Active Exploitation of Vulnerabilities in Citrix NetScaler ADC and Citrix NetScaler Gateway
28 September 2026
Attackers are exploiting multiple vulnerabilities in Citrix NetScaler ADC and Citrix NetScaler Gateway. Patch immediately.
Background
Citrix NetScaler has released security updates to address multiple vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway. The vulnerabilities and their respective Common Vulnerability Scoring System (CVSS) scores are:
CVE-2026-88771 and CVE-2026-88772: 9.5 out of 10
CVE-2026-88773: 9.3 out of 10
CVE-2026-88774: 7.0 out of 10
CVE-2026-88775 to CVE-2060-8878: 8.8 out of 10
Impact
Successful exploitation could allow an unauthenticated attacker to execute arbitrary commands on affected Citrix NetScaler ADC and Citrix NetScaler Gateway appliances. These vulnerabilities, which include improper input validation, memory overflows and inconsistent interpretation of HTTP requests, could also lead to remote code execution, denial of service, unpredictable or erroneous behaviour, HTTP request/response smuggling and a feature policy bypass.
Known Exploitation
One or more of these vulnerabilities are reportedly being actively exploited.
Affected Products
These vulnerabilities affect the following products:
Citrix NetScaler ADC versions before 14.1-73.37
Citrix NetScaler ADC versions before 13.1-64.23
Citrix NetScaler ADC versions before 13.1.37.279 FIPS and NDcPP
Citrix NetScaler ADC versions before 13.1-37.279 and NDcPP
Citrix NetScaler Gateway versions before 14.1-73.37
Citrix NetScaler Gateway versions before 13.1-64.23
Users and administrators should refer to the vendor advisory for the full list of affected versions.
Recommendations
Users and administrators of affected products are advised to update to the latest versions immediately.
References
https://nvd.nist.gov/vuln/detail/CVE-2026-88771 (opens in new tab)
https://nvd.nist.gov/vuln/detail/CVE-2026-88772 (opens in new tab)
https://nvd.nist.gov/vuln/detail/CVE-2026-88773 (opens in new tab)
https://nvd.nist.gov/vuln/detail/CVE-2026-88774 (opens in new tab)
https://nvd.nist.gov/vuln/detail/CVE-2026-88775 (opens in new tab)
https://nvd.nist.gov/vuln/detail/CVE-2026-88776 (opens in new tab)
https://nvd.nist.gov/vuln/detail/CVE-2026-88777 (opens in new tab)
https://nvd.nist.gov/vuln/detail/CVE-2026-88778 (opens in new tab)
