T
Threats
Citrix NetScaler ADC and Gateway Multiple Critical Vulnerabilities
Overview
CVEs: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, CVE-2026-88778
Severity: Critical overall. CVE-2026-88771 and CVE-2026-88772 score 9.5; CVE-2026-88773 scores 9.3. The other five vulnerabilities are High severity.
Publication date: 28 September 2026
Citrix reports exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments. CISA reports both are being actively exploited globally and has added them to its Known Exploited Vulnerabilities catalogue.
Affected Versions
Citrix says the following supported builds are affected. Fixed means that build or a later release in the same branch. The vendor does not list additional unaffected product configurations; issue-specific configuration preconditions are noted below.
ADC and Gateway 14.1: Affected before 14.1-73.37. Fixed: 14.1-73.37 and later. Citrix security bulletin
ADC and Gateway 13.1: Affected before 13.1-64.23. Fixed: 13.1-64.23 and later 13.1 releases. Citrix security bulletin
ADC FIPS 14.1: Affected before 14.1-73.37 FIPS. Fixed: 14.1-73.37 FIPS and later 14.1-FIPS releases. Citrix security bulletin
ADC FIPS and NDcPP 13.1: Affected before 13.1-37.279. Fixed: 13.1-37.279 and later 13.1-FIPS and 13.1-NDcPP releases. Citrix security bulletin
The bulletin applies to customer-managed ADC and Gateway appliances. Citrix says Secure Private Access Hybrid deployments using NetScaler instances are also affected. Citrix-managed cloud services and Citrix-managed Adaptive Authentication are updated by Cloud Software Group.
Vulnerability Breakdown
CVE-2026-88771 - Improper input validation
Severity: Critical
CVSS: 9.5 (CVSS v4.0)
Description: Improper input validation can allow an unauthenticated attacker to execute arbitrary commands remotely.
Impact: Remote code execution.
Conditions: All NetScaler ADC and Gateway deployments are affected, including default configurations. No additional feature is required.
Notes: Citrix and CISA report active exploitation.
CVE-2026-88772 - Memory overflow
Severity: Critical
CVSS: 9.5 (CVSS v4.0)
Description: A memory overflow can lead to remote code execution or denial of service.
Impact: Remote code execution or denial of service.
Conditions: DTLS must be enabled. Citrix notes DTLS is enabled by default on VPN virtual servers.
Notes: Citrix and CISA report active exploitation.
CVE-2026-88773 - HTTP request smuggling
Severity: Critical
CVSS: 9.3 (CVSS v4.0)
Description: Inconsistent interpretation of HTTP requests creates an HTTP request smuggling vulnerability.
Impact: HTTP request smuggling; Citrix does not specify a further impact in its summary.
Conditions: HTTP configuration must be enabled. Citrix identifies HTTP or SSL Load Balancing, Content Switching, VPN, or Authentication virtual servers as relevant configurations.
CVE-2026-88775 - Memory overflow
Severity: High
CVSS: 8.8 (CVSS v4.0)
Description: A memory overflow can cause unpredictable or erroneous behaviour or denial of service.
Impact: Service disruption or denial of service.
Conditions: The appliance must be configured as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy) or an AAA virtual server.
CVE-2026-88776 - Memory overflow
Severity: High
CVSS: 8.8 (CVSS v4.0)
Description: A memory overflow can cause unpredictable or erroneous behaviour or denial of service.
Impact: Service disruption or denial of service.
Conditions: The appliance must have a Load Balancing virtual server of type Oracle.
CVE-2026-88777 - Memory overflow
Severity: High
CVSS: 8.8 (CVSS v4.0)
Description: A memory overflow can cause unpredictable or erroneous behaviour or denial of service.
Impact: Service disruption or denial of service.
Conditions: The appliance must be configured as an LB/CS or CGNAT-LSN/NAT64 device with a non-HTTP Layer 7 protocol feature enabled.
CVE-2026-88778 - TCP initial sequence number prediction
Severity: High
CVSS: 8.8 (CVSS v4.0)
Description: The vulnerability allows prediction of TCP initial sequence numbers.
Impact: TCP initial sequence number prediction; the vendor summary does not specify a further impact.
Conditions: A TCP virtual server must be configured and Enhanced ISN Generation must be disabled.
CVE-2026-88774 - Feature policy bypass
Severity: High
CVSS: 7.0 (CVSS v4.0)
Description: Improper use of an HTTP URL-based expression can bypass a feature policy.
Impact: Feature policy bypass.
Conditions: An HTTP URL-based policy expression must be configured. Citrix identifies HTTP or SSL Load Balancing, Content Switching, VPN, or Authentication virtual servers as relevant configurations.
Mitigation
Upgrade affected appliances to the relevant fixed build above as soon as possible. Prioritise all exposed NetScaler deployments because CVE-2026-88771 affects default configurations and CVE-2026-88771 and CVE-2026-88772 are being actively exploited.
Review appliance configuration for the preconditions listed above. Configuration checks do not replace patching.
For CVE-2026-88778, Citrix documents enabling Enhanced ISN Generation as a TCP configuration change:
set ns tcpparam -enhancedISNgeneration ENABLED. This is a specific mitigation for that issue, not a substitute for upgrading. NetScaler TCP configuration guidanceIf compromise is suspected, check for indicators of compromise where possible and preserve forensic evidence before patching. CISA warns that applying updates may reduce forensic visibility. Follow Citrix's guidance for suspected compromise.
Summary for IT Teams
Products: Citrix NetScaler ADC and NetScaler Gateway
Threat level: Critical overall, highest CVSS v4.0 score 9.5
Action required: Identify affected builds, preserve evidence first if compromise is suspected, and upgrade to the corresponding fixed release urgently. Review configuration-specific exposure and apply the documented Enhanced ISN Generation change where relevant.
References
Citrix NetScaler ADC and Gateway security bulletin, CTX697096
CISA alert: Critical zero-day vulnerabilities exploited in Citrix NetScaler ADC and Gateway
NetScaler TCP configuration guidance: Enhanced ISN Generation
Need Help?
Contact the Secure ISS SOC on 1300 769 460 to discuss exposure assessment and remediation.

