About:
Multiple vulnerabilities affect Citrix NetScaler ADC and NetScaler Gateway, including two critical zero-days actively exploited in the wild: CVE-2026-88771 and CVE-2026-88772, both rated CVSS 9.5.
CVE-2026-88771 allows unauthenticated command execution and affects NetScaler deployments without requiring additional features or configurations. CVE-2026-88772 can allow unauthenticated remote code execution or denial of service when DTLS is enabled.
Citrix Security Bulletin CTX697096 also addresses six additional vulnerabilities affecting NetScaler deployments. Citrix states that every NetScaler deployment is affected by at least one vulnerability covered by the bulletin.
Organizations should upgrade immediately to the applicable fixed builds, investigate potentially exposed appliances for compromise, and review configuration-specific remediation requirements.
RedLegg will occasionally communicate vulnerabilities released outside the usual release schedule to provide additional value to our customers. These emergency bulletins describe vulnerabilities or threats we classify as the highest severity level and warrant out-of-band emergency patching or mitigation action.
Identifier: CVE-2026-88771
PoC or Exploitation:
Confirmed actively exploited as a zero-day. Discovered during forensic investigations of compromised customer environments. CISA added to KEV catalog September 27, 2026. NCSC-NL confirmed exploitation at multiple Citrix customers worldwide.
CVSS Score: 9.5 (Critical, CVSS v4.0)
Update / Patch:
Citrix has released security bulletin CTX697096 addressing this vulnerability.
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 before 14.1-73.37
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 before 13.1-64.23
Citrix NetScaler ADC 14.1-FIPS before 14.1-73.37 FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP before 13.1-37.279
Fixed via: builds 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, and 13.1-37.279
Citrix Security Bulletin CTX697096:
https://support.citrix.com/external/article/CTX697096/citrix-netscaler-adc-and-citrix-netscale.html
Description:
CVE-2026-88771 is an improper input validation vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary commands on the appliance. Because NetScaler appliances operate at the network perimeter and handle VPN, authentication, and application delivery traffic, successful exploitation can provide an attacker with a foothold for credential theft, session hijacking, and lateral movement into the internal network.
Precondition: All NetScaler ADC and NetScaler Gateway deployments are affected, including those deployed with the default configuration. No additional features or settings need to be enabled for the NetScaler deployment to be vulnerable.
Mitigation Recommendation:
Upgrade to the fixed builds listed above immediately. Cloud Software Group strongly urges affected customers of NetScaler ADC and NetScaler Gateway to install the relevant updated versions as soon as possible.
Appliances patched for earlier 2026 NetScaler vulnerabilities (CVE-2026-19490, CVE-2026-8452) remain vulnerable to this flaw unless upgraded to the new fixed builds.
Run the IOC scan available through NetScaler Console's Security Advisory workflow (requires version 14.1-73.36 or later with telemetry enabled) or contact Citrix Support for indicators of compromise. Citrix cautions that the IOC checks do not cover every attacker technique and a clean result does not confirm the appliance was not compromised.
Organizations unable to patch immediately should restrict inbound access to NetScaler appliances to trusted IP ranges only.
End-of-life versions (12.1 and 13.0) will not receive patches. Migrate to a supported version.
Identifier: CVE-2026-88772
PoC or Exploitation:
Confirmed actively exploited as a zero-day. Discovered during forensic investigations of compromised customer environments. CISA added to KEV catalog September 27, 2026.
CVSS Score: 9.5 (Critical, CVSS v4.0)
Update / Patch:
Citrix has released security bulletin CTX697096 addressing this vulnerability.
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 before 14.1-73.37
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 before 13.1-64.23
Citrix NetScaler ADC 14.1-FIPS before 14.1-73.37 FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP before 13.1-37.279
Fixed via: builds 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, and 13.1-37.279
Citrix Security Bulletin CTX697096:
https://support.citrix.com/external/article/CTX697096/citrix-netscaler-adc-and-citrix-netscale.html
Description:
CVE-2026-88772 is a memory overflow vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway that can lead to remote code execution or denial of service. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary code on the appliance without credentials or user interaction.
Precondition: DTLS must be enabled on NetScaler ADC or NetScaler Gateway. NetScaler enables DTLS by default for VPN virtual servers, meaning most Gateway deployments are exposed unless DTLS has been explicitly disabled.
To determine if your deployment is affected, inspect the configuration for DTLS-enabled virtual servers:
VULNERABLE (DTLS enabled by default, not explicitly disabled):
add vpn vserver vpn1 SSL 10.0.0.0 443 -Listenpolicy NONE
NOT VULNERABLE (DTLS explicitly disabled):
add vpn vserver vpn1 SSL 10.0.0.0 443 -dtls OFF -Listenpolicy NONE
VULNERABLE (DTLS explicitly enabled):
add vpn vserver vs1 DTLS 10.11.1.1 443
VULNERABLE (DTLS load balancing virtual server):
add lb vserver vd_dtls DTLS 10.146.111.74 443 -persistenceType NONE -cltTimeout 120
Mitigation Recommendation:
Upgrade to the fixed builds listed above immediately.
As a temporary mitigation if patching is not immediately possible, disable DTLS on VPN virtual servers by setting -dtls OFF. This reduces exposure to CVE-2026-88772 specifically but does not address CVE-2026-88771 or the other six vulnerabilities in CTX697096. Patching remains the only complete remediation.
Run the IOC scan and review appliance logs for signs of compromise as described in the CTX697096 bulletin. Citrix cautions that these checks cannot cover every attacker technique and may miss compromises.
Additionally, NetScaler deployments impacted by CVE-2026-88778 (TCP ISN prediction flaw, also in CTX697096) should apply the TCP configuration change to enable Enhanced ISN Generation as described at:
This configuration change is required because upgrading alone does not fully resolve CVE-2026-88778.
Identifier: CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, CVE-2026-88778
PoC or Exploitation:
No confirmed active exploitation for these six CVEs at this time.
CVSS Score: Ranging from 7.0 to 9.3 (High to Critical, CVSS v4.0)
Update / Patch:
All six are addressed in the same Citrix security bulletin CTX697096 and the same fixed builds as CVE-2026-88771 and CVE-2026-88772 above.
Citrix Security Bulletin CTX697096:
https://support.citrix.com/external/article/CTX697096/citrix-netscaler-adc-and-citrix-netscale.html
Description
CTX697096 addresses six additional vulnerabilities alongside the two actively exploited zero-days.
These include HTTP request smuggling (CVE-2026-88773, CVSS 9.3), feature policy bypass (CVE-2026-88774, CVSS 7.0), memory overflow conditions (CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, each CVSS 8.8), and a TCP Initial Sequence Number prediction flaw (CVE-2026-88778, CVSS 8.8). Each requires specific feature configurations to be exploitable.
Citrix states that every NetScaler deployment is affected by at least one vulnerability in this bulletin.
Mitigation Recommendation:
Upgrade to the fixed builds (14.1-73.37 or 13.1-64.23) and review the CTX697096 bulletin for configuration-specific applicability and precondition checks for each CVE.
For CVE-2026-88778 specifically: upgrading alone does not fully resolve this flaw. Administrators must also enable Enhanced ISN Generation in the TCP configuration after upgrading.