CVE-2026-88771
CVE-2026-88772
September 28, 2026
·
0
Minutes Read

Citrix NetScaler ADC and NetScaler Gateway Remote Code Execution Zero-Days

Security Advisory
Advisory
September 28, 2026
·
0
Minutes Read

Citrix NetScaler ADC and NetScaler Gateway Remote Code Execution Zero-Days

Security Advisory
Advisory
September 28, 2026
·
0
Minutes Read
Kudelski Security Team
Find out more
table of contents
Share on
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Summary

Citrix disclosed two critical, unauthenticated remote code execution (RCE) vulnerabilities in NetScaler ADC and NetScaler Gateway (CVE-2026-88771 and CVE-2026-88772) alongside six lower-severity flaws (CVE-2026-88773 through CVE-2026-88778) in security bulletin CTX697096. Citrix confirmed that exploits of CVE-2026-88771 and CVE-2026-88772 have been observed on unmitigated deployments, and CISA confirmed active global exploitation corroborated by partner threat intelligence and victim reporting.

Affected Systems and/or Applications

  • Citrix NetScaler ADC and Citrix NetScaler Gateway, version 14.1 before 14.1-73.37
  • Citrix NetScaler ADC and Citrix NetScaler Gateway, version 13.1 before 13.1-64.23
  • Citrix NetScaler ADC 14.1-FIPS before 14.1-73.37 FIPS
  • Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP before 13.1.37.279
  • Secure Private Access Hybrid deployments built on the above versions
  • CVE-2026-88771 affects all deployments, including default configurations
  • CVE-2026-88772 affects deployments with DTLS enabled, which is on by default for VPN virtual servers

Technical Details

Vulnerability Mechanism

CVE-2026-88771 is caused by improper input validation (CWE-20), enabling an unauthenticated remote attacker to execute arbitrary commands on the appliance over the network with low attack complexity.

CVE-2026-88772 is a memory overflow vulnerability that can result in remote code execution or denial of service; it is reachable when DTLS is enabled, which is the default setting on VPN virtual servers.

Six additional vulnerabilities were disclosed in the same bulletin - CVE-2026-88773 (HTTP request smuggling, CVSS 9.3), CVE-2026-88774 (policy bypass via HTTP URL expressions, CVSS 7.0), CVE-2026-88775 (memory overflow DoS on Gateway/AAA servers, CVSS 8.8), CVE-2026-88776 (memory overflow affecting Oracle load balancers, CVSS 8.8), CVE-2026-88777 (memory overflow with non-HTTP L7 protocols, CVSS 8.8), and CVE-2026-88778 (TCP Initial Sequence Number prediction, CVSS 8.8) - none of which are reported as actively exploited.

Other observed exploitation of CVE-2026-88771/CVE-2026-88772 follows a two-step pattern: the payload is first staged by writing it into an HTTP access log (via the User-Agent header), then triggered/executed through a separate vector.

Key Points

  • Both zero-days are unauthenticated, network-exploitable, and reachable without special configuration on CVE-2026-88771's part.
  • Citrix has issued no workaround; the only remediation is upgrading to a fixed build.
  • Citrix explicitly warns that patching closes the vulnerabilities but does not remove any persistence or artifacts an attacker may have already left on a compromised system.
  • Compromise/IOC scanning is available through NetScaler Console version 14.1-73.36 and later, though Citrix acknowledges this scanning may not provide complete coverage.

Mitigation

Limit Exposure

No vendor-published workaround exists for either CVE. Until patched, organizations should minimize exposure of management interfaces and internet-facing NetScaler ADC/Gateway virtual servers where feasible. If patches cannot be applied within hours, organizations implement interim compensating controls such as broad geo-IP restrictions on affected virtual servers.

Patch/Upgrade

Upgrade Citrix NetScaler ADC and NetScaler Gateway to 14.1-73.37 or later, or 13.1-64.23 or later (14.1-73.37 FIPS or later; 13.1.37.279 FIPS/NDcPP or later, as applicable). An unverified, community-contributed hardening suggestion (not validated by Citrix) is enabling enhanced TCP Initial Sequence Number generation (set ns tcpParam -enhancedISNgeneration ENABLED) as a general hardening measure relevant to the separate TCP ISN prediction issue tracked as CVE-2026-88778.

What the Cyber Fusion Center is Doing

The CFC is monitoring the situation and analyzing the case to identify potential threat-hunting campaigns. This advisory will be updated if required.

References

‍

Related Post