pre-notification, watchTowr Rapid Reaction warning), and Citrix published the bulletin CTX697096 on 2026-09-27. Each is independently sufficient for RCE. Six further CVEs ship in the same bulletin (88773 HTTP request smuggling 9.3, 88774 7.0, 88775/88776/88777/88778 8.8) — configuration-dependent, not reported exploited. 88778 is fixed by enabling Enhanced ISN Generation, not by the upgrade alone.
Fixed builds: 14.1-73.37, 13.1-64.23 (13.1-64.24 if
show ns variablereturns anything — 13.1 has a reboot loop), 13.1-37.279 for the FIPS/NDcPP branch. No workaround published. Appliances already patched for CVE-2026-19490 remain vulnerable to this pair.Why this matters for APIARY
main.gois a merge hotspot for the per-CVE classifiers) — a conflicting-Content-Length/Transfer-Encoding request against the citrix surface is exactly the input it needs.Proposed detection
Signal A — pre-auth request-shape match (primary). No public PoC detail is reproduced here on purpose; instead, classify on shape:
Content-LengthalongsideTransfer-Encoding, duplicate CL with differing values) against the citrix surface → route to the 88773 smuggling class.;,`,$(,|) in a path or query against the citrix surface → 88771 class. This is coarse but it is the only signature available before a PoC stabilises, and the decoy costs nothing when it misfires.Signal B — transport-ordering recon. Flag source IPs that probe UDP/DTLS on the citrix address before any TCP connection, and any source that re-probes within a short window after a rejected management-path request. Attacker tooling for an edge appliance normally walks transports before payloads.
Signal C — device fingerprint divergence. Log TLS/HTTP fingerprint (JA3/JA4, ALPN, offered cipher order, cookie/
netscalebranding in responses) per source so a probe claiming to be a browser but presenting a non-browser TLS shape is queryable. No credential material is involved in either CVE — pure fingerprint divergence is the honest tell.Proposed Kibana query shape (field names to be mapped to the real schema; do not take this literally):
then group by
source.ipover a 15m window and surface the count of distinct decoys touched.Severity
Critical — CVSS 4.0 9.5 on both, unauthenticated, default configuration, remote, KEV-listed with confirmed global exploitation.
References
Note on scope
This issue is detection coverage only. It does not propose emulating the vulnerable code paths, and it does not ask for a working exploit reproduction on the decoy.