ALMC
ALMC Security Logo - Mantenimiento Web, Programación Web Barcelona, Servidores Barcelona, Ciberseguridad Barcelona
  • Online store
  • English
    Español English Français Català

Quick search

Results without leaving the page.

Type to search ALMC products, services, articles and tools.

View all results
Habla a nuestro AgenteIA · respuestas al instante · 24/7
  • HomeALMC
  • ALMCAbout Us
  • ALMC SECURITY S.L.U.Contact
  • Online store
  • Posts
    • All posts
    • Categories
    • Tags
    • Statuses
  • Solutions
    • Desarrollo Web en Lleida — Diseño a Medida que Vende
    • Tienda Online a Medida — E-commerce que Vende de Verdad
    • Chatbot IA para Empresas — Automatiza tu Atención al Cliente
    • Automatización de Procesos para Empresas — Menos Tareas, Más Resultados
    • Desarrollo de Apps Móviles — iOS y Android a Medida
  • Services
    • Cybersecurity
      • Security Audits and Pentesting
      • Monitoring & Incident Response (SIEM)
      • System & Server Hardening
      • Compliance Consulting (GDPR, ENS, ISO 27001)
      • Cloud Security (AWS, Azure, Google Cloud)
    • Programming
      • Full Stack Web Development Laravel, Vue.js
      • Process Automation (Scripts and Bots)
      • Process Automation Scripts and Bots
      • API Integrations & Microservices
      • Code Maintenance and Optimization
    • Servers
      • Server Management & Monitoring
      • Cloud Migration (AWS, Azure, Google Cloud)
      • Performance Optimization
      • Virtualization & Containers (Docker, Kubernetes)
      • Backup & Disaster Recovery Plans
    • Malware Removal
    • Website Maintenance
      • WordPress Maintenance
      • PrestaShop Maintenance
      • Magento Maintenance
      • Joomla Maintenance
      • Drupal Maintenance
      • Shopify Maintenance
      • Wix Maintenance
      • Concrete5 Maintenance
      • HTML Maintenance
      • PHP Maintenance
      • JavaScript Maintenance
      • Python Maintenance
    • Website Repair
      • Hacked site cleanup
      • Fix WordPress
      • Fix PrestaShop
      • Fix Magento
      • Fix Joomla
      • Fix Drupal
      • Fix Shopify
      • Fix OpenCart
      • Fix Moodle
  • Industries
    • 3D Printing & Additive
    • Accounting
    • Advertising & Marketing
    • Aerospace & Defense
    • Agriculture
    • Architecture & Engineering
    • Arts & Culture
    • Automotive
    • Banking & Finance
    • Biomedical Research
    • Biotechnology
    • Breweries
    • Call Centers & BPO
    • Chemicals
    • Cleaning Services
    • Clinics
    • Cloud Providers
    • Construction
    • Consulting
    • Cosmetics & Beauty
    • Courier & Last Mile
    • Cybersecurity
    • Data Centers
    • Defense & Security
    • E-Commerce
    • EdTech
    • Education (K-12)
    • Electrical Equipment
    • Electronics
    • Environmental NGOs
    • Environmental Services
    • Events & Conferences
    • Facilities Management
    • Fashion & Luxury
    • FinTech
    • Fishing & Aquaculture
    • Food & Beverage Manufacturing
    • Forestry
    • Freight Transport
    • Furniture
    • Gaming
    • Government & Public Administration
    • GovTech
    • Gyms & Fitness Centers
    • Healthcare Providers
    • HealthTech
    • Higher Education
    • Home Appliances
    • Home Services
    • Hospitality
    • Hospitals
    • Human Resources
    • Insurance
    • InsurTech
    • Internet & Web Services
    • Investment & Asset Management
    • IT Services
    • Jewelry
    • Landscaping & Gardening
    • Legal Services
    • Logistics & Supply Chain
    • Machinery
    • Maritime
    • Media & Entertainment
    • Medical Devices
    • Metals
    • Mining
    • Music Industry
    • Nonprofit & NGOs
    • Oil & Gas
    • Paper & Print Media
    • Paper & Pulp
    • Pharmaceuticals
    • Photography & Video
    • Plastics
    • Postal & Courier
    • Printing
    • Private Education & Academies
    • Property Development
    • Property Management
    • PropTech
    • Public Safety & Emergency
    • Publishing
    • Rail & Public Transport
    • Real Estate
    • Real Estate Agencies
    • Religious Organizations
    • Renewable Energy
    • Research & Development
    • Research Labs
    • Restaurants & Food Service
    • Retail
    • Security Services
    • Semiconductors
    • Software Development
    • Sports & Fitness
    • Sports Clubs
    • Staffing & Recruitment
    • Telecommunications
    • Textile & Apparel
    • Tobacco
    • Toys
    • Travel & Tourism
    • Travel Agencies
    • Utilities
    • Veterinary & Animal Care
    • Warehousing
    • Waste Management
    • Water Treatment
    • Wholesale
    • Wineries & Vineyards
  • Tools
    • Network
      • What's my IP
      • WHOIS IP
      • Domain WHOIS
      • Geolocate IP
      • DNS Lookup
      • DNS Propagation
      • ASN Lookup
      • Reverse Lookup
      • Domain monitoring
    • Image Compressor
    • MCP Servers
  • Products
    • Whatsboost
      • Whatsboost PrestaShop
      • Whatsboost WordPress
      • Whatsboost Shopify
    • Ulix
      • Extension QR para navegador
    • Chatbot
      • Chatbot WhatsApp
      • Chatbot Instagram
      • Chatbot Facebook
      • Chatbot TikTok
    • VeriFactu
    • Web TV
      • Mis pantallas
      • Vincular nueva TV
      • Dispositivos vinculados
      • Releases APK
      • Pantallas por cliente
    • Control de Fichajes

5 News at ALMC
  • Inauguration of the... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    Inauguration of the...It was a very busy and special day. 30 Jun 2025
  • Website Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    WebsiteI recover the domain I had in the past and set up... 01 Jun 2025
  • Signing of the Lease... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    Signing of the Lease...After spending some time looking for premises, my... 01 Jun 2025
  • ALMC returns and com... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    ALMC returns and com...We reactivate the brand with ALMC SECURITY SL (CIF... 23 Apr 2025
  • feb. 2025 Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    feb. 2025The decision to start entrepreneurship again was b... 01 Feb 2025

View all news

Citrix NetScaler zero-days: detect, patch and shield your servers

  1. Home
  2. Blog
  3. Categories
  4. Cybersecurity
  5. Citrix NetScaler zero-days: detect, patch and...
  • All articles
  • Categories
  • Tags
  • Statuses

Citrix NetScaler zero-days: detect, patch and shield your servers

Two critical zero-days in Citrix NetScaler, exploited in the wildIf your organisation exposes Citrix NetScaler ADC or NetScaler Gateway to the interne...

Two critical zero-days in Citrix NetScaler, exploited in the wild

If your organisation exposes Citrix NetScaler ADC or NetScaler Gateway to the internet, this is one of those weeks where patching is not a routine task but an urgent one. Two zero-day vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are being actively exploited to achieve unauthenticated remote code execution (RCE) on internet-facing appliances. Both carry a critical severity rating, with CVSS v4.0 scores around 9.5, and they are already part of real intrusion campaigns, not just proof-of-concept research.

The first flaw, CVE-2026-88771, stems from improper input validation and affects NetScaler ADC and Gateway deployments with default configurations. The second, CVE-2026-88772, is a memory overflow that can lead to RCE or denial of service, and it requires DTLS to be enabled. That detail matters: DTLS is often enabled by default on VPN vServers, so the practical attack surface may be wider than many administrators assume.

What attackers are doing after the initial breach

The post-exploitation phase is where things get uncomfortable. Investigators have observed password-protected PHP web shells being dropped on compromised appliances, along with deliberate attempts to hide them. In some cases, attackers modify the web server configuration so that files with supposedly harmless extensions, such as CSS or even images, are processed as PHP. This makes manual hunting much harder and allows malicious payloads to blend in with legitimate resources.

Persistence techniques are also notable. There have been attempts to elevate privileges by setting the setuid bit on /bin/sh, so commands launched from the web shell run with root permissions. If your team detects unusual permissions on that binary, treat it as a strong indicator of compromise rather than a system quirk.

Other artefacts linked to these intrusions include the file /var/netscaler/logon/LogonPoint/custom/.ctxs.receiver, suspicious Alias or AliasMatch entries in httpd.conf, and unusual handlers forcing PHP execution where it should not happen. Later stages involve known tooling such as WHIPSHOT, a disguised PHP web shell, and SLAPSHOT, a Python TCP tunnelling tool designed to open paths to internal hosts and facilitate lateral movement. Signs of this include Python processes launched with nohup and files such as /tmp/.uxdport or /tmp/.uxdlock.

Patch now, but check for compromise first

Citrix has released updates to break the attack chain. Affected products include Citrix NetScaler ADC 13.1 before 13.1-64.23, Citrix NetScaler ADC 14.1 before 14.1-73.37, and their NetScaler Gateway equivalents, plus FIPS and NDcPP builds. The practical recommendation is to apply 14.1-73.37 or later, or 13.1-64.23 or later, using the branch that fits your environment.

However, patching blindly can be costly from a forensic perspective. On exposed appliances, the priority should combine two steps: assess whether the system is already compromised before updating, so you do not lose useful traces, and then deploy the patch. If there is reasonable suspicion, preserve evidence and logs before touching the system, and bring in forensic support when the scope is unclear.

Adding pressure, CISA has added both flaws to its Known Exploited Vulnerabilities (KEV) catalogue and set 30 September 2026 as the deadline for US federal agencies to mitigate or patch. That decision often sets the pace for the wider industry, because many security teams outside the US use the KEV as a real-world exploitation thermometer.

The end-of-life problem and partial mitigations

There is also a structural issue. NetScaler versions 12.1 and 13.0 are already end-of-life and no longer receive security fixes, so waiting for a patch is not an option. The way out is to migrate to supported branches.

For those who cannot patch immediately, a partial mitigation exists: disable DTLS where feasible and block incoming UDP to port 443 if DTLS is not used. This measure does not cover CVE-2026-88771, so it is not a substitute for updating. In parallel, review concrete indicators: look for web shells, audit httpd.conf, check permissions on /bin/sh, and monitor for tunnelling signals from the appliance.

In 2026, remote access appliances remain a direct motorway into the internal network, and this campaign is a fast reminder of that reality. For system administrators, hosting companies and SMEs with their own servers in Barcelona, Lleida, Tarragona or Girona, the lesson is clear: exposure management and rapid response are not optional.

Centralised protection with Abuse Shield

Beyond emergency patching, reducing the attack surface is essential. At ALMC we offer Abuse Shield, a service that centralises server protection: automatic blocking of malicious IPs, managed fail2ban across multiple machines, and a shared reputation feed between all your servers. This means that when one of your servers detects an attack, the others learn from it and block the same source automatically. For hosting providers and SMEs managing several servers, this coordinated defence saves time and strengthens security without adding complexity.

Combined with timely patching and forensic readiness, Abuse Shield helps you keep your infrastructure resilient against campaigns like the one targeting Citrix NetScaler. If you need advice on how to implement it in your environment, our team in Lleida can help you assess your current exposure and design a tailored protection strategy.

Related

  • How to Harden Your Servers with Fail2ban and IP Reputation Feeds
  • Fail2ban: Your First Line of Defense Against Unauthorized Server Access
  • Critical libssh2 flaw: urgent patch for SSH servers
  • Desarrollo web

Put these ideas into practice

Talk to ALMC about a solution for your business. Explore your options or contact our team.

Soluciones ALMC

Cloud Migration (AWS, Azure, Google Cloud)
Server Management & Monitoring
Code Maintenance and Optimization
Performance Optimization
API Integrations & Microservices
Relacionados
  • Malicious PDFs: The Silent Threat to Your Servers
    Cybersecurity · 1 hour ago
  • Exposed Vite Dev Servers: How Attackers Steal Cloud Secrets
    Cybersecurity · 1 day ago
  • Citrix NetScaler Zero-Days: Why Perimeter Patching Is Not Enough
    Cybersecurity · 2 days ago
  • InjectSetConsole: a stealthier path to remote code injection on Windows
    Cybersecurity · 3 days ago
  • Vibe Coding Security: 5 Questions to Ask Before Trusting an AI-Built App
    Cybersecurity · 4 days ago
  • CRA Compliance for Mobile Apps: A 2027 Guide for EU Businesses
    Cybersecurity · 4 days ago
Servidores MCP Destacados
  • MCP Screenshot
    Productivity
  • Open Brewery DB
    Search
  • laundry-timer-mcp
    Productivity
  • GDB
    Development
  • Baby-SkyNet
    Development
  • Nessus MCP Server
    Development
  • OP.GG
    Other
  • Hackle
    Development
  • Malaysia Prayer Time MCP Server
    Other
Ver todos los servidores MCP
Cybersecurity · Blog Brain · 2026-10-01
Cerrar panel
Your ecosystem

SaaS applications

Open each workspace directly with your ALMC account.

My account Create account
VeriFactuVerified invoicingAbuse ShieldWeb securityWhatsBoostSales and CRMCommerceStore and POSEmail AISmart emailWebTVDigital signageTime trackingWorking-time controlPrintFlowPrint workflows
Agente Smith · ALMCAgente IA propio on-premise

Hola 👋 Soy Smith, el agente IA de ALMC. Pregúntame sobre ciberseguridad, IA, desarrollo a medida o nuestros productos SaaS.

¿Prefieres hablar con persona? Contacto humano

ALMC access centre

One account · All your services

Start wherever you want.

Create an account to centralise your services, or ask for guidance if you do not know what you need yet.

Create account Talk to ALMC

Explore by product

VeriFactuInvoicingAbuse ShieldSecurityWhatsBoostSalesCommerceStore and POSEmail AIAutomationWebTVDigital signage

Sign in to your account.

The same sign-in brings together your services, team and billing.

Enter my panelAccess your services, team and billing.
Sign in

Not a client yet? Create an account

ALMC Security Logo

Experts in cybersecurity, custom Laravel development, and server management. We deliver robust, secure, and personalized technological solutions.

Latest News

Inauguration of the first office in Lleida of ALMC SECURITY SL
Inauguration of the first office in Lleida of ALMC...
30 Jun 2025
Website
01 Jun 2025
Signing of the Lease Contract
Signing of the Lease Contract
01 Jun 2025

Main Services

  • desarrollo web lleida
  • tienda online a medida
  • chatbot ia empresa
  • automatización procesos empresa
  • desarrollo aplicaciones móviles

SaaS Suite

  • PrintFlow (print shops)
  • WebTV (digital signage)
  • VeriFactu (invoicing)
  • Time tracking

Contact

  • Rambla de Ferran, 37, 25007 Lleida

  • +34 614 443 757

  • info@almc.es

Follow Us

Useful links

  • About us
  • Contact
  • Reserva cita
  • Hacked website repair
  • Website maintenance
  • Website repair
  • Tools
  • What is my IP
  • Compress images
  • Site search
  • Blog

© Copyright 2026. ALMC SECURITY S.L.U.

  • Legal
      • Privacy Policy
      • Terms and Conditions of Service
      • Legal Notice and Corporate Information
      • Cookie Policy
  • Resources
    • Blog
    • Sitemap

ALMC

Legal

This site only uses first-party cookies and local browser storage, and only to make it work: keeping your session, protecting forms, remembering your language and not showing you this notice again. We use no analytics or advertising cookies, there are no third-party cookies and we do not build profiles. As strictly necessary technical cookies, they are exempt from consent under Article 22.2 of the Spanish LSSI-CE: this notice is informative and the button only stops it from appearing again. You can delete or block them from your browser, though some features may then stop working. Cookie Policy · Privacy Policy.

Chat now
Call Sales
+34 614 443 757

More ways to contact us

Shall we talk directly?

Book an appointment in my calendar — I will call you or we can meet via Google Meet

  • ✓Instant confirmation via WhatsApp
  • ✓Real-time availability
  • ✓Reminder 1 hour before
  • ✓Cancel or reschedule with a single click
Initial consultation · 30min
📅 Check availability and book