Citrix published a security bulletin on September 27, 2026. It covers eight vulnerabilities in customer-managed NetScaler ADC and NetScaler Gateway. Two of them, CVE-2026-88771 and CVE-2026-88772, are under active exploitation. Both score 9.5 under CVSS v4.0. This post summarizes the critical CVEs, the exposure checks, and the fix.
It’s also has this gem in the header:
<meta name="robots" content="noindex">
Source: NetScaler ADC and NetScaler Gateway security bulletin
Let’s make sure it gets indexed in other ways!
Here’s some helpful info you’ll find more details of in their bulletin.
Critical CVEs
CVE-2026-88771 is a remote code execution flaw from improper input validation. An unauthenticated attacker can run arbitrary commands. Every deployment is affected, and no optional feature is required.
CVE-2026-88772 is a memory overflow that leads to remote code execution or denial of service. The precondition is DTLS. DTLS is enabled by default on VPN virtual servers, so a deployment that never turned it off is exposed.
CVE-2026-88773 scores 9.3. It is an HTTP request smuggling flaw that affects deployments with HTTP or SSL virtual servers.
All eight vulnerabilities
| CVE | Description | Precondition | CWE | CVSS v4.0 |
|---|---|---|---|---|
| CVE-2026-88771 | Remote code execution from improper input validation. | All deployments, default config included. | CWE-20 | 9.5 |
| CVE-2026-88772 | Memory overflow that leads to remote code execution or denial of service. | DTLS enabled. Default on VPN virtual servers. | CWE-119 | 9.5 |
| CVE-2026-88773 | HTTP request smuggling. | HTTP or SSL virtual servers. | CWE-444 | 9.3 |
| CVE-2026-88774 | Policy bypass from improper HTTP URL expression use. | HTTP or SSL virtual servers. | CWE-16 | 7.0 |
| CVE-2026-88775 | Memory overflow that leads to erroneous behavior or denial of service. | Gateway or AAA virtual server. | CWE-119 | 8.8 |
| CVE-2026-88776 | Memory overflow that leads to erroneous behavior or denial of service. | Oracle load balancing virtual server. | CWE-119 | 8.8 |
| CVE-2026-88777 | Memory overflow that leads to erroneous behavior or denial of service. | LB/CS or CGNAT-LSN/NAT64 with a non-HTTP L7 protocol. | CWE-119 | 8.8 |
| CVE-2026-88778 | TCP initial sequence number prediction. | TCP enabled. | CWE-342 | 8.8 |
Check your exposure
Run the checks that match your deployment.
- CVE-2026-88771: every deployment is exposed. No check is needed.
- CVE-2026-88772: DTLS is on.
add vpn vserver vpn1 SSL 10.0.0.0 443 -Listenpolicy NONEmeans on.-dtls OFFmeans off. ADTLSvirtual server means on. - CVE-2026-88773 and CVE-2026-88774: you use an LB, CS, VPN, or Authentication virtual server of type HTTP or SSL.
- CVE-2026-88775: the config holds
add vpn vserver .*oradd authentication vserver .*. - CVE-2026-88776: the config holds
add lb vserver.*ORACLE.*. - CVE-2026-88777: you run LB/CS or CGNAT-LSN/NAT64 with FTP, RTSP, DNS64, or NAT64 enabled.
- CVE-2026-88778: a listed virtual server type is present, and
show ns tcpparam | grep "Enhanced ISN Generation"returnsDISABLED.
Fix it
- Install a fixed release: 14.1-73.37, 13.1-64.23, 14.1-FIPS 14.1-73.37, or 13.1-FIPS and 13.1-NDcPP 13.1.37.279.
- Take the later release in the branch when one exists.
- Run
show ns variable. If it returns output, install 13.1-64.24, not 13.1-64.23. - Make sure your identity provider signs SAML assertions.
- Turn on the telemetry channel and run the IoC scan from the NetScaler Console Security Advisory page.
- Forward NetScaler logs to your SIEM platform.