Urgent.News

What's breaking now, across thousands of outlets.

Tech

After the patch: verifying remediation for CVE-2026-88772 on NetScaler ADC and Gateway

After the patch: verifying remediation for CVE-2026-88772 on NetScaler ADC and Gateway A completed maintenance window and a remediated appliance are not the same claim. The Citrix NetScaler advisory CTX697096 of 27 September 2026, with CVE-2026-88771 and CVE-2026-88772 confirmed as exploited, sets a higher bar for what counts as done. Confirm the build, not the activity The first verification is…

Post-patch verification for CVE-2026-88772 on Citrix NetScaler ADC and Gateway requires more than just confirming the build version. Citrix's advisory CTX697096, issued 27 September 2026 for CVE-2026-88771 and CVE-2026-88772, sets a strict standard for what constitutes proper remediation. Rather than merely documenting the maintenance window, the focus must be on verifying the specific build numbers.

For NetScaler ADC and Gateway 14.1, the minimum acceptable version is 14.1-73.37, while for 13.1, the requirement is 13.1-64.23. For FIPS-enabled versions, 14.1-73.37 FIPS and 13.1-37.279 respectively meet the criteria. These build numbers must be verified on the live appliance, not merely the ticket status.

The two vulnerabilities in the bundle depend on different configurations. CVE-2026-88772 is triggered when DTLS is enabled, which is the default setting for VPN virtual servers. CVE-2026-88773 is activated by enabling HTTP. Other roles, including SSL VPN, ICA Proxy, CVPN, RDP Proxy, AAA virtual servers, Oracle-type load-balancing virtual servers, and configurations involving load-balancing, content-switching, or CGNAT LSN/NAT64 with non-HTTP Layer 7 protocols, also require verification.

After the upgrade, it's essential to re-check these prerequisites to account for any defaults that may have been inherited during object creation.

Preserving evidence before and after the patch is crucial. NCSC-NL recommends capturing relevant logs and a memory dump prior to the update. Post-patch, these should be reviewed alongside the indicators of compromise provided by Citrix on their console. It's not enough to merely note the firmware date in a remediation record; the full scope of the advisory's requirements must be documented.

This includes logs, the build string, the current configuration, and any crash material, all of which should be submitted with the change request.

When applying patches across an entire infrastructure, it's important to verify each appliance independently, including failover and standby units. Failover during an incident could potentially route traffic to the standby unit, which may not have been updated. Similarly, hybrid Secure Private Access deployments that utilize multiple NetScaler instances must be included in the verification process.

Finally, it's worth noting that even a successful verification does not rule out the possibility of exposure during the patching window, nor does it confirm that Citrix-managed components are within scope. These aspects should be carefully documented to ensure a comprehensive case closure.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Meetup Events Scraper: the search page ships its whole Apollo cache, and that is the API

Quick answer The Meetup Events Scraper pulls public Meetup.com events by keyword and city into JSON, CSV or Excel: title, start time with timezone, in-person or online, venue with coordinates, the…

  • Meetup Events Scraper retrieves public events via keyword searches and cities.
  • Scrapes normalized Apollo GraphQL cache from NEXTDATA script tag.
  • Provides 23 event fields, handles free and online events, costs $4.20 for 1,000 events.

More from Thursday 8 October →