Multiple Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway

Summary

Multiple vulnerabilities have been disclosed in Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway).

The vulnerabilities include unauthenticated remote code execution, memory corruption, HTTP request smuggling, security-policy bypass, denial of service and TCP Initial Sequence Number (ISN) prediction issues.

Two vulnerabilities, CVE-2026-88771 and CVE-2026-88772, have a CVSS v4.0 base score of 9.5 and can result in remote code execution. According to Citrix and multiple observations from third-parties, exploitation of these vulnerabilities has been observed against unmitigated NetScaler deployments.

Of particular concern, CVE-2026-88771 affects all vulnerable NetScaler ADC and NetScaler Gateway deployments, including appliances using the default configuration. No additional feature needs to be enabled for the vulnerability to be exposed.

CIRCL strongly recommends administrators of affected NetScaler systems to upgrade without delay and to investigate potentially exposed systems for signs of compromise.

Affected Products

The following supported versions are affected:

  • NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
  • NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
  • NetScaler ADC 14.1 FIPS before 14.1-73.37 FIPS
  • NetScaler ADC 13.1 FIPS and NDcPP before 13.1-37.279

Secure Private Access Hybrid deployments using NetScaler instances are also affected and the associated NetScaler appliances must be upgraded.

The vulnerabilities concern customer-managed NetScaler ADC and NetScaler Gateway appliances. Citrix-managed cloud services and Citrix-managed Adaptive Authentication are updated by Cloud Software Group.

Vulnerabilities

CVE-2026-88771 — Unauthenticated Remote Code Execution

A remote code execution vulnerability caused by improper input validation can allow an unauthenticated remote attacker to execute arbitrary commands.

Precondition: None. All affected NetScaler ADC and NetScaler Gateway deployments are concerned, including default configurations.

  • CWE: CWE-20 — Improper Input Validation
  • CVSS v4.0: 9.5
  • Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
  • Exploitation: Observed in the wild

This vulnerability should be considered the highest priority because exposure does not depend on an optional NetScaler feature being enabled.

CVE-2026-88772 — Memory Overflow Leading to RCE or DoS

A memory overflow vulnerability can result in remote code execution or denial of service.

Precondition: DTLS must be enabled. DTLS is enabled by default on VPN virtual servers unless explicitly disabled.

  • CWE: CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer
  • CVSS v4.0: 9.5
  • Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
  • Exploitation: Observed in the wild

CVE-2026-88773 — HTTP Request Smuggling

The vulnerability allows inconsistent interpretation of HTTP requests, resulting in an HTTP request smuggling condition.

Precondition: HTTP functionality must be configured on the affected appliance. This includes Load Balancing, Content Switching, VPN or Authentication virtual servers using HTTP or SSL.

  • CWE: CWE-444 — Inconsistent Interpretation of HTTP Requests
  • CVSS v4.0: 9.3
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N

CVE-2026-88774 — HTTP URL Policy Bypass

Improper use or interpretation of HTTP URL-based expressions can allow configured security or feature policies to be bypassed.

Precondition: An affected HTTP URL-based policy expression must be configured.

  • CWE: CWE-16 — Configuration
  • CVSS v4.0: 7.0
  • Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:N

CVE-2026-88775 — Memory Overflow in Gateway or AAA Configurations

A memory overflow vulnerability can result in unpredictable behaviour or denial of service.

Precondition: NetScaler must be configured as one of the following:

  • Gateway:
    • SSL VPN
    • ICA Proxy
    • CVPN
    • RDP Proxy
  • AAA virtual server

  • CWE: CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer
  • CVSS v4.0: 8.8
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N

CVE-2026-88776 — Memory Overflow in Oracle Load Balancing

A memory overflow vulnerability can lead to unpredictable behaviour or denial of service.

Precondition: NetScaler must be configured with a Load Balancing virtual server of type Oracle.

  • CWE: CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer
  • CVSS v4.0: 8.8
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N

CVE-2026-88777 — Memory Overflow in Non-HTTP L7 Services

A memory overflow vulnerability can result in unpredictable behaviour or denial of service.

Precondition: NetScaler must be configured as an LB/CS or CGNAT-LSN/NAT64 device with a non-HTTP Layer 7 protocol feature enabled.

Potentially affected configurations include FTP, RTSP, DNS64 and NAT64 deployments.

  • CWE: CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer
  • CVSS v4.0: 8.8
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N

CVE-2026-88778 — TCP Initial Sequence Number Prediction

The TCP Initial Sequence Number generation mechanism can result in predictable values, potentially weakening assumptions about the integrity of TCP connections.

Precondition: TCP functionality is enabled and Enhanced ISN Generation is disabled.

  • CWE: CWE-342 — Predictable Exact Value from Previous Values
  • CVSS v4.0: 8.8
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:L/SI:L/SA:L

CIRCL recommends that administrators upgrade affected NetScaler appliances as soon as possible.

The following versions contain fixes:

Product Fixed version
NetScaler ADC / Gateway 14.1 14.1-73.37 or later
NetScaler ADC / Gateway 13.1 13.1-64.23 or later
NetScaler ADC 14.1 FIPS 14.1-73.37 FIPS or later
NetScaler ADC 13.1 FIPS / NDcPP 13.1-37.279 or later

Because exploitation of CVE-2026-88771 and CVE-2026-88772 has already been observed, upgrading should not be considered sufficient evidence that an appliance was not previously compromised.

For Internet-facing appliances that were running an affected version, administrators should also:

  1. preserve relevant logs and forensic evidence before making significant changes where operationally possible;
  2. review NetScaler and external network/security logs for suspicious activity;
  3. investigate unexpected configuration, filesystem or process changes;
  4. review administrative and authentication activity;
  5. review activity from the appliance towards internal infrastructure;
  6. use the indicators and detection mechanisms provided by Citrix;
  7. follow the organisation’s incident response process if compromise is suspected.

External forwarding of NetScaler logs to a SIEM or other independent logging infrastructure is strongly recommended, as it can provide evidence that remains available if the appliance itself is compromised.

Configuration Checks

Administrators can use their NetScaler configuration to identify whether additional vulnerability-specific preconditions are met.

CVE-2026-88771

No configuration check is required. All affected versions meet the vulnerability precondition.

CVE-2026-88772

Review VPN and virtual-server configurations for DTLS.

For example:

text add vpn vserver vpn1 SSL 10.0.0.0 443 -Listenpolicy NONE

DTLS is enabled by default in this configuration.

An explicit:

text -dtls OFF

indicates that DTLS has been disabled for the VPN virtual server.

Also review explicitly configured DTLS virtual servers.

CVE-2026-88773

Review HTTP/SSL Load Balancing, Content Switching, VPN and Authentication virtual servers:

text add lb vserver <vserver-name> <HTTP or SSL> add cs vserver <vserver-name> <HTTP or SSL> add vpn vserver <vserver-name> <HTTP or SSL> add authentication vserver <vserver-name> <HTTP or SSL>

CVE-2026-88775

Relevant configuration entries include:

text add vpn vserver .* add authentication vserver .*

CVE-2026-88776

Search for Oracle Load Balancing virtual servers:

text add lb vserver.*ORACLE.*

CVE-2026-88777

Review configurations using non-HTTP Layer 7 protocols, including:

text add (lb|cs) vserver .* FTP add service .* FTP add lb monitor .* FTP add lb monitor .* FTP-EXTENDED set lsn group .* -rtspalg ENABLED add lb vserver .* DNS .* -dns64 ENABLED add dns policy64 add nat64

For LSN/CGNAT configurations, administrators should pay particular attention to FTP ALG configuration.

CVE-2026-88778

Check whether Enhanced ISN Generation is disabled:

shell show ns tcpparam | grep "Enhanced ISN Generation"

A result containing:

text Enhanced ISN Generation: DISABLED

indicates that the vulnerable configuration precondition may be met when applicable TCP-based virtual servers are configured.

Administrators affected by CVE-2026-88778 should also apply the TCP configuration changes recommended by Citrix.

Incident Response Considerations

Due to the reported exploitation of the two remote-code-execution vulnerabilities, CIRCL recommends treating vulnerable Internet-exposed NetScaler appliances with additional caution.

Where an appliance was exposed to untrusted networks while vulnerable, organisations should consider performing a compromise assessment rather than relying exclusively on successful installation of the security update.

In particular, successful patching prevents subsequent exploitation of the corrected vulnerabilities but does not remediate persistence or other changes potentially introduced before the update.

References

Classification of this document

TLP:CLEAR information may be distributed without restriction, subject to copyright controls.

Revision

  • Version 1.0 - TLP:CLEAR - First version - 27th September 2026