Citrix NetScaler ADC and NetScaler Gateway Remote Code Execution Zero-Days
Citrix NetScaler ADC and NetScaler Gateway Remote Code Execution Zero-Days
Summary
Citrix disclosed two critical, unauthenticated remote code execution (RCE) vulnerabilities in NetScaler ADC and NetScaler Gateway (CVE-2026-88771 and CVE-2026-88772) alongside six lower-severity flaws (CVE-2026-88773 through CVE-2026-88778) in security bulletin CTX697096. Citrix confirmed that exploits of CVE-2026-88771 and CVE-2026-88772 have been observed on unmitigated deployments, and CISA confirmed active global exploitation corroborated by partner threat intelligence and victim reporting.
Affected Systems and/or Applications
- Citrix NetScaler ADC and Citrix NetScaler Gateway, version 14.1 before 14.1-73.37
- Citrix NetScaler ADC and Citrix NetScaler Gateway, version 13.1 before 13.1-64.23
- Citrix NetScaler ADC 14.1-FIPS before 14.1-73.37 FIPS
- Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP before 13.1.37.279
- Secure Private Access Hybrid deployments built on the above versions
- CVE-2026-88771 affects all deployments, including default configurations
- CVE-2026-88772 affects deployments with DTLS enabled, which is on by default for VPN virtual servers
Technical Details
Vulnerability Mechanism
CVE-2026-88771 is caused by improper input validation (CWE-20), enabling an unauthenticated remote attacker to execute arbitrary commands on the appliance over the network with low attack complexity.
CVE-2026-88772 is a memory overflow vulnerability that can result in remote code execution or denial of service; it is reachable when DTLS is enabled, which is the default setting on VPN virtual servers.
Six additional vulnerabilities were disclosed in the same bulletin - CVE-2026-88773 (HTTP request smuggling, CVSS 9.3), CVE-2026-88774 (policy bypass via HTTP URL expressions, CVSS 7.0), CVE-2026-88775 (memory overflow DoS on Gateway/AAA servers, CVSS 8.8), CVE-2026-88776 (memory overflow affecting Oracle load balancers, CVSS 8.8), CVE-2026-88777 (memory overflow with non-HTTP L7 protocols, CVSS 8.8), and CVE-2026-88778 (TCP Initial Sequence Number prediction, CVSS 8.8) - none of which are reported as actively exploited.
Other observed exploitation of CVE-2026-88771/CVE-2026-88772 follows a two-step pattern: the payload is first staged by writing it into an HTTP access log (via the User-Agent header), then triggered/executed through a separate vector.
Key Points
- Both zero-days are unauthenticated, network-exploitable, and reachable without special configuration on CVE-2026-88771's part.
- Citrix has issued no workaround; the only remediation is upgrading to a fixed build.
- Citrix explicitly warns that patching closes the vulnerabilities but does not remove any persistence or artifacts an attacker may have already left on a compromised system.
- Compromise/IOC scanning is available through NetScaler Console version 14.1-73.36 and later, though Citrix acknowledges this scanning may not provide complete coverage.
Mitigation
Limit Exposure
No vendor-published workaround exists for either CVE. Until patched, organizations should minimize exposure of management interfaces and internet-facing NetScaler ADC/Gateway virtual servers where feasible. If patches cannot be applied within hours, organizations implement interim compensating controls such as broad geo-IP restrictions on affected virtual servers.
Patch/Upgrade
Upgrade Citrix NetScaler ADC and NetScaler Gateway to 14.1-73.37 or later, or 13.1-64.23 or later (14.1-73.37 FIPS or later; 13.1.37.279 FIPS/NDcPP or later, as applicable). An unverified, community-contributed hardening suggestion (not validated by Citrix) is enabling enhanced TCP Initial Sequence Number generation (set ns tcpParam -enhancedISNgeneration ENABLED) as a general hardening measure relevant to the separate TCP ISN prediction issue tracked as CVE-2026-88778.
What the Cyber Fusion Center is Doing
The CFC is monitoring the situation and analyzing the case to identify potential threat-hunting campaigns. This advisory will be updated if required.
References
- Citrix Security Bulletin CTX697096 - https://support.citrix.com/external/article/CTX697096/citrix-netscaler-adc-and-citrix-netscale.html
- CISA Alert: Critical Zero-Day Vulnerabilities Exploited - Citrix NetScaler ADC/Gateway (2026-09-27) - https://www.cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway
- watchTowr Intelligence - https://watchtowr.com/intelligence/citrix-netscaler-adc-citrix-netscaler-gateway-remote-code-execution-cve-2026-88771/
- OpenCVE - CVE-2026-88771 - https://app.opencve.io/cve/CVE-2026-88771

.avif)





.webp)