Skip to main content
All posts

Critical zero-days in Citrix NetScaler ADC & Gateway: Patch CVE-2026-88771 and CVE-2026-88772 immediately

A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands.

Critical zero-days in Citrix NetScaler ADC & Gateway: Patch CVE-2026-88771 and CVE-2026-88772 immediately
Updated 3 min read

On September 27, 2026, Citrix released a critical security bulletin (CTX697096) addressing eight vulnerabilities in customer-managed NetScaler ADC and NetScaler Gateway appliances.

Among these findings are two critical unauthenticated Remote Code Execution (RCE) zero-days—CVE-2026-88771 and CVE-2026-88772—that are actively being exploited in the wild.

The Cybersecurity and Infrastructure Security Agency (CISA) has added both flaws to its Known Exploited Vulnerabilities (KEV) catalog, underscoring the urgency for immediate remediation.

Breakdown of the vulnerabilities

The bulletin discloses eight total vulnerabilities, ranging from critical unauthenticated remote execution down to high-severity denial-of-service (DoS) conditions and HTTP request smuggling.

CVE ID Severity (CVSS v3) Vulnerability type Preconditions / affected setup
CVE-2026-88771 Critical (9.5) Unauthenticated RCE (Improper Input Validation) Default configuration. Affects all instances on impacted versions. (Exploited in the wild)
CVE-2026-88772 Critical (9.5) Unauthenticated RCE / DoS (Memory Overflow) DTLS enabled (default on NetScaler Gateway VPN vServers). (Exploited in the wild)
CVE-2026-88773 High (9.3) HTTP Request Smuggling HTTP URL-based policy expressions configured
CVE-2026-88774 High (7.0) Policy Bypass HTTP URL-based policy expressions configured
CVE-2026-88775 High (8.8) Memory Overflow / DoS Gateway or AAA vServer configured
CVE-2026-88776 High (8.8) Memory Overflow / DoS Load Balancing (LB) vServer of type Oracle configured
CVE-2026-88777 High (8.8) Memory Overflow / DoS LB/CS or CGNAT-LSN/NAT64 with non-HTTP L7 protocol enabled
CVE-2026-88778 Medium Predictable TCP Initial Sequence Numbers (ISNs) TCP configuration enabled (Requires manual mitigation configuration)

Why this threat is severe

NetScaler appliances sit at the perimeter of many enterprise networks, serving as key gateways for authentication and load balancing. Vulnerabilities in these appliances offer attackers direct network access:

  1. No authentication required: An unauthenticated remote attacker can execute arbitrary commands on vulnerable perimeter devices without needing valid credentials.
  2. Default configurations exposed: CVE-2026-88771 requires no special feature toggles or non-default configurations—meaning any exposed appliance running a vulnerable build is vulnerable out-of-the-box.
  3. Widespread preconditions: CVE-2026-88772 triggers when DTLS is active. Because DTLS is enabled by default on NetScaler VPN virtual servers, most enterprise deployments meet this precondition.

Affected Citrix NetScaler products and immediate actions

1. Log into the ADC Portal

The Loadbalancer.org ADC Portal automatically scans for Common Vulnerabilities and Exposures (CVEs) affecting connected Application Delivery Controllers (ADCs) by querying the NIST National Vulnerability Database.

Once logged in to your ADC Portal account, navigate to Security > Insights.

From there, identify your affected NetScaler appliances.

2. Preserve logs and state evidence

Because updating software can overwrite volatile forensic traces, check for signs of potential compromise first if you manage internet-facing instances. Take snapshot logs and evaluate system activity before applying the patch.

3. Apply the official firmware patches

No configuration workarounds exist for RCEs so there are no functional workaround settings for CVE-2026-88771 or CVE-2026-88772.

Deploy the fixed software build (14.1-73.37 or 13.1-64.23 dependent on branch) across all customer-managed devices immediately by clicking 'Update ADC':

4. Enable enhanced ISN generation

Upgrading the software alone does not resolve CVE-2026-88778. For deployments utilizing TCP configurations, explicitly enable Enhanced ISN Generation within your NetScaler configuration settings to prevent predictable initial sequence numbers.

5. Contact our support team for a free load balancer health check

The ADC Portal can help you identify, mitigate, and resolve Common Vulnerabilities and Exposures (CVEs) across your NetScaler, F5, Progress Kemp and Loadbalancer.org fleet. To find out how, contact our support team.

Further reading

What to do when your NetScaler becomes a liability.

Read blog

Related posts