Citrix NetScaler ADC and Gateway Multiple Vulnerabilities, Including Two Actively Exploited Zero-Days
Release Date: 4th October 2026 (Added 6th October 2026)
Impact : CRITICAL
TLP Rating: Clear 
The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.
This alert is relevant to Organizations and System/Network administrators that utilize the above product(s). This alert is intended to be understood by technical users and systems administrators.
What is it?
Citrix has released security bulletin CTX697096 covering eight vulnerabilities (CVE-2026-88771 to CVE-2026-88778) in NetScaler ADC and NetScaler Gateway. Because they affect the same products and are fixed by the same updates, CERTVU has combined them in this single advisory. Two of them, CVE-2026-88771 and CVE-2026-88772, were exploited as zero-days before a patch was available.
CVE-2026-88771 is an improper input validation flaw that lets an unauthenticated attacker run commands on the appliance, and it affects all configurations. CVE-2026-88772 is a memory overflow in Datagram Transport Layer Security (DTLS) handling that can lead to remote code execution or denial of service; it is reachable when DTLS is enabled, which is the default on VPN virtual servers.
The other six flaws only affect appliances with particular configurations, and no exploitation has been reported for them: CVE-2026-88773, HTTP request smuggling (CVSS 9.3; HTTP/SSL load balancing, content switching, VPN or AAA virtual servers); CVE-2026-88774, feature policy bypass through URL normalization (CVSS 7.0; policy expressions using HTTP URL parameters); CVE-2026-88775, memory overflow causing unpredictable behavior or denial of service (CVSS 8.8; Gateway or AAA virtual servers); CVE-2026-88776, memory overflow (CVSS 8.8; load balancing virtual servers of Oracle type); CVE-2026-88777, memory overflow (CVSS 8.8; non-HTTP Layer 7 features such as FTP, RTSP ALG, DNS64 and NAT64); and CVE-2026-88778, TCP Initial Sequence Number prediction (CVSS 8.8; TCP virtual servers with Enhanced ISN Generation disabled).
What are the systems affected?
The following NetScaler versions are affected:
NetScaler ADC and Gateway 14.1, before 14.1-73.37 – (Affected)
NetScaler ADC and Gateway 13.1, before 13.1-64.23 (13.1-64.24 per some sources) – (Affected)
NetScaler ADC 14.1-FIPS, before 14.1-73.37, and 13.1-FIPS/NDcPP, before 13.1-37.279 – (Affected)
Secure Private Access hybrid deployments that use NetScaler – (Affected)
Customer-managed (on-premises) appliances must be updated by the customer. Releases that are end of life receive no fix and must be upgraded to a supported branch. Only CVE-2026-88771 affects all configurations; check the pre-conditions in the bulletin for each of the others.
Not affected / patched versions:
NetScaler ADC and Gateway 14.1-73.37 or later, and 13.1-64.24 or later (confirm 64.23 versus 64.24 in CTX697096) – (Not affected)
NetScaler ADC 14.1-FIPS 14.1-73.37 or later, and 13.1-FIPS/NDcPP 13.1-37.279 or later – (Not affected)
CVE-2026-88778 also requires enabling Enhanced ISN Generation after upgrading, as described in the Citrix bulletin
To also cover CVE-2026-88779 (see CERTVU Advisory 342), use 14.1-73.41 or later and 13.1-64.28 or later
What does this mean?
Successful exploitation may allow attackers to:
- Run commands on the NetScaler appliance without credentials (CVE-2026-88771)
- Execute code or crash the appliance through a crafted DTLS handshake (CVE-2026-88772)
- Smuggle HTTP requests, bypass policies, crash the appliance, or predict TCP sequence numbers on appliances with the affected configurations (CVE-2026-88773 to CVE-2026-88778)
- Deploy web shells, harvest VPN and session credentials, and pivot from the network edge into the internal network
Mitigation process?
CERTVU recommends the following:
-
Upgrade Immediately
Upgrade to 14.1-73.37 or later, 13.1-64.24 or later, or the fixed FIPS/NDcPP build listed above. Treat this as an emergency change, and consider going straight to 14.1-73.41 or 13.1-64.28 to also cover CVE-2026-88779. -
Reduce DTLS Exposure if You Cannot Patch Yet
-
Review the Pre-Conditions for Each CVE
-
Hunt for Compromise Before and After Patching
-
Preserve Evidence, Isolate and Rotate Credentials
Reference
- https://support.citrix.com/external/article/CTX697096/citrix-netscaler-adc-and-citrix-netscale.html
- https://unit42.paloaltonetworks.com/netscaler-zero-days-exploited/
- https://labs.watchtowr.com/here-we-go-again-citrix-netscaler-dtls-preauth-memory-overflow-cve-2026-88772/
- https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/critical-vulnerabilities-in-citrix-netscaler-adc-and-citrix-netscaler-gateway-products
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://nvd.nist.gov/vuln/detail/CVE-2026-88772
- Download advisory (English): Citrix NetScaler ADC and Gateway Multiple Vulnerabilities