Citrix NetScaler ADC and Gateway — Multiple Remote Code Execution Zero-Day Vulnerabilities Under Active Exploitation (CVE-2026-88771 and CVE-2026-88772)
Publication date: September 27, 2026
Category: Vulnerability / Network Security
Introduction
In late September 2026, global perimeter security faced an acute crisis as Citrix confirmed that multiple remote code execution (RCE) vulnerabilities in NetScaler ADC and NetScaler Gateway had been actively exploited in the wild prior to the availability of public patches. Anticipated by external threat intelligence warnings and reports of system administrators preemptively taking appliances offline, Citrix issued an urgent security advisory addressing eight separate flaws. Among these, two critical zero-day vectors stand out for compromising enterprise edge infrastructure even under default configurations, requiring no prior privileges or user interaction.
What is NetScaler ADC and Gateway? (General Analysis)
NetScaler ADC (Application Delivery Controller) and NetScaler Gateway are critical infrastructure solutions positioned at the perimeter of corporate networks. Their primary function is to act as advanced load balancers, VPN gateways, SSL/TLS termination points, and user authentication proxies for secure remote access. Due to their strategic exposure directly to the public internet, any security flaw in these devices provides potential attackers with an ideal pivot point into the internal corporate network, enabling lateral movement and the interception of sensitive traffic.
For the evaluated vulnerabilities, official verified severity data (CVSS v4.0) and weakness classifications (CWE) are structured as follows:
| CVE | Category (CWE) | Impact | CVSS | Vector (summary) |
|---|---|---|---|---|
| CVE-2026-88771 | CWE-20 (Improper Input Validation) | Arbitrary command execution | 9.5 (Critical) | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H |
| CVE-2026-88772 | CWE-119 (Memory Buffer Errors) | RCE / Denial of Service (DoS) | 9.5 (Critical) | AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H |
| CVE-2026-19490 | CWE-288 (Authentication Bypass) | Authentication Bypass / RCE | 9.3 (Critical) | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H |
| CVE-2026-88773 | CWE-444 (HTTP Request Smuggling) | HTTP Request Smuggling | 9.3 (Critical) | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N |
| CVE-2026-88774 | Unknown / Not reported | Feature policy bypass | 7.0 (High) | AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N |
| CVE-2026-88775 | CWE-120 (Buffer Overflow) | Erroneous behavior / DoS | 8.8 (High) | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H |
| CVE-2026-88776 | CWE-119 (Memory Buffer Errors) | Erroneous behavior / DoS | 8.8 (High) | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H |
| CVE-2026-88777 | CWE-119 (Memory Buffer Errors) | Erroneous behavior / DoS | 8.8 (High) | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H |
(Note: The data above is sourced directly from official NVD records and is treated as confirmed facts).
How Does It Work? (Technical Analysis)
The exploitation mechanism behind these vulnerabilities exploits structural deficiencies in input handling and memory management within the NetScaler packet engine:
- Exploit Entry Flow (CVE-2026-88771): This flaw stems from improper input validation. An unauthenticated attacker can submit specially crafted HTTP requests or network probes that the system processes without adequately filtering control characters or embedded commands, resulting in arbitrary operating system command execution on deployments running default configurations.
- Memory Exploitation and DTLS (CVE-2026-88772): This memory overflow vulnerability resides in components handling the Datagram Transport Layer Security (DTLS) protocol. Because DTLS is enabled by default for VPN virtual servers, NetScaler Gateway appliances are inherently affected unless DTLS has been explicitly disabled. Precise manipulation of transport layer datagrams allows buffer overflows, leading to remote code execution or denial of service (DoS).
- Secondary Vectors and Logical Overflows (CVE-2026-88773 to CVE-2026-88778): Additional weaknesses include HTTP Request Smuggling, URL expression policy bypasses, memory overflows in Layer 7 protocol handlers (such as Oracle, FTP, RTSP, DNS64), and TCP Initial Sequence Number (ISN) prediction issues when enhanced ISN generation is turned off.
Affected Systems / Environments
The vulnerabilities impact both NetScaler ADC and NetScaler Gateway across customer-managed appliances, including instances deployed in Secure Private Access hybrid setups. Affected product branches include:
- ADC and Gateway versions prior to
14.1-73.37and prior to13.1-64.23. - FIPS builds prior to
14.1-73.37 FIPSand13.1-37.279 FIPS. - NDcPP variants prior to
13.1-37.279. - Notably, appliances that applied the August update to remediate the authentication bypass flaw (
CVE-2026-19490) fall within the affected range and require the new corrective update.
Mitigation and Detection
Remediation
The sole effective and permanent mitigation provided by the vendor is the immediate update of affected firmwares to the patched versions:
- Upgrade to NetScaler ADC / Gateway 14.1-73.37 or later.
- Upgrade to NetScaler ADC / Gateway 13.1-64.23 or later (for branch 13.1).
- Apply corresponding FIPS and NDcPP patches starting from build
13.1-37.279or later. - For the TCP sequence flaw (
CVE-2026-88778), administrators must apply the recommended TCP configuration change to enable Enhanced ISN Generation. - Ensure management interfaces are strictly kept off the public internet.
Detection
Threat Intelligence Warning: Because zero-day exploitation occurred prior to public patch availability, applying software updates does not eliminate residual risk if an attacker previously established persistence on the appliance.
For Blue Teams and incident responders, Citrix’s established guidance for suspected compromise outlines the following protocols:
- Preserve Evidence First: Take a snapshot of the VPX instance, gather logs from remote syslog servers and NetScaler Console, collect a technical support bundle, and obtain a core dump of the packet engine.
- Isolate the Appliance: Disconnect the affected device from the network immediately.
- Rotate Credentials: Change every service account password and secret stored on the device, reset passwords for users who authenticated through it, and revoke all certificates and private keys.
- Conduct Forensic Audits: Execute live-appliance verification scripts and full image reviews to search for anomalous files or unauthorized system modifications.
Wrapping Up
The emergence of these zero-day vulnerabilities in NetScaler devices highlights the relentless pursuit of threat actors targeting critical perimeter infrastructure. With multiple critical flaws actively exploited under unauthenticated vectors, organizations face a scenario where patching alone is insufficient if the perimeter was previously compromised. Adopting rigorous countermeasures, isolating management interfaces, and performing thorough post-patch forensic audits remain vital imperatives for operational security resilience.
References
- Citrix Support. (2026). Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, and related flaws (CTX697096). https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096
- U.S. National Vulnerability Database. (2026). NVD Record: CVE-2026-88771. https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-88771
- U.S. National Vulnerability Database. (2026). NVD Record: CVE-2026-88772. https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-88772
- U.S. National Vulnerability Database. (2026). NVD Record: CVE-2026-19490. https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-19490
- Citrix Support. (2026). Steps to take if NetScaler ADC is suspected to be compromised. https://support.citrix.com/external/article/CTX694799/steps-to-take-if-netscaler-adc-is-suspected-to-be-compromised.html
- Netherlands National Cyber Security Centre (NCSC-NL). (2025). Casus Citrix kwetsbaarheid. https://www.ncsc.nl/alerts/casus-citrix-kwetsbaarheid
- NCSC-NL GitHub Repository. (2025). Live-host bash check README. https://github.com/NCSC-NL/citrix-2025/blob/main/live-host-bash-check/README.md