Mastodon Mastodon Mastodon Mastodon

CISA warns of active exploitation of two critical vulnerabilities in Citrix NetScaler ADC and Gateway

Photo of author

CyberSecureFox Editorial Team

Published:

On September 27, 2026, CISA added two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway — CVE-2026-88771 and CVE-2026-88772, both with a CVSS v4.0 score of 9.5 — to its Known Exploited Vulnerabilities (KEV) catalog. According to the Citrix security advisory, both vulnerabilities are already being exploited on unprotected NetScaler deployments. The flaws allow an unauthenticated attacker to execute arbitrary commands or cause a denial of service. Citrix has released fixed firmware versions, and U.S. federal agencies have been given a remediation deadline of September 30, 2026.

Technical details of the vulnerabilities

CVE-2026-88771 (CVSS v4.0: 9.5, CWE-20: Improper Input Validation) is a remote code execution vulnerability caused by improper input validation. It allows an unauthenticated attacker to execute arbitrary commands on the target device. According to the Citrix advisory, this vulnerability affects all NetScaler ADC and NetScaler Gateway deployments in the default configuration — no additional features or settings are required for exploitation.

CVE-2026-88772 (CVSS v4.0: 9.5, CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer) is a memory buffer overflow vulnerability that can lead to remote code execution or denial of service. Successful exploitation requires DTLS to be enabled on the device. A critically important nuance: on VPN virtual servers (VPN vServer), the DTLS protocol is enabled by default unless explicitly disabled by an administrator. As a result, most NetScaler Gateway VPN deployments are vulnerable with no additional conditions.

Differences in scope of impact

The two vulnerabilities have significantly different scopes of impact. CVE-2026-88771 affects all customer NetScaler ADC and Gateway deployments without exception, which makes it the broadest in coverage. CVE-2026-88772 is formally limited to configurations with DTLS enabled, but since this protocol is enabled by default on VPN servers, the real attack surface is also substantial. To determine exposure to CVE-2026-88772, administrators should check the DTLS configuration on their virtual servers.

Affected versions

According to the Citrix advisory, the following versions are vulnerable:

  • Citrix NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
  • Citrix NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
  • Citrix NetScaler ADC FIPS before 14.1-73.37 FIPS
  • Citrix NetScaler ADC FIPS and NDcPP before 13.1.37.279

The advisory applies to customer (self-managed) deployments. Citrix cloud services and managed adaptive authentication are updated by Cloud Software Group.

Impact assessment

NetScaler ADC and NetScaler Gateway are key components of network infrastructure, providing load balancing, VPN access, and application delivery. Compromising these devices gives attackers a pathway into the corporate network and potential access to internal systems connected to NetScaler. Given that CVE-2026-88771 does not require authentication and affects default configurations, every unprotected internet-exposed NetScaler device is an immediate target.

We have previously covered the addition of Citrix NetScaler vulnerabilities to the KEV catalog — the current incident confirms that the NetScaler product line remains a priority target for attackers.

Detection and response

Citrix has provided generalized indicators of compromise (IoCs) via the NetScaler Console for an initial assessment of deployment status. However, Citrix explicitly warns that these indicators do not cover all attacker tactics, techniques, and procedures (TTPs) and cannot serve as definitive proof that no compromise has occurred. A negative scan result in NetScaler Console is a starting point for investigation, not a guarantee of security.

Practical recommendations

Immediate update: install the fixed firmware versions — 14.1-73.37 and later, 13.1-64.23 and later, 14.1-73.37 FIPS and later, 13.1.37.279 and later for the FIPS and NDcPP branches.

If compromise is suspected Citrix recommends the following sequence of actions:

  1. Preserve evidence (an image of the NetScaler ADC VPX instance)
  2. Isolate the device from the network
  3. Revoke all credentials and access rights
  4. Investigate all servers and systems that NetScaler ADC connected to for signs of further compromise
  5. Rebuild the device and update the firmware to the latest version
  6. Rotate all local passwords, key encryption keys (KEKs), and replace SSL certificates when restoring from backup
  7. Harden the device in line with best practices

Since CVE-2026-88771 affects all deployments without additional conditions, every customer NetScaler ADC and Gateway device should be treated as an urgent update target. To assess exposure to CVE-2026-88772, you must additionally check whether DTLS is enabled on virtual servers — primarily on VPN servers, where this protocol is active by default.

Both vulnerabilities have been confirmed as actively exploited, patches are available, and the remediation deadline for U.S. federal agencies is September 30, 2026. Organizations using NetScaler ADC or Gateway should update firmware to the fixed versions within hours, not days, and in parallel run checks via NetScaler Console for indicators of compromise, followed by a full investigation if any suspicious activity is detected.


CyberSecureFox Editorial Team

The CyberSecureFox Editorial Team covers cybersecurity news, vulnerabilities, malware campaigns, ransomware activity, AI security, cloud security, and vendor security advisories. Articles are prepared using official advisories, CVE/NVD data, CISA alerts, vendor publications, and public research reports. Content is reviewed before publication and updated when new information becomes available.

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.