DEV Community

jeffrey
jeffrey

Posted on

Citrix NetScaler ADC and Gateway: eight advisories, two under active exploitation (CVE-2026-88776)

Citrix NetScaler ADC and Gateway: eight advisories, two under active exploitation (CVE-2026-88776)

The Dutch national cyber security centre published NCSC-2026-0394 on 27 September 2026 with a High priority rating. The subject is a single hardening release from Citrix that resolves eight tracked vulnerabilities across NetScaler ADC and NetScaler Gateway. The easiest way to read the release is as one operational event rather than eight unrelated bug reports, because a single upgrade covers the whole set and because two of the entries are already being used against real systems.

The vulnerability set at a glance

CVE CVSS v4 Weakness and outcome Precondition Exploitation
CVE-2026-88771 9.5 Insufficient input validation; unauthenticated remote command execution All ADC and Gateway deployments Confirmed exploited
CVE-2026-88772 9.5 Memory overflow allowing remote code execution or denial of service DTLS enabled (default on a VPN virtual server) Confirmed exploited
CVE-2026-88773 9.3 HTTP request smuggling HTTP functionality enabled Not reported
CVE-2026-88774 7.0 Feature policy bypass via HTTP URL-based policy expressions URL-based policy expressions configured Not reported
CVE-2026-88775 8.8 Memory overflow causing unpredictable behaviour or denial of service Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server Not reported
CVE-2026-88776 8.8 Memory overflow causing unpredictable behaviour or denial of service Oracle-type load-balancing virtual server Not reported
CVE-2026-88777 8.8 Memory overflow causing unpredictable behaviour or denial of service LB, CS or CGNAT-LSN/NAT64 with a non-HTTP Layer 7 protocol Not reported
CVE-2026-88778 8.8 Predictable TCP initial sequence numbers TCP functionality enabled Not reported

Why the set matters more than any single entry

CVE-2026-88776 is the identifier this article leads with, and it is a memory overflow that produces unpredictable behaviour or a denial of service when an Oracle-type load-balancing virtual server is configured. It is serious on its own terms, but the advisory is honest about where the immediate danger sits: CVE-2026-88771 and CVE-2026-88772 carry CVSS v4 scores of 9.5 and, according to Citrix, have both been observed in exploitation.
The distinction between the two exploited flaws is worth holding on to. CVE-2026-88771 is an input validation failure that lets an unauthenticated remote attacker run arbitrary commands, and Citrix states that every ADC and Gateway deployment is affected with no extra configuration required. CVE-2026-88772 is a memory overflow reachable when DTLS is switched on, and DTLS is enabled by default on a VPN virtual server. One is universal, the other is default-on for the most common VPN use case.

Where a defender should start

Inventory comes first. Any customer-managed NetScaler ADC or Gateway instance on the versions listed below needs to be treated as potentially reachable, and the patched builds should be applied on an emergency footing rather than a routine maintenance window. Before the update is installed, the NCSC advises capturing logging and a memory dump so that evidence of earlier compromise is preserved, a hint that patching alone may not close an incident that has already begun.

Affected products and scope

Citrix advises that the following customer-managed builds are exposed:

  • NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
  • NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
  • NetScaler ADC FIPS before 14.1-73.37 FIPS
  • NetScaler ADC FIPS and NDcPP before 13.1-37.279

Secure Private Access hybrid deployments that rely on NetScaler instances inherit the same exposure. Only customer-managed appliances are in scope here; Citrix states that its own managed cloud services and Citrix Managed Adaptive Authentication receive the necessary updates from the vendor.

Remediation

Citrix has issued security updates and the NCSC recommends applying them without delay. The fixed builds are:

  • 14.1-73.37 and later (14.1 branch)
  • 13.1-64.23 and later (13.1 branch)
  • 14.1-73.37 FIPS and later (FIPS branch)
  • 13.1-37.279 and later (FIPS / NDcPP branch)

Because CVE-2026-88771 and CVE-2026-88772 have been observed in the wild, the NCSC adds guidance that goes beyond a normal patch cycle. Before installing the update, preserve relevant logging and take a memory dump, so that forensic evidence of any earlier compromise remains available. Installing the update stops new exploitation but does not rule out that a system was already breached, so organisations that were exposed before patching should also assess for prior compromise.

Exposure context

A ZoomEye search with the product fingerprint app="Citrix NetScaler" reports 239.3k matching instances, which places the population of internet-reachable NetScaler deployments well above the threshold at which this class of flaw warrants urgent attention. NetScaler appliances commonly sit directly on the internet as VPN concentrators and load balancers, so a reachable management or data plane usually means no additional network foothold is needed to attempt exploitation.

Sources

  • NCSC-2026-0394, Netherlands Cyber Security Center, 27 September 2026.
  • Citrix security bulletin CTX697096 for CVE-2026-88771 through CVE-2026-88778.

Top comments (0)