Skip to content

research: CVE-2026-88771/88772 Citrix NetScaler ADC+Gateway zero-day RCE pair (KEV 2026-09-27) — citrix-honeypot detection coverage #3467

Description

@Xore

Finding

CVE-2026-88771 + CVE-2026-88772 — Citrix NetScaler ADC / NetScaler Gateway zero-day RCE pair, actively exploited, added to CISA KEV on 2026-09-27.

Verified this run against the live CISA KEV feed (catalog version 2026.09.27, released 2026-09-27T21:30:35Z, 1728 entries):

CVE Vendor name in KEV Date added Score (CVSS 4.0) Primitive Precondition
CVE-2026-88771 Improper Input Validation Vulnerability 2026-09-27 9.5 Critical Unauthenticated arbitrary command execution on the appliance None — default configuration affected, no feature to enable
CVE-2026-88772 Improper Restriction of Operations within the Bounds of a Memory Buffer 2026-09-27 9.5 Critical Memory overflow → RCE or DoS DTLS enabled (default on VPN virtual servers)

Both are zero-days: the exploitation was found in forensic investigations before any CVE existed, surfaced publicly 2026-09-26 (NCSC-NL private pre-notification, watchTowr Rapid Reaction warning), and Citrix published the bulletin CTX697096 on 2026-09-27. Each is independently sufficient for RCE. Six further CVEs ship in the same bulletin (88773 HTTP request smuggling 9.3, 88774 7.0, 88775/88776/88777/88778 8.8) — configuration-dependent, not reported exploited. 88778 is fixed by enabling Enhanced ISN Generation, not by the upgrade alone.

Fixed builds: 14.1-73.37, 13.1-64.23 (13.1-64.24 if show ns variable returns anything — 13.1 has a reboot loop), 13.1-37.279 for the FIPS/NDcPP branch. No workaround published. Appliances already patched for CVE-2026-19490 remain vulnerable to this pair.

Why this matters for APIARY

  1. It is the same surface we already decoy, at a much higher value. The prior Citrix work (research: CVE-2026-19490 Citrix NetScaler auth bypass exploited in the wild — citrix-honeypot detection coverage #2977, citrix-honeypot: present the NetScaler AAA/SAML/OAuth surface (ungated), and classify CVE-2026-19490 once its request shape is confirmed #3032) covered an auth bypass on the AAA/Gateway surface — that is a credential-free probe. This pair is unauthenticated command execution on the appliance, default-config, no feature flag. A hit on a citrix-honeypot endpoint is now a materially stronger signal than it was two weeks ago and should outrank generic login-failure events in triage.
  2. The vendor explicitly warns the IOC scan is incomplete ("a clean result is not proof"). That argument for external decoys gets stronger, not weaker — this is exactly the case where an internal appliance tells you "clean" and an internet-facing decoy tells you what the probe actually looks like.
  3. 88772 is the one to watch on our side. DTLS is a UDP transport our surface does not currently exercise. A NetScaler that probes for DTLS before it probes HTTP is fingerprinting the appliance, not using it. Classifying that as an ordered-recon event — rather than as scan noise — is cheap now and expensive later.
  4. 88773 (request smuggling, same bulletin, 9.3) is a classifier, not a firewall rule. It is directly in scope for the existing HTTP payload-classification work (see main.go is a merge hotspot: split http-honeypot CVE classifiers into one file per CVE #3464, which notes main.go is a merge hotspot for the per-CVE classifiers) — a conflicting-Content-Length/Transfer-Encoding request against the citrix surface is exactly the input it needs.

Proposed detection

Signal A — pre-auth request-shape match (primary). No public PoC detail is reproduced here on purpose; instead, classify on shape:

  • Any citrix-honeypot request that reaches a management/config path with no preceding session-establishment request. Our decoy does not serve management paths, so a probe there is a fingerprint, not a user.
  • Requests with contradictory framing headers (Content-Length alongside Transfer-Encoding, duplicate CL with differing values) against the citrix surface → route to the 88773 smuggling class.
  • Any request carrying a shell metacharacter burst (;, `, $(, |) in a path or query against the citrix surface → 88771 class. This is coarse but it is the only signature available before a PoC stabilises, and the decoy costs nothing when it misfires.

Signal B — transport-ordering recon. Flag source IPs that probe UDP/DTLS on the citrix address before any TCP connection, and any source that re-probes within a short window after a rejected management-path request. Attacker tooling for an edge appliance normally walks transports before payloads.

Signal C — device fingerprint divergence. Log TLS/HTTP fingerprint (JA3/JA4, ALPN, offered cipher order, cookie/netscale branding in responses) per source so a probe claiming to be a browser but presenting a non-browser TLS shape is queryable. No credential material is involved in either CVE — pure fingerprint divergence is the honest tell.

Proposed Kibana query shape (field names to be mapped to the real schema; do not take this literally):

sensor: citrix-honeypot
AND ( path_preauth_management: true
      OR framing_conflict: true
      OR shell_metachars_in_path: true )

then group by source.ip over a 15m window and surface the count of distinct decoys touched.

Severity

Critical — CVSS 4.0 9.5 on both, unauthenticated, default configuration, remote, KEV-listed with confirmed global exploitation.

References

Note on scope

This issue is detection coverage only. It does not propose emulating the vulnerable code paths, and it does not ask for a working exploit reproduction on the decoy.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    honeypotHoneypot sensor or deception technologyresearchResearch findings or reportssecuritySecurity hardening or a security defect

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions