Citrix NetScaler ADC and Gateway Zero-day Vulnerabilities Exploited in Attacks (CVE-2026-88771 & CVE-2026-88772)
CISA says exploited Citrix NetScaler zero-days CVE-2026-88771 and CVE-2026-88772 need urgent patching.
CISA added CVE-2026-88771 and CVE-2026-88772 to the Known Exploited Vulnerabilities catalog and ordered agencies to patch Citrix NetScaler ADC and Gateway before September 30, 2026. CVE-2026-88771 is an improper input validation flaw that can let an unauthenticated attacker run arbitrary commands and affects default deployments. CVE-2026-88772 is a memory overflow that can lead to remote code execution or denial of service when DTLS is enabled, which is on by default for VPN virtual servers. Citrix bulletin CTX697096 also fixes CVE-2026-88773 through CVE-2026-88778, including request smuggling, policy bypass, and denial-of-service bugs, in 14.1-73.37, 13.1-64.23, and corresponding FIPS builds.
- CVE-2026-88771 allows unauthenticated command execution on default NetScaler setups.
- CVE-2026-88772 can yield remote code execution or denial of service via DTLS.
- Both flaws are in CISA's KEV catalog with a September 30, 2026 deadline.
- Fixed builds include 14.1-73.37 and 13.1-64.23, plus listed FIPS releases.
- Six further issues, CVE-2026-88773 through CVE-2026-88778, were also patched.
Vulnerabilities mentionedAll →
- CVE-2026-887729.51%Unauthenticated RCE/DoS in Citrix NetScaler ADC and Gatewaypublished · Citrix NetScaler ADC KEV PoC ×2+1 related
Full article582 words · extracted from threatprotect.qualys.com · click to collapse
The Cybersecurity and Infrastructure Security Agency (CISA) has ordered agencies to secure their systems against two critical Citrix NetScaler vulnerabilities that have been exploited in attacks. CISA added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities Catalog. CISA urged users to patch the vulnerabilities before September 30, 2026.
CVE-2026-88771
This is an improper input validation flaw that may allow an unauthenticated attacker to execute arbitrary commands on the target system.
CVE-2026-88772
This is a memory overflow vulnerability that may allow an attacker to achieve remote code execution or denial of service.
Steps to verify the prerequisites for the vulnerabilities
CVE-2026-88771
Prerequisite: All NetScaler ADC and NetScaler Gateway deployments (Default configuration / No additional feature required).
Instructions: All NetScaler ADC and NetScaler Gateway deployments are affected, including those deployed with the default configuration.
CVE-2026-88772
Prerequisite: DTLS configuration enabled on NetScaler ADC or NetScaler Gateway (Note: Enabled by default on VPN vServer).
Instructions: Users can determine whether their NetScaler deployment meets this precondition by inspecting the configuration for DTLS-enabled virtual servers. A NetScaler Gateway is vulnerable if DTLS is not explicitly disabled, and other virtual servers are vulnerable if configured with DTLS.
Relevant configuration patterns to check:
-
add vpn vserver vpn1 SSL 10.0.0.0 443 -Listenpolicy NONEThis indicates that DTLS is not explicitly disabled; it is enabled by default.
-
add vpn vserver vpn1 SSL 10.0.0.0 443 -dtls OFF -Listenpolicy NONEThis indicates DTLS is explicitly disabled, so the precondition is not met.
-
add vpn vserver vs1 DTLS 10.11.1.1 443
This indicates DTLS is enabled.
-
add lb vserver vd_dtls DTLS 10.146.111.74 443 -persistenceType NONE -cltTimeout 120
This indicates DTLS is enabled.
Citrix also addressed the following vulnerabilities in the advisory:
- CVE-2026-88773 is an HTTP request smuggling vulnerability affecting systems with HTTP enabled. Successful exploitation allows threat actors to interfere with how the affected system interprets and processes HTTP requests.
- CVE-2026-88774 is a configuration vulnerability affecting policies that use HTTP URL-based expressions. Successful exploitation allows threat actors to bypass affected feature policies.
- CVE-2026-88775 is a memory buffer-bound vulnerability affecting systems configured as a Gateway or an authentication, authorization, and auditing (AAA) virtual server. Successful exploitation allows threat actors to cause unexpected system behavior or a DoS condition.
- CVE-2026-88776 is a memory buffer bounds vulnerability affecting systems configured with an Oracle load-balancing virtual server. Successful exploitation allows threat actors to cause unexpected system behavior or a DoS condition.
- CVE-2026-88777 is a memory buffer overflow vulnerability affecting systems that use specified non-HTTP Layer 7 protocol features. Successful exploitation allows threat actors to cause unexpected system behavior or a DoS condition.
- CVE-2026-88778 is a predictable value vulnerability affecting systems with TCP enabled. Successful exploitation allows threat actors to predict TCP Initial Sequence Numbers (ISNs) on affected connections.
Affected versions
- Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 BEFORE 14.1-73.37
- Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 BEFORE 13.1-64.23
- Citrix NetScaler ADC FIPS BEFORE 14.1-73.37 FIPS
- Citrix NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.279
Mitigation
- Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later
- Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
- Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
- Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.279 and later releases of 13.1-FIPS and 13.1-NDcPP
Please refer to the Citrix Security Bulletin (CTX697096) for more information.
Qualys Detection
Qualys customers can scan their devices with QID 388834 to detect vulnerable assets.
Please continue to follow Qualys Threat Protection for more coverage of the latest vulnerabilities.
References
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096