🛡 VULNERABILIDADES 🛡

Advertencia: Dos vulnerabilidades RCE de día cero en Citrix NetScaler sin parches están siendo explotadas activamente.

🛡CyberObservatorio
Advertencia: Dos vulnerabilidades RCE de día cero en Citrix NetScaler sin parches están siendo explotadas activamente.
Idioma

Advertencia: Dos vulnerabilidades RCE de día cero en Citrix NetScaler sin parches están siendo explotadas activamente.

Fuente: The Hacker News

El 27 de septiembre de 2023, Citrix confirmó la existencia de dos vulnerabilidades críticas en sus productos NetScaler ADC y NetScaler Gateway que permiten la ejecución remota de código. Este anuncio es de suma importancia, ya que estas fallas podrían afectar a un amplio espectro de organizaciones que utilizan estas herramientas para gestionar el acceso remoto y la seguridad en sus redes empresariales. La confirmación de Citrix se produjo un día después de que la firma de seguridad watchTowr publicara información sobre la explotación de dos vulnerabilidades en NetScaler que no habían sido parcheadas, lo que llevó a varios administradores a desconectar sus dispositivos como medida preventiva.

Los dispositivos NetScaler ADC y NetScaler Gateway desempeñan un papel crucial en la infraestructura de redes de las empresas, ya que son responsables de gestionar el acceso remoto, el equilibrio de carga y la autenticación de usuarios. Las implicaciones de estas vulnerabilidades son significativas, ya que cualquier atacante no autenticado podría potencialmente ejecutar comandos arbitrarios en todos los despliegues afectados.

Las vulnerabilidades identificadas son las siguientes:

La primera, etiquetada como CVE-2026-88771, tiene un puntaje CVSS v4 de 9.5 y se trata de una falla en la validación de entradas que permite a un atacante ejecutar comandos arbitrarios sin necesidad de autenticación. Esta vulnerabilidad afecta a todas las implementaciones de NetScaler ADC y NetScaler Gateway, sin requerir características adicionales.

La segunda, CVE-2026-88772, también con un puntaje CVSS v4 de 9.5, es un desbordamiento de memoria que puede provocar la ejecución remota de código o un ataque de denegación de servicio (DoS). Esta falla afecta a los dispositivos con DTLS habilitado, que es la configuración predeterminada para los servidores VPN virtuales. Por lo tanto, cualquier NetScaler Gateway es susceptible de ser explotado a menos que DTLS haya sido desactivado de manera explícita.

Citrix advirtió que ya se han observado explotaciones de estas vulnerabilidades en implementaciones de NetScaler sin mitigaciones. Sin embargo, la compañía no ha proporcionado detalles sobre la magnitud de estas explotaciones ni sobre quiénes las están llevando a cabo.

El boletín emitido por Citrix es el primer aviso público sobre estas vulnerabilidades, lo que sugiere que ambas ya estaban siendo atacadas antes de que se hiciera público el parche. En este aviso no se ofrecen soluciones alternativas ni indicadores de compromiso. Se destaca que los dispositivos que operan con las versiones 14.1-73.32 y 13.1-63.21, que ya habían recibido una corrección para una vulnerabilidad de bypass de autenticación (CVE-2026-19490) en agosto, se encuentran dentro del rango afectado y requieren las nuevas actualizaciones.

Las correcciones están disponibles en las siguientes versiones, y Citrix ha instado a los clientes afectados a instalarlas lo antes posible:

- NetScaler ADC y NetScaler Gateway 14.1-73.37 y versiones posteriores. - NetScaler ADC y NetScaler Gateway 13.1-64.23 y versiones posteriores de la rama 13.1. - NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS y versiones posteriores. - NetScaler ADC 13.1-FIPS y 13.1-NDcPP 13.1-37.279 y versiones posteriores.

El boletín también abarca los dispositivos gestionados por los clientes, incluyendo las instancias de NetScaler utilizadas en implementaciones de acceso privado híbrido. Es importante mencionar que Citrix también actualiza sus propios servicios en la nube y la autenticación adaptativa gestionada por Citrix.

Adicionalmente, se identificaron seis vulnerabilidades más, que aunque no se listan como explotadas, presentan riesgos significativos:

- CVE-2026-88773 (puntaje CVSS v4: 9.3): falla de "HTTP request smuggling" en dispositivos con equilibrio de carga, conmutación de contenido, VPN o servidores virtuales de autenticación de tipo HTTP o SSL. - CVE-2026-88774 (puntaje CVSS v4: 7.0): bypass de políticas en dispositivos donde cualquier política utiliza una expresión basada en URL HTTP. - CVE-2026-88775 (puntaje CVSS v4: 8.8): desbordamiento de memoria que puede provocar comportamientos impredecibles o DoS en dispositivos configurados como Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) o un servidor virtual de autenticación, autorización y auditoría (AAA). - CVE-2026-88776 (puntaje CVSS v4: 8.8): desbordamiento de memoria en servidores virtuales de equilibrio de carga de tipo Oracle. - CVE-2026-88777 (puntaje CVSS v4: 8.8): desbordamiento de memoria en configuraciones de equilibrio de carga, conmutación de contenido o CGNAT-LSN/NAT64 con una función de protocolo de capa 7 no HTTP habilitada, como FTP, RTSP o DNS64. - CVE-2026-88778 (puntaje CVSS v4: 8.8): falla en la predicción del Número de Secuencia Inicial (ISN) TCP en dispositivos con servidores virtuales basados en TCP, como HTTP, SSL o TCP, donde la generación mejorada de ISN está desactivada. Citrix aconseja a los dispositivos afectados que apliquen un cambio en la configuración de TCP que lo active.

La primera publicación de watchTowr en X el 26 de septiembre mencionó que estaba reaccionando a rumores sobre varias vulnerabilidades en NetScaler que no habían sido parcheadas. En una publicación de seguimiento, se indicó que las dos vulnerabilidades fueron descubiertas durante investigaciones forenses y que se esperaban comunicaciones y parches de Citrix a principios de la semana del 28 de septiembre.

El 26 de septiembre, un administrador en el foro r/Citrix reportó que el equipo de seguridad de su proveedor de TI había llamado para aconsejarles que desconectaran inmediatamente sus NetScalers, sin ofrecer más detalles. Otros participantes en el hilo confirmaron que sus organizaciones habían tomado medidas similares. La fuente de la advertencia del proveedor no ha sido establecida.

Dado que las vulnerabilidades fueron explotadas antes de la publicación de un parche, la instalación de la actualización no permitirá determinar si un atacante ya había conseguido acceso antes.

En 2025, tras la explotación de una vulnerabilidad en NetScaler como un zero-day contra organizaciones holandesas, el Centro Nacional de Ciberseguridad de los Países Bajos advirtió que simplemente actualizar no eliminaba el riesgo, ya que un atacante podría mantener el acceso obtenido antes de la actualización, recomendando a los administradores ejecutar sus scripts de verificación.

La guía existente de Citrix para una posible compromisión de NetScaler sugiere que:

Se preserve la evidencia primero: una instantánea de una instancia VPX, los registros almacenados en servidores syslog remotos y en la consola de NetScaler, un paquete de soporte técnico y un volcado de núcleo del motor de paquetes.

Se aísle el aparato de la red.

Se cambien todas las contraseñas de cuentas de servicio y secretos almacenados, se restablezcan las contraseñas de los usuarios que hayan accedido a través de él, y se revoquen sus certificados y claves privadas.

Se mantenga la interfaz de gestión fuera de Internet. "Los Servicios de Gestión de NetScaler nunca deben estar expuestos a internet público", indica la guía.

Los scripts de verificación de la agencia holandesa de 2025, que cubren un dispositivo en funcionamiento, volcados de núcleo e imágenes completas de NetScaler, son una opción adicional, aunque con limitaciones.

El archivo README para el script de dispositivo en funcionamiento indica que busca archivos que sugieren un compromiso, no es específico para una vulnerabilidad y no garantiza eficacia. El código fue actualizado por última vez en septiembre de 2025.

The Hacker News ha solicitado comentarios a Cloud Software Group, la empresa que posee Citrix y NetScaler, así como a watchTowr, y actualizará la historia si recibe respuesta.

Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation

Source: The Hacker News

Two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway that allow remote code execution have been exploited in the wild, Citrix confirmed on September 27. It released fixes for both, along with six other flaws. One of the two affects every deployment on an affected version, including those in the default configuration. The bulletin came a day after security firm watchTowr said two unpatched NetScaler RCE flaws had been exploited, and after some administrators said they had taken appliances offline. Citrix did not say whether its two flaws are the ones watchTowr described, but they match that account. NetScaler ADC and NetScaler Gateway sit at the edge of enterprise networks, where they handle VPN and remote access, load balancing, and user authentication. Citrix said in itsbulletinthat the two exploited flaws are: CVE-2026-88771 (CVSS v4 score: 9.5)- An improper input validation flaw that lets an unauthenticated attacker run arbitrary commands. It affects all NetScaler ADC and NetScaler Gateway deployments, with no extra feature required. CVE-2026-88772 (CVSS v4 score: 9.5)- A memory overflow that can lead to remote code execution or denial-of-service (DoS). It affects appliances with DTLS enabled. DTLS is on by default for VPN virtual servers, so a NetScaler Gateway is affected unless DTLS has been explicitly turned off. "Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed," the company said. It did not say how widely the flaws have been exploited, by whom, or since when. The bulletin is Citrix's first public notice of the flaws, so both were attacked before a fix was public. It lists no workaround for either and no indicators of compromise. Appliances on 14.1-73.32 and 13.1-63.21, the builds that fixed the exploited authentication bypassCVE-2026-19490in August, fall inside the affected range and need the new update. The fixes are in the following versions, which Citrix urged affected customers to install as soon as possible: NetScaler ADC and NetScaler Gateway 14.1-73.37 and later releases NetScaler ADC and NetScaler Gateway 13.1-64.23 and later releases of 13.1 NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later releases of 13.1-FIPS and 13.1-NDcPP The bulletin covers customer-managed appliances, including NetScaler instances used in Secure Private Access Hybrid deployments. Citrix upgrades its own cloud services and Citrix-managed Adaptive Authentication. The 13.1 fix arrives after that branch reached End of Maintenance on September 15 underCitrix's release schedule. The six other flaws, which the bulletin does not list as exploited, are: CVE-2026-88773 (CVSS v4 score: 9.3)- An HTTP request smuggling flaw, on appliances with load balancing, content switching, VPN, or authentication virtual servers of type HTTP or SSL. CVE-2026-88774 (CVSS v4 score: 7.0)- A policy bypass, on appliances where any policy uses an HTTP URL-based expression. CVE-2026-88775 (CVSS v4 score: 8.8)- A memory overflow that can cause unpredictable behavior or DoS, on appliances configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or an authentication, authorization, and auditing (AAA) virtual server. CVE-2026-88776 (CVSS v4 score: 8.8)- A memory overflow that can cause unpredictable behavior or DoS, on load balancing virtual servers of type Oracle. CVE-2026-88777 (CVSS v4 score: 8.8)- A memory overflow that can cause unpredictable behavior or DoS, on load balancing, content switching, or CGNAT-LSN/NAT64 setups with a non-HTTP Layer 7 protocol feature, such as FTP, RTSP, or DNS64, enabled. CVE-2026-88778 (CVSS v4 score: 8.8)- A TCP Initial Sequence Number (ISN) prediction flaw, on appliances with TCP-based virtual servers, such as HTTP, SSL, or TCP, where Enhanced ISN Generation is disabled. Citrix advises affected appliances to apply aTCP configuration changethat turns it on. watchTowr's firstpost on Xon September 26 said it was reacting to rumors of several unpatched NetScaler RCE vulnerabilities in the wild. "While details are scarce, the information is credible," it wrote. Afollow-up postat 22:19 UTC said the two flaws were discovered during forensic investigations and that Citrix communications and patches were expected early in the week of September 28. On September 26, an administrator posting onr/Citrixwrote that their IT supplier's security team had phoned to advise shutting their NetScalers down immediately, without giving details. Others in the thread said their organizations had done the same. Where the suppliers' warning came from has not been established. Because the flaws were exploited before a fix was public, installing the update will not show whether an attacker got in first. In 2025, after a NetScaler flaw wasexploited as a zero-dayagainst Dutch organizations, the Netherlands' National Cyber Security Centresaidthat updating alone did not remove the risk, because an attacker could keep access gained before the patch, and told administrators to run its check scripts. Citrix's existingguidancefor a suspected NetScaler compromise says to: Preserve evidence first: a snapshot of a VPX instance, the logs held on remote syslog servers and NetScaler Console, a technical support bundle, and a core dump of the packet engine. Isolate the appliance from the network. Change every service account password and secret stored on it, reset the passwords of users who signed in through it, and revoke its certificates and private keys. Keep the management interface off the internet. "The NetScaler Management Services should never be exposed to the public internet," the guidance says. The Dutch agency's 2025 check scripts, which cover a live appliance, core dumps, and full NetScaler images, are a further option, with limits. TheREADMEfor the live-appliance script says it looks for files that indicate compromise, is not specific to one vulnerability, and comes with no guarantee of effectiveness. The code was last updated in September 2025. The Hacker News has asked Cloud Software Group, the company that owns Citrix and NetScaler, and watchTowr for comment, and will update the story if it hears back.

Advertencia: Dos vulnerabilidades RCE de día cero en Citrix NetScaler sin parches están siendo explotadas activamente. | Ciberseguridad - NarcoObservatorio