Summary
Multiple vulnerabilities have been disclosed in Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway).
The vulnerabilities include unauthenticated remote code execution, memory corruption, HTTP request smuggling, security-policy bypass, denial of service and TCP Initial Sequence Number (ISN) prediction issues.
Two vulnerabilities, CVE-2026-88771 and CVE-2026-88772, have a CVSS v4.0 base score of 9.5 and can result in remote code execution. According to Citrix and multiple observations from third-parties, exploitation of these vulnerabilities has been observed against unmitigated NetScaler deployments.
Of particular concern, CVE-2026-88771 affects all vulnerable NetScaler ADC and NetScaler Gateway deployments, including appliances using the default configuration. No additional feature needs to be enabled for the vulnerability to be exposed.
CIRCL strongly recommends administrators of affected NetScaler systems to upgrade without delay and to investigate potentially exposed systems for signs of compromise.
Affected Products
The following supported versions are affected:
- NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
- NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
- NetScaler ADC 14.1 FIPS before 14.1-73.37 FIPS
- NetScaler ADC 13.1 FIPS and NDcPP before 13.1-37.279
Secure Private Access Hybrid deployments using NetScaler instances are also affected and the associated NetScaler appliances must be upgraded.
The vulnerabilities concern customer-managed NetScaler ADC and NetScaler Gateway appliances. Citrix-managed cloud services and Citrix-managed Adaptive Authentication are updated by Cloud Software Group.
Vulnerabilities
CVE-2026-88771 — Unauthenticated Remote Code Execution
A remote code execution vulnerability caused by improper input validation can allow an unauthenticated remote attacker to execute arbitrary commands.
Precondition: None. All affected NetScaler ADC and NetScaler Gateway deployments are concerned, including default configurations.
- CWE: CWE-20 — Improper Input Validation
- CVSS v4.0: 9.5
-
Vector:
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H - Exploitation: Observed in the wild
This vulnerability should be considered the highest priority because exposure does not depend on an optional NetScaler feature being enabled.
CVE-2026-88772 — Memory Overflow Leading to RCE or DoS
A memory overflow vulnerability can result in remote code execution or denial of service.
Precondition: DTLS must be enabled. DTLS is enabled by default on VPN virtual servers unless explicitly disabled.
- CWE: CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVSS v4.0: 9.5
-
Vector:
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H - Exploitation: Observed in the wild
CVE-2026-88773 — HTTP Request Smuggling
The vulnerability allows inconsistent interpretation of HTTP requests, resulting in an HTTP request smuggling condition.
Precondition: HTTP functionality must be configured on the affected appliance. This includes Load Balancing, Content Switching, VPN or Authentication virtual servers using HTTP or SSL.
- CWE: CWE-444 — Inconsistent Interpretation of HTTP Requests
- CVSS v4.0: 9.3
-
Vector:
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N
CVE-2026-88774 — HTTP URL Policy Bypass
Improper use or interpretation of HTTP URL-based expressions can allow configured security or feature policies to be bypassed.
Precondition: An affected HTTP URL-based policy expression must be configured.
- CWE: CWE-16 — Configuration
- CVSS v4.0: 7.0
-
Vector:
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:N
CVE-2026-88775 — Memory Overflow in Gateway or AAA Configurations
A memory overflow vulnerability can result in unpredictable behaviour or denial of service.
Precondition: NetScaler must be configured as one of the following:
- Gateway:
- SSL VPN
- ICA Proxy
- CVPN
- RDP Proxy
-
AAA virtual server
- CWE: CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVSS v4.0: 8.8
-
Vector:
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
CVE-2026-88776 — Memory Overflow in Oracle Load Balancing
A memory overflow vulnerability can lead to unpredictable behaviour or denial of service.
Precondition: NetScaler must be configured with a Load Balancing virtual server of type Oracle.
- CWE: CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVSS v4.0: 8.8
-
Vector:
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
CVE-2026-88777 — Memory Overflow in Non-HTTP L7 Services
A memory overflow vulnerability can result in unpredictable behaviour or denial of service.
Precondition: NetScaler must be configured as an LB/CS or CGNAT-LSN/NAT64 device with a non-HTTP Layer 7 protocol feature enabled.
Potentially affected configurations include FTP, RTSP, DNS64 and NAT64 deployments.
- CWE: CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVSS v4.0: 8.8
-
Vector:
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
CVE-2026-88778 — TCP Initial Sequence Number Prediction
The TCP Initial Sequence Number generation mechanism can result in predictable values, potentially weakening assumptions about the integrity of TCP connections.
Precondition: TCP functionality is enabled and Enhanced ISN Generation is disabled.
- CWE: CWE-342 — Predictable Exact Value from Previous Values
- CVSS v4.0: 8.8
-
Vector:
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:L/SI:L/SA:L
Recommended Actions
CIRCL recommends that administrators upgrade affected NetScaler appliances as soon as possible.
The following versions contain fixes:
| Product | Fixed version |
|---|---|
| NetScaler ADC / Gateway 14.1 | 14.1-73.37 or later |
| NetScaler ADC / Gateway 13.1 | 13.1-64.23 or later |
| NetScaler ADC 14.1 FIPS | 14.1-73.37 FIPS or later |
| NetScaler ADC 13.1 FIPS / NDcPP | 13.1-37.279 or later |
Because exploitation of CVE-2026-88771 and CVE-2026-88772 has already been observed, upgrading should not be considered sufficient evidence that an appliance was not previously compromised.
For Internet-facing appliances that were running an affected version, administrators should also:
- preserve relevant logs and forensic evidence before making significant changes where operationally possible;
- review NetScaler and external network/security logs for suspicious activity;
- investigate unexpected configuration, filesystem or process changes;
- review administrative and authentication activity;
- review activity from the appliance towards internal infrastructure;
- use the indicators and detection mechanisms provided by Citrix;
- follow the organisation’s incident response process if compromise is suspected.
External forwarding of NetScaler logs to a SIEM or other independent logging infrastructure is strongly recommended, as it can provide evidence that remains available if the appliance itself is compromised.
Configuration Checks
Administrators can use their NetScaler configuration to identify whether additional vulnerability-specific preconditions are met.
CVE-2026-88771
No configuration check is required. All affected versions meet the vulnerability precondition.
CVE-2026-88772
Review VPN and virtual-server configurations for DTLS.
For example:
text
add vpn vserver vpn1 SSL 10.0.0.0 443 -Listenpolicy NONE
DTLS is enabled by default in this configuration.
An explicit:
text
-dtls OFF
indicates that DTLS has been disabled for the VPN virtual server.
Also review explicitly configured DTLS virtual servers.
CVE-2026-88773
Review HTTP/SSL Load Balancing, Content Switching, VPN and Authentication virtual servers:
text
add lb vserver <vserver-name> <HTTP or SSL>
add cs vserver <vserver-name> <HTTP or SSL>
add vpn vserver <vserver-name> <HTTP or SSL>
add authentication vserver <vserver-name> <HTTP or SSL>
CVE-2026-88775
Relevant configuration entries include:
text
add vpn vserver .*
add authentication vserver .*
CVE-2026-88776
Search for Oracle Load Balancing virtual servers:
text
add lb vserver.*ORACLE.*
CVE-2026-88777
Review configurations using non-HTTP Layer 7 protocols, including:
text
add (lb|cs) vserver .* FTP
add service .* FTP
add lb monitor .* FTP
add lb monitor .* FTP-EXTENDED
set lsn group .* -rtspalg ENABLED
add lb vserver .* DNS .* -dns64 ENABLED
add dns policy64
add nat64
For LSN/CGNAT configurations, administrators should pay particular attention to FTP ALG configuration.
CVE-2026-88778
Check whether Enhanced ISN Generation is disabled:
shell
show ns tcpparam | grep "Enhanced ISN Generation"
A result containing:
text
Enhanced ISN Generation: DISABLED
indicates that the vulnerable configuration precondition may be met when applicable TCP-based virtual servers are configured.
Administrators affected by CVE-2026-88778 should also apply the TCP configuration changes recommended by Citrix.
Incident Response Considerations
Due to the reported exploitation of the two remote-code-execution vulnerabilities, CIRCL recommends treating vulnerable Internet-exposed NetScaler appliances with additional caution.
Where an appliance was exposed to untrusted networks while vulnerable, organisations should consider performing a compromise assessment rather than relying exclusively on successful installation of the security update.
In particular, successful patching prevents subsequent exploitation of the corrected vulnerabilities but does not remediate persistence or other changes potentially introduced before the update.
References
Classification of this document
TLP:CLEAR information may be distributed without restriction, subject to copyright controls.
Revision
- Version 1.0 - TLP:CLEAR - First version - 27th September 2026