CTIPilot

Citrix NetScaler

product · product:citrix-netscaler

Also known as: NetScaler ADC, NetScaler Gateway

Coverage timeline
4
first 2026-07-01 → last 2026-08-20
Peak priority
high
4 high
Sources cited
18
16 hosts
Sections touched
3
active-threats, deep-dive, trending-vulnerabilities
Co-occurring entities
8
see Co-occurring entities below
ATT&CK techniques
20
pinned v19.2 · see below

ATT&CK techniques

20 techniques observed across 4 entries, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Reconnaissance TA0043

T1595Active Scanning×1

Adversaries may execute active reconnaissance scans to gather information that can be used during targeting. Active scans are those where the adversary probes victim infrastructure via network traffic, as opposed to other forms of reconnaissance that do not involve direct interaction.

Evidence: 2026-07-31/unit42-autonomous-deepseek-hermes-netscaler-cve-2026-3055 · ATT&CK page ↗

T1595.002Active Scanning: Vulnerability Scanning×1

Adversaries may scan victims for vulnerabilities that can be used during targeting. Vulnerability scans typically check if the configuration of a target host/application (ex: software and version) potentially aligns with the target of a specific exploit the adversary may seek to use.

Evidence: 2026-07-31/unit42-autonomous-deepseek-hermes-netscaler-cve-2026-3055 · ATT&CK page ↗

Resource Development TA0042

T1588.005Obtain Capabilities: Exploits×1

Adversaries may buy, steal, or download exploits that can be used during targeting. An exploit takes advantage of a bug or vulnerability in order to cause unintended or unanticipated behavior to occur on computer hardware or software. Rather than developing their own exploits, an adversary may find/modify exploits from online or purchase them from exploit vendors.

Evidence: 2026-07-31/unit42-autonomous-deepseek-hermes-netscaler-cve-2026-3055 · ATT&CK page ↗

Initial Access TA0001

T1190Exploit Public-Facing Application×4

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-08-20/cve-2026-19490-netscaler-gateway-aaa-auth-bypass · 2026-07-31/unit42-autonomous-deepseek-hermes-netscaler-cve-2026-3055 · 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · 2026-07-01/cve-2026-8451-citrix-netscaler-adc-gateway-pre-auth-saml-mem · ATT&CK page ↗

Execution TA0002

T1059Command and Scripting Interpreter×1

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell.

Evidence: 2026-07-31/unit42-autonomous-deepseek-hermes-netscaler-cve-2026-3055 · ATT&CK page ↗

Persistence TA0003

T1098Account Manipulation×1

Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include account activity designed to subvert security policies, such as performing iterative password updates to bypass password duration policies and preserve the life of compromised credentials.

Evidence: 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · ATT&CK page ↗

T1112Modify Registry×1

Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.

Evidence: 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · ATT&CK page ↗

T1136.001Create Account: Local Account×1

Adversaries may create a local account to maintain access to victim systems. Local accounts are those configured by an organization for use by users, remote support, services, or for administration on a single system or service.

Evidence: 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · ATT&CK page ↗

T1505.003Server Software Component: Web Shell×1

Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.

Evidence: 2026-07-01/cve-2026-8451-citrix-netscaler-adc-gateway-pre-auth-saml-mem · ATT&CK page ↗

Privilege Escalation TA0004

T1068Exploitation for Privilege Escalation×2

Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.

Evidence: 2026-07-31/unit42-autonomous-deepseek-hermes-netscaler-cve-2026-3055 · 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · ATT&CK page ↗

T1098Account Manipulation×1

Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include account activity designed to subvert security policies, such as performing iterative password updates to bypass password duration policies and preserve the life of compromised credentials.

Evidence: 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · ATT&CK page ↗

T1548.001Abuse Elevation Control Mechanism: Setuid and Setgid×1

An adversary may abuse configurations where an application has the setuid or setgid bits set in order to get code running in a different (and possibly more privileged) user’s context. On Linux or macOS, when the setuid or setgid bits are set for an application binary, the application will run with the privileges of the owning user or group respectively. Normally an application is run in the current user’s context, regardless of which user or group owns the application. However, there are instances where programs need to be executed in an elevated context to function properly, but the user running them may not have the specific required privileges.

Evidence: 2026-07-01/cve-2026-8451-citrix-netscaler-adc-gateway-pre-auth-saml-mem · ATT&CK page ↗

Stealth TA0005

T1070Indicator Removal×1

Adversaries may selectively delete or modify artifacts generated to reduce indications of their presence and blend in with legitimate activity. Rather than broadly removing evidence, adversaries may target specific artifacts that appear anomalous or are likely to draw scrutiny, while leaving sufficient data intact to maintain the appearance of normal system behavior.

Evidence: 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · ATT&CK page ↗

Defense Impairment TA0112

T1112Modify Registry×1

Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.

Evidence: 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · ATT&CK page ↗

Credential Access TA0006

T1003OS Credential Dumping×1

Adversaries may attempt to dump credentials to obtain account login and credential material, normally in the form of a hash or a clear text password. Credentials can be obtained from OS caches, memory, or structures. Credentials can then be used to perform Lateral Movement and access restricted information.

Evidence: 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · ATT&CK page ↗

T1539Steal Web Session Cookie×1

An adversary may steal web application or service session cookies and use them to gain access to web applications or Internet services as an authenticated user without needing credentials. Web applications and services often use session cookies as an authentication token after a user has authenticated to a website.

Evidence: 2026-07-31/unit42-autonomous-deepseek-hermes-netscaler-cve-2026-3055 · ATT&CK page ↗

Lateral Movement TA0008

T1550.001Use Alternate Authentication Material: Application Access Token×1

Adversaries may use stolen application access tokens to bypass the typical authentication process and access restricted accounts, information, or services on remote systems. These tokens are typically stolen from users or services and used in lieu of login credentials.

Evidence: 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · ATT&CK page ↗

T1570Lateral Tool Transfer×1

Adversaries may transfer tools or other files between systems in a compromised environment. Once brought into the victim environment (i.e., Ingress Tool Transfer) files may then be copied from one system to another to stage adversary tools or other files over the course of an operation.

Evidence: 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · ATT&CK page ↗

Command and Control TA0011

T1090.003Proxy: Multi-hop Proxy×1

Adversaries may chain together multiple proxies to disguise the source of malicious traffic. Typically, a defender will be able to identify the last proxy traffic traversed before it enters their network; the defender may or may not be able to identify any previous proxies before the last-hop proxy. This technique makes identifying the original source of the malicious traffic even more difficult by requiring the defender to trace malicious traffic through several proxies to identify its source.

Evidence: 2026-07-31/unit42-autonomous-deepseek-hermes-netscaler-cve-2026-3055 · ATT&CK page ↗

T1102Web Service×1

Adversaries may use an existing, legitimate external Web service as a means for relaying data to/from a compromised system. Popular websites, cloud services, and social media acting as a mechanism for C2 may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to a compromise. Using common services, such as those offered by Google, Microsoft, or Twitter, makes it easier for adversaries to hide in expected noise. Web service providers commonly use SSL/TLS encryption, giving adversaries an added level of protection.

Evidence: 2026-07-31/unit42-autonomous-deepseek-hermes-netscaler-cve-2026-3055 · ATT&CK page ↗

T1219Remote Access Tools×1

An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network. Remote access tools create a session between two trusted hosts through a graphical interface, a command line interaction, a protocol tunnel via development or management software, or hardware-level access such as KVM (Keyboard, Video, Mouse) over IP solutions. Desktop support software (usually graphical interface) and remote management software (typically command line interface) allow a user to control a computer remotely as if they are a local user inheriting the user or software permissions. This software is commonly used for troubleshooting, software installation, and system management. Adversaries may similarly abuse response features included in EDR and other defensive tools that enable remote access.

Evidence: 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · ATT&CK page ↗

Impact TA0040

T1486Data Encrypted for Impact×1

Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.

Evidence: 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · ATT&CK page ↗

Story timeline

  1. 2026-08-20CVE-2026-19490, Citrix NetScaler: an authentication bypass on Gateway and AAA virtual servers (CVSS 9.3), and on older builds no SAML configuration is needed to be exposed
    trending-vulnerabilitiesThe precondition is wider than the headline version numbers suggest; on older builds a Gateway or AAA vserver alone is enough
  2. 2026-07-31Unit 42 recovers a live autonomous-AI attack operation after it exposed its own home directory, the confirmed compromises came from manual Citrix NetScaler exploitation (CVE-2026-3055), not the agent
    active-threatsThe autonomous agent attacked at scale and landed nothing; the same operator's hand-driven NetScaler exploitation took data from three organisations
  3. 2026-07-10CitrixBleed 2 (CVE-2025-5777) weaponised into a repeatable IAB kill chain ending in DragonForce ransomware (STAC3725)
    deep-diveHuntress reconstructs a productised CitrixBleed 2-to-DragonForce runbook: token theft, a registry-symlink SYSTEM escalation, then ransomware
  4. 2026-07-01CVE-2026-8451, Citrix NetScaler ADC/Gateway: pre-auth SAML memory overread (CitrixBleed lineage), public PoC
    trending-vulnerabilities

Where this entity is cited

  • trending-vulnerabilities2
  • deep-dive1
  • active-threats1

Source distribution

  • labs.watchtowr.com3 (17%)
  • 0patch.com1 (6%)
  • advisories.ncsc.nl1 (6%)
  • api.first.org1 (6%)
  • cert.europa.eu1 (6%)
  • cisa.gov1 (6%)
  • cyberscoop.com1 (6%)
  • euvd.enisa.europa.eu1 (6%)
  • other8 (44%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

All cited sources (18)

Entries about Citrix NetScaler (4)

2026-07-01 · view entry permalink →

HIGHCVE-2026-8451 +1exploitedupdatedNATOA1

CVE-2026-8451, Citrix NetScaler ADC/Gateway: pre-auth SAML memory overread (CitrixBleed lineage), public PoC

Citrix's 2026-06-30 bulletin CTX696604 fixes six NetScaler ADC/Gateway CVEs. The headline flaw, CVE-2026-8451 (CVSS 8.8), is a pre-authentication out-of-bounds read reported by watchTowr Labs in the hand-rolled XML attribute parser behind the /saml/login endpoint, reachable only when the appliance is configured as a SAML Identity Provider (watchTowr Labs, 2026-06-30). The parser terminates unquoted attribute values only on NUL, > or a matching quote (not on whitespace/newline) so an unterminated attribute in a crafted SAML AuthnRequest walks the parser past the buffer boundary; the over-read bytes are returned to the unauthenticated client inside the NSC_TASS response cookie, leaking adjacent process memory one request at a time. This is the fourth CitrixBleed-class memory-safety defect in NetScaler's auth code paths that watchTowr has documented (after CVE-2025-5777, CVE-2025-12101 and the March-2026 CVE-2026-3055); watchTowr released a "Detection Artefact Generator" on GitHub that produces the malformed request so operators can test their own exposure, and no in-the-wild exploitation of CVE-2026-8451 was confirmed at disclosure (watchTowr Labs, 2026-06-30 · CyberScoop, 2026-06-30). The companion CVEs span additional memory overread with TCP TimeStamp enabled (CVE-2026-10817), DoS/undefined-control-flow memory-management issues in Gateway/DNS-proxy/AAA vserver configs (CVE-2026-8452, CVE-2026-8655), an unauthenticated arbitrary file read in the Management Interface (CVE-2026-10816), and CVE-2026-13474. Affected: 14.1 before 14.1-72.61 and 13.1 before 13.1-63.18 (plus FIPS builds); patches are available. NCSC-NL issued advisory NCSC-2026-0216 (NCSC-NL, 2026-06-30).

However, we believe this is CVE-2026-8452 given its description as a “Memory Overflow” vulnerability.

the vulnerability we’re discussing today is reachable when the Netscaler appliance is configured to use SAML as either a Service Provider (SP) or an Identity Provider (IdP).

During signature canonicalization, earlier versions of the NetScaler solution copy attacker-controlled data from the SAML message's ds:SignedInfo element into a fixed-size global buffer, without checking whether it actually fits.

So we now have a memcpy copying from our packet to any address we want, which is a write-what-where primitive.

nsppe already runs as root, so our shellcode executes as root too.

watchTowr Labs

Actively Exploited, Proof of Concept Available

NCSC Switzerland, Cyber Security Hub, advisory of 2026-07-03 on CVE-2026-8451

A new technical analysis, likely related to CVE-2026-8452, was published by Watchtowr

NCSC Switzerland, Cyber Security Hub, update of 2026-08-14

Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability which could lead to denial of service.

CISA Known Exploited Vulnerabilities Catalog
Updaterun 2026-08-15T0412Z-intelactionsaffected_productscvesevidenceregionssectorssourcestagstechniquesbody

The original entry covered Citrix's six-CVE NetScaler bulletin and its headline flaw CVE-2026-8451, a pre-authentication memory overread in the SAML /saml/login parser, and described the companion CVE-2026-8452 as a denial-of-service and undefined-control-flow memory-management issue in Gateway and AAA vserver configurations. That description was faithful to the vendor's CVE record and is now known to be a serious understatement. Two deltas follow, and the second is a correction to this pipeline's own record.

The bug published as a memory-overflow issue is a pre-authentication root shell. watchTowr identifies its target from the public record's own wording, writing that "we believe this is CVE-2026-8452 given its description as a “Memory Overflow” vulnerability", the same sparse framing behind the denial-of-service characterisation this pipeline carried on 1 July from Citrix's bulletin. On 2026-08-14 watchTowr Labs published a chain that ends in a root command shell, entirely pre-authentication (watchTowr Labs, 2026-08-14). The identifier is an inference rather than a confirmation, watchTowr says so plainly, and Switzerland's NCSC describes the work as "A new technical analysis, likely related to CVE-2026-8452, was published by Watchtowr" (NCSC-CH, 2026-08-14), but the bug watchTowr analysed is fixed by the same release, so the operational conclusion does not depend on resolving the mapping.

The kill chain. The defect is in SAML signature canonicalization: "During signature canonicalization, earlier versions of the NetScaler solution copy attacker-controlled data from the SAML message's ds:SignedInfo element into a fixed-size global buffer, without checking whether it actually fits" (watchTowr Labs, 2026-08-14). The attacker-controlled field is the PrefixList attribute of the InclusiveNamespaces element inside the ds:SignedInfo block, and the copy target sits in nsppe, NetScaler's packet-processing engine. An oversized value overflows linearly into the header of the adjacent chunk in the appliance's network-buffer pool, corrupting that neighbour's data-pointer and freelist-link fields. The corruption becomes an attacker primitive later, when the packet engine retrieves that chunk and performs a memcpy using the corrupted pointer as its destination with an attacker-influenced length: "So we now have a memcpy copying from our packet to any address we want, which is a write-what-where primitive." From there the exploit is unusually cheap, because the target offers almost no mitigations ("The nsppe binary lacks almost all of the protections you'd hope to find, and the heap is executable, for reasons known only to Citrix") so watchTowr redirected execution into shellcode placed on a heap that is both executable and at a fixed address, and "nsppe already runs as root, so our shellcode executes as root too."

Two engineering details in the chain matter to defenders more than the memory corruption does. First, an nsppe crash normally triggers a full appliance reboot through a watchdog process, which would destroy anything the attacker dropped; watchTowr neutralised the packet engine's crash-signal handlers so the watchdog merely respawned the process instead of rebooting the box, letting a dropped PHP webshell survive. Second, because the web server executing that webshell runs as an unprivileged account while nsppe runs as root, the exploit set the SUID bit on /bin/sh from the root shellcode so that commands issued through the webshell execute with a root effective UID (watchTowr Labs, 2026-08-14). The result is durable root that survives the process restart an operator would most likely dismiss as a glitch.

Reachability. watchTowr states the vulnerability "is reachable when the Netscaler appliance is configured to use SAML as either a Service Provider (SP) or an Identity Provider (IdP)" (watchTowr Labs, 2026-08-14), which, in the deployment terms Citrix's bulletin used and this pipeline recorded on 1 July, is any appliance acting as a Gateway or AAA virtual server. That is the ordinary shape of a remote-access appliance in a European government or critical-infrastructure network, and it is broader than the sibling flaw's precondition: NCSC-CH records that one as requiring the appliance to be configured as a SAML Identity Provider specifically (NCSC-CH, advisory of 2026-07-03). Affected are NetScaler ADC and Gateway 14.1 before 14.1-72.61 and 13.1 before 13.1-63.18, and both CVE records additionally list the FIPS and NDcPP builds, 14.1 FIPS before 14.1-72.61 and 13.1 FIPS/NDcPP before 13.1-37.272, a different fixed build that an estate running certified appliances has to check for separately. Both flaws were fixed together in that June/July release. No party reports in-the-wild exploitation of the code-execution chain.

The correction. The original entry recorded that no in-the-wild exploitation of CVE-2026-8451 was confirmed at disclosure. NCSC-CH's advisory on that flaw, timestamped 2026-07-03, states its current exploitation status as "Actively Exploited, Proof of Concept Available", and cites reporting that it was exploited immediately after public disclosure (NCSC-CH, advisory of 2026-07-03, updated 2026-08-14). That status has stood since early July and this pipeline did not carry it, so an estate that read the 1 July entry and concluded the memory-overread flaw was unexploited was working from a stale picture for six weeks. The exploitation is not new; the record here was wrong.

Triage: the distinctive telemetry is a crash that does not behave like a NetScaler crash. In appliance system and error logs, an nsppe process restart without the full appliance reboot that normally follows one is the signature this exploit deliberately produces, and it is worth correlating against inbound SAML authentication attempts in the same interval. On the request side, SAML AuthnRequest and Response bodies carrying an anomalously large InclusiveNamespaces PrefixList attribute inside a SignedInfo block are the delivery shape; legitimate SAML messages carry short namespace-prefix lists, so length is a usable discriminator here rather than a heuristic. Where any host-level telemetry is available from the appliance, a shell process spawned by the web server is decisive: a NetScaler web server has no legitimate reason to spawn a shell, and the SUID step means the shell will carry a root effective UID under a process that should never have one.

Updaterun 2026-08-28T0409Z-intelcvesbody

CISA added CVE-2026-8452 to its Known Exploited Vulnerabilities catalog on 2026-08-26: "Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability which could lead to denial of service" (CISA Known Exploited Vulnerabilities Catalog, 2026-08-26). This is the first authoritative confirmation that CVE-2026-8452 specifically is under active exploitation, closing the gap the prior update left open when watchTowr said only that it "believes but cannot confirm" its pre-authentication root-shell chain maps to this identifier, and NCSC-CH called the analysis merely "likely related." The KEV addition does not itself confirm which exploitation activity is occurring (CISA's own description still reads as a memory-safety/denial-of-service issue, the same sparse framing that understated the flaw's true severity in the first place) but it does establish exploitation in the wild of the CVE watchTowr's root-shell chain is believed to target.

No new patch action follows: CVE-2026-8452 is fixed in the same NetScaler 14.1-72.61 / 13.1-63.18 (13.1-37.272 on the FIPS/NDcPP train) release already recommended for CVE-2026-8451, so an estate that completed that upgrade is already remediated against both. Any appliance still unpatched, or whose upgrade was deferred on the assumption that CVE-2026-8452 was availability-only, should now be treated as having a confirmed unauthenticated remote-code-execution exposure under active exploitation rather than a theoretical one, and the compromise-assessment guidance already carried in this entry's actions applies with the same urgency to CVE-2026-8452 as to CVE-2026-8451.

vulnerability01 Jul 04:41Zmulti-sourceOpen finding ↗

2026-08-20 · view entry permalink →

CVE-2026-19490, Citrix NetScaler: an authentication bypass on Gateway and AAA virtual servers (CVSS 9.3), and on older builds no SAML configuration is needed to be exposed

Citrix published a security bulletin on 2026-08-19 covering two vulnerabilities in NetScaler ADC and NetScaler Gateway, and CERT-EU issued its own advisory for its constituency the same day, recommending that affected devices be updated as soon as possible (CERT-EU, 2026-08-19). The more serious of the two, CVE-2026-19490, is described as an authentication bypass using an alternate path and scored 9.3 (CERT-EU, 2026-08-19), a CVSS v4.0 base score, per Rapid7's analysis of the same advisory (Rapid7, 2026-08-19). It applies where the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN or RDP Proxy) or as an AAA virtual server, which is the configuration that fronts remote access and authentication brokering for the network behind it.

The part that decides how much of an estate is exposed is version-dependent, and it cuts the wrong way for anyone behind on builds: on 14.1-43.56 or later and 13.1-61.28 or later the flaw applies only when a SAML action is configured, but on earlier builds and on 13.1 FIPS, a Gateway or AAA virtual server configuration is sufficient on its own (CERT-EU, 2026-08-19). An operator who checks only for SAML and concludes they are unaffected will be wrong on exactly the appliances that are furthest behind. The second flaw, CVE-2026-19489, is a memory overflow that can lead to unpredictable behaviour or denial of service, and it is reachable only where SIP ALG is enabled inside a Large Scale NAT group configuration (CERT-EU, 2026-08-19).

Detection here is thin by nature; an authentication bypass on an appliance leaves no failed-credential trail, because the point of it is that the credential step does not happen. The telemetry class that carries signal is the authentication and session record on the Gateway or AAA virtual server itself: a session established for a user identity with no preceding credential-validation or SAML assertion-processing event for that same session, and session establishment from addresses or client profiles that do not match the population that normally reaches the appliance. Because CVE-2026-19489 manifests as unpredictable behaviour or a service failure rather than as a login, an unexplained NetScaler restart or packet-engine fault on an appliance carrying an LSN group with SIP ALG belongs in the same review rather than in capacity triage. Fixed builds are 14.1-73.32, 13.1-63.21, 14.1-73.32 FIPS and 13.1-37.277 (Rapid7, 2026-08-19); where CVE-2026-19489 cannot be patched immediately, SIP ALG on LSN groups that do not need it is a configuration that can simply be turned off.

The vulnerability CVE-2026-19490 (CVSS: 9.3) is an authentication bypass using an alternate path.

CERT-EU 2026-08-19

As of August 19, 2026, Rapid7 has not observed evidence that CVE-2026-19490 is being exploited in the wild. However, organizations should prioritize patching affected systems on an emergency basis, since Citrix products are high-value targets that tend to quickly see exploitation in the wild.

Rapid7 2026-08-19

Builds on: 2026-07-01/cve-2026-8451-citrix-netscaler-adc-gateway-pre-auth-saml-mem

vulnerability20 Aug 04:33Zmulti-sourceOpen finding ↗
Sources: CERT-EU · Rapid7

2026-07-31 · view entry permalink →

HIGHCVE-2026-3055 +2exploitedupdatedNATOB2

Unit 42 recovers a live autonomous-AI attack operation after it exposed its own home directory, the confirmed compromises came from manual Citrix NetScaler exploitation (CVE-2026-3055), not the agent

Palo Alto Unit 42 published an unusually complete reconstruction of a live offensive operation on 2026-07-30, made possible by the operator's own mistake: its agent framework, acting on a command sent over Telegram, started an HTTP file server from the operator's home directory rather than an isolated staging path, exposing AI tool configurations, API keys, exploit scripts, target lists, shell history and the agent's own session logs (Unit 42, 2026-07-30). Unit 42 notes this was out of character; the same operator had emptied exploit directories after use and disabled conversation logging in one of its tools.

The operator, who uses the handles knaithe and KnYuan and describes themselves as a Zhuhai-based binary-security researcher, ran DeepSeek as the reasoning engine behind the open-source Hermes Agent, extended with three capabilities: a framework-bundled jailbreak skill, a custom module for attacking unauthenticated WebSocket endpoints, and a custom procedure that drives internet-wide asset enumeration through a scanning service, wired to a natural-language-to-search-query translator exposed to the agent as a tool.

The result is the part worth reading carefully. Unit 42 states it could confirm only three successful exploitations across every attempt, autonomous and manual, and identifies those three as the Citrix NetScaler cases. Both fully autonomous exploitation attempts failed. Against Langflow, the agent needed either a login-bypass setting enabled or a public flow identifier and found neither; against n8n (which its scanning put at 647,017 instances globally and 25,209 in China) it worked the Chinese slice, sampled about a hundred, probed roughly forty, found three candidates, and was stopped because the unauthenticated form endpoint the exploit chain required was behind authentication on every one. Unit 42's own reading is that the failures were target-side configuration, not defensive detection, and that targets with weaker defaults would have been compromised, a hardening finding rather than a ceiling on the capability. The agent's decision-making is visible in the recovered logs: it abandoned the Langflow target set after assessing the deployment population as too small to be worth the effort and pivoted to a more widely deployed product on its own.

What actually worked was hand-driven. Using CVE-2026-3055, an out-of-bounds memory read in Citrix NetScaler ADC and Gateway, the operator exfiltrated appliance memory from three organisations and searched the recovered bytes for NetScaler authentication cookies, which Unit 42 reads as session-hijacking intent. It describes persistent multi-day targeting of a Malaysian government entity using memory-grooming parameters and maximum read attempts, with the operator returning behind proxy anonymisation on later attempts, behaviour it contrasts with the autonomous campaigns, which hit Chinese domestic infrastructure indiscriminately. Other manual activity included command execution against Marimo notebook instances, deserialization reverse-shell attempts against Tomcat servers and callbacks against Windows IKE VPN endpoints; a cloned PAN-OS exploit was non-functional, carrying placeholder values that cannot achieve code execution, with no evidence of modification or execution found.

The CVE itself deserves separate attention from the AI story, because it is the element with direct constituency exposure. It affects NetScaler ADC and Gateway only when the appliance is configured as a SAML Identity Provider; a precondition Unit 42 does not mention and which comes from the vulnerability record and the vendor's bulletin (Citrix, 2026-03-23). It is KEV-listed, and watchTowr's honeypot network observed exploitation from known threat-actor addresses as of 2026-03-27, months before and unrelated to this operator (watchTowr Labs, 2026-03-29). watchTowr also documents a second overread path under the same CVE reachable through a different endpoint, so an operator validating exposure should not assume a single request signature covers it.

Unit 42 also reports that the operator routed two Western tools, Claude Code and Codex, through a third-party proxy with attribution headers disabled and response storage turned off. It says Claude Code was used only for connectivity testing and proxy validation, its session history holding model checks, connectivity tests and one package-install request across three sessions, and that there were signs of Codex use in exploit-development directories though those chat logs were not preserved, and it relays OpenAI's confirmation that its provider-side safeguards refused the policy-violating requests and that its safety systems flagged and disabled the linked account before Unit 42 shared intelligence. Unit 42's inference is that the operator chose the model with the fewest controls for the autonomous engine precisely because provider-side controls limited the alternatives.

Detection. For the NetScaler exposure the observable is in the appliance's own web logs: repeated requests to the SAML identity-provider endpoints from a single source, returning responses whose length varies request to request, with no corresponding completed authentication; memory-overread harvesting looks like a failing login loop that never fails cleanly. Follow it with authentication telemetry: a session cookie presented from an address or client fingerprint that never performed the sign-in that minted it is the downstream consequence the operator was working toward. More broadly, the enumeration behaviour Unit 42 describes leaves an approach signature worth hunting on any exposed application, high-volume version-fingerprinting requests from a narrow address set, followed within a short window by a small number of precisely-targeted exploit attempts against just the instances whose version replied in scope.

Triage: scanning noise against edge appliances is constant, so volume alone discriminates nothing. Two things separate this from background scanning: the requests target the specific identity-provider paths rather than sweeping the whole surface, and successful reads produce responses that are neither errors nor valid authentication outcomes. On the enumeration side, ordinary vulnerability scanners announce themselves through breadth and user-agent consistency; what Unit 42 describes is narrow, sequenced and selective, a fingerprint pass followed by exploitation of only the matching subset.

Across all the exploitation attempts, both autonomous and manual, Unit 42 was only able to confirm three targets were successfully exploited.

The three successful exploitations had memory data exfiltrated through the Citrix NetScaler out-of-bounds memory read vulnerability (CVE-2026-3055). The actor searched the exfiltrated data for NetScaler authentication cookies (NSC_AAAC=), indicating session hijacking intent.

Autonomous AI-driven attack cycles are operationally viable, and the margin of failure was narrow: Exploitation was prevented by target-side configuration requirements, the absence of prerequisite workflow configurations (Langflow) and authentication on form endpoints (n8n). Targets with weaker default configurations would have been susceptible.

Unit 42 (Palo Alto Networks) 2026-07-30

Across all the exploitation attempts, both autonomous and manual, Unit 42 confirmed data exfiltration from three Citrix NetScaler targets (CVE-2026-3055) and command execution on 11 Marimo notebook endpoints (CVE-2026-39987).

Unit 42

This is a pre-authentication double free in ikeext.dll, the module behind the "IKE and AuthIP IPsec Keying Modules" service, which runs as Local System inside a svchost.exe. The flaw is in function IkeReinjectReassembledPacket, on the IKEv2 fragment reassembly path.

We recreated a POC from the official patch, which allowed us to reproduce the issue and create patches

0patch (ACROS Security) 2026-08-05

An unauthenticated attacker could send specially crafted packets to a Windows machine with Internet Key Exchange (IKE) version 2 enabled, which could enable remote code execution.

Microsoft Security Response Center 2026-04-14

Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.

CISA Known Exploited Vulnerabilities catalog

Block inbound traffic on UDP ports 500 and 4500 for systems that do not use IKE.

For systems that require IKE, configure firewall rules to allow inbound traffic on UDP ports 500 and 4500 only from known peer addresses.

Microsoft Security Response Center 2026-04-14
Correctionrun 2026-08-02T1309Z-auditactionsaffected_productscvesevidencetagstechniquesbody

The original entry understated the campaign's confirmed impact, and it did so on the strength of a quotation Unit 42 did not write.

The original entry carried, inside quotation marks and attributed to Unit 42, a sentence reading "Across all the exploitation attempts, both autonomous and manual, Unit 42 was only able to confirm three targets were successfully exploited." Unit 42's actual sentence, at the same point in the post, is "Across all the exploitation attempts, both autonomous and manual, Unit 42 confirmed data exfiltration from three Citrix NetScaler targets (CVE-2026-3055) and command execution on 11 Marimo notebook endpoints (CVE-2026-39987)" (Unit 42, 2026-07-30). The fabricated version dropped the second half of the finding and added a limiting phrase ("was only able to confirm") that carries an editorial judgement the source does not make.

Unit 42's own CVE table is unambiguous on the omitted half: its row for CVE-2026-39987 gives the product as Marimo Notebook, the score as 9.8, the exploitation method as manual, and the status as active exploitation with command execution confirmed. The post's confirmed-impact list runs to four entries rather than one: data exfiltration from three organisations via the Citrix NetScaler flaw, command execution on 11 Marimo notebook instances, Java deserialization reverse-shell attempts against nine Apache Tomcat servers (CVE-2026-34486), and reverse-shell callbacks targeting three IKE VPN endpoints (CVE-2026-33824). Unit 42 also notes it "reviewed evidence of batch exploitation against an unknown number of hosts that were listed in a file deleted by the actor prior to our analysis", so even the enumerated figures are a floor rather than a total.

What survives from the original entry is its central reading of the autonomy question: Unit 42 attributes the confirmed compromises to the operator's manual work, and its table records the manual method against each of the four CVEs above, so the autonomous scanning component still did not itself produce the confirmed intrusions. What does not survive is the impact framing. A reader who took "three confirmed compromises, all NetScaler" from the original entry built the wrong exposure list, and the missing item is the awkward one: Marimo is an open-source reactive Python notebook that data-science and research teams install themselves, so it is far more likely to be absent from a central asset inventory than a NetScaler appliance is.

Triage: the discriminator for a notebook server is lineage rather than the process itself. A Marimo host legitimately spawns Python child processes constantly (that is what a notebook does) so process creation under the notebook service is noise. What is not noise is a child process that is not the interpreter: a shell, a download utility, or a scheduling command spawned by the notebook service account, especially on a host where no interactive session was open at that timestamp. Outbound connections from a notebook server to destinations outside the package-registry and data-source set it normally reaches are the second signal, and the two together (a non-interpreter child plus an unfamiliar egress destination within the same minute) are worth an alert on a host that was internet-reachable during the campaign window.

Updaterun 2026-08-10T0411Z-intelaffected_productscvesevidencesourcestagstechniquesbody

The correction entry on the autonomous-agent intrusion campaign listed four CVEs the operation actually reached, and recorded this one only as "callbacks from three IKE VPN endpoints", an observed effect with no mechanism behind it. 0patch has now published the root cause, which closes that gap (0patch, 2026-08-05).

The analysis places CVE-2026-33824 as "a pre-authentication double free in ikeext.dll, the module behind the 'IKE and AuthIP IPsec Keying Modules' service, which runs as Local System inside a svchost.exe", with the flaw "in function IkeReinjectReassembledPacket, on the IKEv2 fragment reassembly path". An unauthenticated party who can reach UDP 500 or 4500 on a host acting as an IKEv2 responder can free the same heap block twice. 0patch's interest is not offensive (it "recreated a POC from the official patch" by diffing Microsoft's fix, in order to build micropatches for Windows versions no longer receiving official updates) but the consequence is that a working reproduction exists and its derivation is described.

Microsoft's own record corroborates the surrounding facts without endorsing the function-level detail: CWE-415 double free, CVSS 9.8 with a network vector requiring no privileges and no user interaction, released 2026-04-14, and Microsoft's own summary that "An unauthenticated attacker could send specially crafted packets to a Windows machine with Internet Key Exchange (IKE) version 2 enabled, which could enable remote code execution" (Microsoft Security Response Center, 2026-04-14). The affected range spans Windows Server 2016 through Windows Server 2025 and Windows 10 version 1607 through Windows 11 version 26H1 (effectively every supported release at the time) and the vendor records both exploitation and public disclosure as no.

Two qualifications keep this proportionate. The service must be acting as an IKEv2 responder: Microsoft's own wording conditions the attack on IKE version 2 being enabled, so this is not every Windows host on the network, and its stated interim guidance is to block inbound UDP 500 and 4500 where IKE is unused and restrict it to known peers where it is required. And the campaign linkage is the tracked entry's, not 0patch's or Microsoft's; neither source makes any attribution claim, and neither states that the callbacks observed in that campaign resulted from this mechanism.

Detection, telemetry class first. The exploitable surface is a UDP service, so network telemetry is where this lives: inbound sessions to UDP 500 or 4500 from sources outside the configured VPN peer set are the population to look at, and fragmented IKE negotiation traffic from an unrecognised peer is the specific shape, since the flaw sits on the fragment-reassembly path. On the host, the keying service crashing or restarting under svchost is the crash signature, and because the service runs as Local System, any child process descending from that svchost instance is anomalous. Triage: a host that legitimately terminates IPsec tunnels sees fragmented IKE traffic from its real peers constantly, so fragmentation alone is normal; the discriminator is the peer address, and secondarily fragment sequences that never complete a negotiation.

Updaterun 2026-08-19T0410Z-intelactionscvesevidencesectorssourcesbody

The double free in the Windows IKE and AuthIP IPsec Keying Modules service is now catalogued as exploited. CISA added CVE-2026-33824 to its Known Exploited Vulnerabilities catalog on 2026-08-18, recording it as a double free that "could enable remote code execution" (CISA KEV catalog, 2026-08-18), ENISA's EU Vulnerability Database carries the same 2026-08-18 date and an EPSS probability of 0.5585 for its corresponding record (EUVD renders this as the percentage 55.85), though as a mirror of CISA's determination rather than a second assessment of it (ENISA EUVD, 2026-08-18). The prior entry recorded this flaw as patched with exploitation reported as no; that is the part that changed, and it is the only part.

The mechanism and the remediation are unchanged from the earlier coverage: the flaw sits on the IKEv2 fragment-reassembly path, needs no authentication and no user interaction, and yields code execution in the Local System context that hosts the IKEEXT service. What the exploitation confirmation changes is which hosts are in scope, because the vulnerable surface is not only the VPN concentrator, Microsoft's affected list spans Windows Server 2016 through 2025 and Windows 10 v1607 through Windows 11 v26H1, so any domain member that answers IKE, including a Routing and Remote Access role nobody remembers enabling, is a responder (ENISA EUVD, 2026-08-18).

The sourcing split is itself the operationally useful part. Microsoft's record has not been revised since it was published on 14 April 2026, and it still records exploitation as no with an exploitability assessment of "Exploitation Less Likely" (Microsoft Security Response Center, 2026-04-14). Any triage pipeline that ranks Windows CVEs on the vendor's own exploitability field (a common and otherwise reasonable design) has this flaw sitting four months deep in a patch backlog while two cataloguing authorities now class it as exploited. Neither authority publishes the telemetry behind its determination, and neither names an actor, so nothing here supports an attribution.

Detection and hunting concentrate on the service rather than the packet, because the trigger is a malformed fragment sequence that no ordinary log records as anomalous. In process and service telemetry, the signals are unexpected termination, restart or crash-dump generation for the host process running the IKE and AuthIP IPsec Keying Modules service, and any child process created under it, that service should never spawn a command interpreter or a script host. In network telemetry, inbound UDP 500 and 4500 flows from source addresses outside the known VPN peer set are the exposure indicator, and fragmented IKE traffic volumes that do not match the peer population are worth a look. Triage: a legitimate IKEv2 negotiation produces the same port pair and the same fragmentation, so traffic shape alone does not discriminate; what separates suspicious from normal is the source address falling outside the configured peer set, and the correlation of that flow with a service fault or a new child process on the responder. Microsoft's own interim guidance is a firewall control rather than a configuration change: block inbound UDP 500 and 4500 where IKE is unused, and restrict them to known peers where it is required (Microsoft Security Response Center, 2026-04-14).

Correctionrun 2026-09-06T1308Z-auditcvesbody

The EPSS figure quoted twice for CVE-2026-33824 was ENISA's EU Vulnerability Database rendering, which expresses EPSS as a percentage rather than as the probability itself. EUVD's API returns the value multiplied by one hundred, so 55.85 is an exploitation probability of 0.5585 (FIRST.org EPSS API, value as of 2026-08-18). The point the passage makes, that EUVD mirrors CISA's determination rather than assessing it independently, is unaffected.

threat31 Jul 04:09Zmulti-sourceOpen finding ↗

Earlier coverage (1)