T

Threats

Citrix NetScaler ADC and Gateway Multiple Critical Vulnerabilities

Overview

  • CVEs: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, CVE-2026-88778

  • Severity: Critical overall. CVE-2026-88771 and CVE-2026-88772 score 9.5; CVE-2026-88773 scores 9.3. The other five vulnerabilities are High severity.

  • Publication date: 28 September 2026


Citrix reports exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments. CISA reports both are being actively exploited globally and has added them to its Known Exploited Vulnerabilities catalogue.

Affected Versions

Citrix says the following supported builds are affected. Fixed means that build or a later release in the same branch. The vendor does not list additional unaffected product configurations; issue-specific configuration preconditions are noted below.

  • ADC and Gateway 14.1: Affected before 14.1-73.37. Fixed: 14.1-73.37 and later. Citrix security bulletin

  • ADC and Gateway 13.1: Affected before 13.1-64.23. Fixed: 13.1-64.23 and later 13.1 releases. Citrix security bulletin

  • ADC FIPS 14.1: Affected before 14.1-73.37 FIPS. Fixed: 14.1-73.37 FIPS and later 14.1-FIPS releases. Citrix security bulletin

  • ADC FIPS and NDcPP 13.1: Affected before 13.1-37.279. Fixed: 13.1-37.279 and later 13.1-FIPS and 13.1-NDcPP releases. Citrix security bulletin

The bulletin applies to customer-managed ADC and Gateway appliances. Citrix says Secure Private Access Hybrid deployments using NetScaler instances are also affected. Citrix-managed cloud services and Citrix-managed Adaptive Authentication are updated by Cloud Software Group.


Vulnerability Breakdown

CVE-2026-88771 - Improper input validation

  • Severity: Critical

  • CVSS: 9.5 (CVSS v4.0)

  • Description: Improper input validation can allow an unauthenticated attacker to execute arbitrary commands remotely.

  • Impact: Remote code execution.

  • Conditions: All NetScaler ADC and Gateway deployments are affected, including default configurations. No additional feature is required.

  • Notes: Citrix and CISA report active exploitation.

CVE-2026-88772 - Memory overflow

  • Severity: Critical

  • CVSS: 9.5 (CVSS v4.0)

  • Description: A memory overflow can lead to remote code execution or denial of service.

  • Impact: Remote code execution or denial of service.

  • Conditions: DTLS must be enabled. Citrix notes DTLS is enabled by default on VPN virtual servers.

  • Notes: Citrix and CISA report active exploitation.

CVE-2026-88773 - HTTP request smuggling

  • Severity: Critical

  • CVSS: 9.3 (CVSS v4.0)

  • Description: Inconsistent interpretation of HTTP requests creates an HTTP request smuggling vulnerability.

  • Impact: HTTP request smuggling; Citrix does not specify a further impact in its summary.

  • Conditions: HTTP configuration must be enabled. Citrix identifies HTTP or SSL Load Balancing, Content Switching, VPN, or Authentication virtual servers as relevant configurations.

CVE-2026-88775 - Memory overflow

  • Severity: High

  • CVSS: 8.8 (CVSS v4.0)

  • Description: A memory overflow can cause unpredictable or erroneous behaviour or denial of service.

  • Impact: Service disruption or denial of service.

  • Conditions: The appliance must be configured as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy) or an AAA virtual server.

CVE-2026-88776 - Memory overflow

  • Severity: High

  • CVSS: 8.8 (CVSS v4.0)

  • Description: A memory overflow can cause unpredictable or erroneous behaviour or denial of service.

  • Impact: Service disruption or denial of service.

  • Conditions: The appliance must have a Load Balancing virtual server of type Oracle.

CVE-2026-88777 - Memory overflow

  • Severity: High

  • CVSS: 8.8 (CVSS v4.0)

  • Description: A memory overflow can cause unpredictable or erroneous behaviour or denial of service.

  • Impact: Service disruption or denial of service.

  • Conditions: The appliance must be configured as an LB/CS or CGNAT-LSN/NAT64 device with a non-HTTP Layer 7 protocol feature enabled.

CVE-2026-88778 - TCP initial sequence number prediction

  • Severity: High

  • CVSS: 8.8 (CVSS v4.0)

  • Description: The vulnerability allows prediction of TCP initial sequence numbers.

  • Impact: TCP initial sequence number prediction; the vendor summary does not specify a further impact.

  • Conditions: A TCP virtual server must be configured and Enhanced ISN Generation must be disabled.

CVE-2026-88774 - Feature policy bypass

  • Severity: High

  • CVSS: 7.0 (CVSS v4.0)

  • Description: Improper use of an HTTP URL-based expression can bypass a feature policy.

  • Impact: Feature policy bypass.

  • Conditions: An HTTP URL-based policy expression must be configured. Citrix identifies HTTP or SSL Load Balancing, Content Switching, VPN, or Authentication virtual servers as relevant configurations.


Mitigation

  • Upgrade affected appliances to the relevant fixed build above as soon as possible. Prioritise all exposed NetScaler deployments because CVE-2026-88771 affects default configurations and CVE-2026-88771 and CVE-2026-88772 are being actively exploited.

  • Review appliance configuration for the preconditions listed above. Configuration checks do not replace patching.

  • For CVE-2026-88778, Citrix documents enabling Enhanced ISN Generation as a TCP configuration change: set ns tcpparam -enhancedISNgeneration ENABLED. This is a specific mitigation for that issue, not a substitute for upgrading. NetScaler TCP configuration guidance

  • If compromise is suspected, check for indicators of compromise where possible and preserve forensic evidence before patching. CISA warns that applying updates may reduce forensic visibility. Follow Citrix's guidance for suspected compromise.


Summary for IT Teams

  • Products: Citrix NetScaler ADC and NetScaler Gateway

  • Threat level: Critical overall, highest CVSS v4.0 score 9.5

  • Action required: Identify affected builds, preserve evidence first if compromise is suspected, and upgrade to the corresponding fixed release urgently. Review configuration-specific exposure and apply the documented Enhanced ISN Generation change where relevant.


References


Need Help?

Contact the Secure ISS SOC on 1300 769 460 to discuss exposure assessment and remediation.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.