Threat Insight
Multiple Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway
On Sept 27th, 2026, Citrix released security updates to address eight vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway.
According to Citrix, the vulnerabilities include multiple remote code execution (RCE), memory corruption, HTTP request smuggling, policy bypass, denial-of-service, and TCP sequence prediction issues.
Of particular concern are CVE-2026-88771 and CVE-2026-88772. Both vulnerabilities were exploited in the wild prior to the release of security updates. While patches are now available, organizations running affected NetScaler deployments should not only prioritize patching but also consider the possibility that vulnerable systems may have been compromised before remediation became available.
CVE-2026-88771 is an unauthenticated remote code execution vulnerability caused by improper input validation and affects all NetScaler ADC and NetScaler Gateway deployments by default.
CVE-2026-88772 is a memory overflow vulnerability that may lead to remote code execution or denial of service when DTLS is enabled, which is enabled by default on VPN virtual servers [1].
CVE
CVE-2026-88771
CVE-2026-88772
CVE-2026-88773
CVE-2026-88774
CVE-2026-88775
CVE-2026-88776
CVE-2026-88777
CVE-2026-88778
Affected Products
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 BEFORE 14.1-73.37
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 BEFORE 13.1-64.23
Citrix NetScaler ADC FIPS BEFORE 14.1-73.37 FIPS
Citrix NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.279
Exploitation
Exploitation of CVE-2026-88771 and CVE-2026-88772 has been observed on unmitigated NetScaler deployments[1].
Recommended Actions
Truesec recommends that customers upgrade vulnerable NetScaler appliances to fixed releases as soon as possible.
NetScaler ADC and NetScaler Gateway 14.1-73.37 or later
NetScaler ADC and NetScaler Gateway 13.1-64.23 or later
NetScaler ADC FIPS 14.1-73.37 FIPS or later
NetScaler ADC FIPS and NDcPP 13.1-37.279 or later
If upgrading is not an option, please implement strict containment measures until you are able to upgrade[2]:
- If your organization utilizes NetScaler Gateway solely for telework or administrative access, immediately configure upstream edge firewalls to restrict inbound traffic on TCP port 443 to verified, geographic IP ranges or corporate-managed static IPs. Completely eliminate public internet access (0.0.0.0/0) to the Gateway interface.
- If NetScaler is used exclusively for application load balancing and Content Switching (without Gateway or AAA features), verify that the VPN virtual server (vserver) is completely disabled: text disable vpn vserver
- If suspicious shell executions, unexpected cron tasks, or memory crash dumps in /var/crash/ are discovered, immediately isolate the appliance from the network. Take a full forensic snapshot of the disk and memory state, revoke all corporate SSL/TLS certificates and private keys hosted on the appliance, and force an organization-wide password and MFA session reset for all users who authenticated through the gateway over the preceding 30 days.
Detection
Truesec has observed these potential C2 IPs:
104.248.244.66
139.180.152.138
77.83.199.39
These IP addresses has been added to automated threat hunting and will be hunted for every 4 hours.
References
[1] https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096&articleTitle=Citrix_NetS…
[2] https://sh3llc0d3.com/blog/inside-the-netscaler-zero-day-siege-chained-pre-auth-rces-weaponized-in-the-wild-watchtowr-disclosure/
Stay ahead with cyber insights
Newsletter
Stay ahead in cybersecurity! Sign up for Truesec’s newsletter to receive the latest insights, expert tips, and industry news directly to your inbox. Join our community of professionals and stay informed about emerging threats, best practices, and exclusive updates from Truesec.
Your current browser privacy settings may be preventing this form from loading properly. To continue, please allow cookies/tracking for this site or temporarily disable strict privacy protection, then refresh the page.
If you’re still experiencing issues, please contact us at hello@truesec.com