Skip navigation

Citrix published a security bulletin on September 27, 2026. It covers eight vulnerabilities in customer-managed NetScaler ADC and NetScaler Gateway. Two of them, CVE-2026-88771 and CVE-2026-88772, are under active exploitation. Both score 9.5 under CVSS v4.0. This post summarizes the critical CVEs, the exposure checks, and the fix.

It’s also has this gem in the header:

<meta name="robots" content="noindex">

Source: NetScaler ADC and NetScaler Gateway security bulletin

Let’s make sure it gets indexed in other ways!

Here’s some helpful info you’ll find more details of in their bulletin.

Critical CVEs

CVE-2026-88771 is a remote code execution flaw from improper input validation. An unauthenticated attacker can run arbitrary commands. Every deployment is affected, and no optional feature is required.

CVE-2026-88772 is a memory overflow that leads to remote code execution or denial of service. The precondition is DTLS. DTLS is enabled by default on VPN virtual servers, so a deployment that never turned it off is exposed.

CVE-2026-88773 scores 9.3. It is an HTTP request smuggling flaw that affects deployments with HTTP or SSL virtual servers.

All eight vulnerabilities

CVE Description Precondition CWE CVSS v4.0
CVE-2026-88771 Remote code execution from improper input validation. All deployments, default config included. CWE-20 9.5
CVE-2026-88772 Memory overflow that leads to remote code execution or denial of service. DTLS enabled. Default on VPN virtual servers. CWE-119 9.5
CVE-2026-88773 HTTP request smuggling. HTTP or SSL virtual servers. CWE-444 9.3
CVE-2026-88774 Policy bypass from improper HTTP URL expression use. HTTP or SSL virtual servers. CWE-16 7.0
CVE-2026-88775 Memory overflow that leads to erroneous behavior or denial of service. Gateway or AAA virtual server. CWE-119 8.8
CVE-2026-88776 Memory overflow that leads to erroneous behavior or denial of service. Oracle load balancing virtual server. CWE-119 8.8
CVE-2026-88777 Memory overflow that leads to erroneous behavior or denial of service. LB/CS or CGNAT-LSN/NAT64 with a non-HTTP L7 protocol. CWE-119 8.8
CVE-2026-88778 TCP initial sequence number prediction. TCP enabled. CWE-342 8.8

Check your exposure

Run the checks that match your deployment.

  • CVE-2026-88771: every deployment is exposed. No check is needed.
  • CVE-2026-88772: DTLS is on. add vpn vserver vpn1 SSL 10.0.0.0 443 -Listenpolicy NONE means on. -dtls OFF means off. A DTLS virtual server means on.
  • CVE-2026-88773 and CVE-2026-88774: you use an LB, CS, VPN, or Authentication virtual server of type HTTP or SSL.
  • CVE-2026-88775: the config holds add vpn vserver .* or add authentication vserver .*.
  • CVE-2026-88776: the config holds add lb vserver.*ORACLE.*.
  • CVE-2026-88777: you run LB/CS or CGNAT-LSN/NAT64 with FTP, RTSP, DNS64, or NAT64 enabled.
  • CVE-2026-88778: a listed virtual server type is present, and show ns tcpparam | grep "Enhanced ISN Generation" returns DISABLED.

Fix it

  1. Install a fixed release: 14.1-73.37, 13.1-64.23, 14.1-FIPS 14.1-73.37, or 13.1-FIPS and 13.1-NDcPP 13.1.37.279.
  2. Take the later release in the branch when one exists.
  3. Run show ns variable. If it returns output, install 13.1-64.24, not 13.1-64.23.
  4. Make sure your identity provider signs SAML assertions.
  5. Turn on the telemetry channel and run the IoC scan from the NetScaler Console Security Advisory page.
  6. Forward NetScaler logs to your SIEM platform.