Citrix NetScaler ADC and Gateway Multiple Vulnerabilities, Including Two Actively Exploited Zero-Days

Release Date: 4th October 2026 (Added 6th October 2026)

Impact : CRITICAL

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations and System/Network administrators that utilize the above product(s). This alert is intended to be understood by technical users and systems administrators.

What is it?

Citrix has released security bulletin CTX697096 covering eight vulnerabilities (CVE-2026-88771 to CVE-2026-88778) in NetScaler ADC and NetScaler Gateway. Because they affect the same products and are fixed by the same updates, CERTVU has combined them in this single advisory. Two of them, CVE-2026-88771 and CVE-2026-88772, were exploited as zero-days before a patch was available.

CVE-2026-88771 is an improper input validation flaw that lets an unauthenticated attacker run commands on the appliance, and it affects all configurations. CVE-2026-88772 is a memory overflow in Datagram Transport Layer Security (DTLS) handling that can lead to remote code execution or denial of service; it is reachable when DTLS is enabled, which is the default on VPN virtual servers.

The other six flaws only affect appliances with particular configurations, and no exploitation has been reported for them: CVE-2026-88773, HTTP request smuggling (CVSS 9.3; HTTP/SSL load balancing, content switching, VPN or AAA virtual servers); CVE-2026-88774, feature policy bypass through URL normalization (CVSS 7.0; policy expressions using HTTP URL parameters); CVE-2026-88775, memory overflow causing unpredictable behavior or denial of service (CVSS 8.8; Gateway or AAA virtual servers); CVE-2026-88776, memory overflow (CVSS 8.8; load balancing virtual servers of Oracle type); CVE-2026-88777, memory overflow (CVSS 8.8; non-HTTP Layer 7 features such as FTP, RTSP ALG, DNS64 and NAT64); and CVE-2026-88778, TCP Initial Sequence Number prediction (CVSS 8.8; TCP virtual servers with Enhanced ISN Generation disabled).

Reference

  1. https://support.citrix.com/external/article/CTX697096/citrix-netscaler-adc-and-citrix-netscale.html
  2. https://unit42.paloaltonetworks.com/netscaler-zero-days-exploited/
  3. https://labs.watchtowr.com/here-we-go-again-citrix-netscaler-dtls-preauth-memory-overflow-cve-2026-88772/
  4. https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/critical-vulnerabilities-in-citrix-netscaler-adc-and-citrix-netscaler-gateway-products
  5. https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  6. https://nvd.nist.gov/vuln/detail/CVE-2026-88772