Blog | Security September 27, 2026

Eight New NetScaler Vulnerabilities, Two Under Active Exploitation, Demand Immediate Action

Eight New NetScaler Vulnerabilities, Two Under Active Exploitation, Demand Immediate Action

Citrix has disclosed eight new vulnerabilities impacting NetScaler Application Delivery Controller (ADC) and Gateway appliances, published under Citrix article CTX697096 and rated Critical. Two of the eight, CVE-2026-88771 and CVE-2026-88772, are already being exploited in the wild against unmitigated NetScaler deployments. Given the severity, breadth, and confirmed exploitation, this bulletin should be treated as an emergency patching event rather than routine maintenance.

As part of our ongoing Citrix expertise and customer support, the Alchemy team reviewed the vulnerabilities and what they mean in practice.

https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096

The Vulnerabilities

CVE-2026-88771 (CVSS 9.5) Actively Exploited

A remote code execution vulnerability caused by improper input validation. It affects all NetScaler ADC and NetScaler Gateway deployments in their default configuration, with no additional feature required. An unauthenticated attacker can execute arbitrary commands. This is the most consequential item in the bulletin: no special configuration is needed to be exposed.

CVE-2026-88772 (CVSS 9.5) Actively Exploited

A memory overflow vulnerability leading to remote code execution or denial-of-service. It affects appliances with DTLS enabled, which is on by default on VPN virtual servers unless explicitly disabled. Given how common VPN vServers are in Gateway deployments, this has a wide blast radius.

CVE-2026-88773 (CVSS 9.3)

An HTTP request smuggling vulnerability affecting appliances with HTTP configuration enabled, including Load Balancing, Content Switching, VPN, or Authentication virtual servers of type HTTP or SSL.

CVE-2026-88774 (CVSS 7.0)

A feature policy bypass caused by improper handling of HTTP URL-based expressions. It applies to the same HTTP/SSL virtual server configurations as CVE-2026-88773.

CVE-2026-88775 (CVSS 8.8)

A memory overflow vulnerability leading to unpredictable behavior or denial-of-service, affecting appliances configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or as an AAA virtual server.

CVE-2026-88776 (CVSS 8.8)

A memory overflow vulnerability leading to unpredictable behavior or denial-of-service, affecting Load Balancing virtual servers configured with type Oracle.

CVE-2026-88777 (CVSS 8.8)

A memory overflow vulnerability affecting LB/CS or CGNAT-LSN/NAT64 deployments with a non-HTTP Layer 7 protocol feature enabled, such as FTP, RTSP, DNS64, or NAT64.

CVE-2026-88778 (CVSS 8.8)

A TCP Initial Sequence Number prediction vulnerability affecting appliances with TCP-type virtual servers where Enhanced ISN Generation is disabled.

Cloud Software Group has confirmed exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments. The remaining six CVEs have no confirmed exploitation reported as of this writing, but given how quickly attention concentrates on NetScaler once a bulletin like this drops, all eight should be assessed and closed out together.

What Alchemy Recommends

1. Confirm your current NetScaler version

If you're running builds before the following, your systems are at risk:

  • NetScaler ADC and NetScaler Gateway 14.1 BEFORE 14.1-73.37
  • NetScaler ADC and NetScaler Gateway 13.1 BEFORE 13.1-64.23
  • NetScaler ADC FIPS BEFORE 14.1-73.37 FIPS
  • NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.279

Note: The vulnerabilities also affect Secure Private Access Hybrid deployments using NetScaler instances. Customers must upgrade these NetScaler instances to the recommended builds to address the vulnerabilities.

This bulletin only applies to customer-managed NetScaler ADC and NetScaler Gateway. Cloud Software Group has already patched the Citrix-managed cloud services and Adaptive Authentication platforms, so no action is needed there.

2. Identify which of the eight CVEs actually apply to you

CVE-2026-88771 applies to every NetScaler ADC and Gateway deployment by default, no configuration check needed. Exposure to the remaining seven depends on how each appliance is configured. Customers can check their NetScaler configuration for the following strings to determine applicability:

CVE-2026-88772: DTLS enabled (default on VPN vServers unless explicitly disabled)

add vpn vserver .* SSL .*        # DTLS on by default unless -dtls OFF is set
add vpn vserver .* DTLS .*
add lb vserver .* DTLS .*

CVE-2026-88773 and CVE-2026-88774: HTTP or SSL virtual servers configured

add lb vserver <name> <HTTP or SSL>
add cs vserver <name> <HTTP or SSL>
add vpn vserver <name> <HTTP or SSL>
add authentication vserver <name> <HTTP or SSL>

CVE-2026-88775: Gateway or AAA virtual server

add vpn vserver .*
add authentication vserver .*

CVE-2026-88776: Load Balancing virtual server of type Oracle

add lb vserver.*ORACLE.*

CVE-2026-88777: Non-HTTP L7 features on LB/CS or CGNAT-LSN/NAT64 (FTP, RTSP, DNS64, NAT64)

add (lb|cs) vserver .* FTP
add service .* FTP
add lsn group .*                 # FTP ALG enabled by default unless "-ftp DISABLED" is also present
add lb monitor .* FTP
add lb monitor .* FTP-EXTENDED
set lsn group .* -rtspalg ENABLED
add lb vserver .* DNS .* -dns64 ENABLED
add dns policy64
add nat64

CVE-2026-88778: TCP-type virtual server with Enhanced ISN Generation disabled

show ns tcpparam | grep "Enhanced ISN Generation"

If this returns DISABLED and any TCP-family virtual server type is configured, treat the appliance as exposed.

If any of these strings return matches in your running configuration, treat that CVE as applicable to your environment and prioritize patching accordingly.

3. Restrict exposure while you plan the upgrade

Given that CVE-2026-88771 requires no special configuration and CVE-2026-88772 is exposed on most default VPN vServer setups, and both are already being actively exploited, appliances that cannot be patched immediately should have management interface and, where feasible, data-plane access restricted to trusted networks until the upgrade is complete. For CVE-2026-88778, apply the documented TCP configuration change to enable Enhanced ISN Generation as an immediate compensating control.

4. Patch on an emergency basis

Given confirmed in-the-wild exploitation of two unauthenticated, network-reachable vulnerabilities, one of which requires zero special configuration, Alchemy recommends treating this bulletin as an emergency patch across all customer-managed NetScaler ADC and Gateway appliances, not just those matching the higher-severity preconditions.

How Alchemy Can Help

If you're unsure whether your NetScaler environment is affected, or need help planning and executing the upgrade, Alchemy's NetScaler Health Check service can assess your current configuration, confirm exposure to all eight CVEs in this bulletin, and guide you through remediation with minimal disruption to production traffic.


Author

John Chaisson avatar John Chaisson
Share

More Articles

Insights
Sep 24, 2026

What We Took Away from Glean:Go 2026

Author avatar Andy Quirin avatar Chris Hogan and Andy Quirin
Awards
Sep 22, 2026

Alchemy Technology Group Named Okta’s 2026 AMER Partner of the Year

Author avatar Alchemy
Insights
Sep 16, 2026

Top 10 Tips and Tricks for a Successful Glean Deployment