Eight New NetScaler Vulnerabilities, Two Under Active Exploitation, Demand Immediate Action
Citrix has disclosed eight new vulnerabilities impacting NetScaler Application Delivery Controller (ADC) and Gateway appliances, published under Citrix article CTX697096 and rated Critical. Two of the eight, CVE-2026-88771 and CVE-2026-88772, are already being exploited in the wild against unmitigated NetScaler deployments. Given the severity, breadth, and confirmed exploitation, this bulletin should be treated as an emergency patching event rather than routine maintenance.
As part of our ongoing Citrix expertise and customer support, the Alchemy team reviewed the vulnerabilities and what they mean in practice.
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096
The Vulnerabilities
CVE-2026-88771 (CVSS 9.5) Actively Exploited
A remote code execution vulnerability caused by improper input validation. It affects all NetScaler ADC and NetScaler Gateway deployments in their default configuration, with no additional feature required. An unauthenticated attacker can execute arbitrary commands. This is the most consequential item in the bulletin: no special configuration is needed to be exposed.
CVE-2026-88772 (CVSS 9.5) Actively Exploited
A memory overflow vulnerability leading to remote code execution or denial-of-service. It affects appliances with DTLS enabled, which is on by default on VPN virtual servers unless explicitly disabled. Given how common VPN vServers are in Gateway deployments, this has a wide blast radius.
CVE-2026-88773 (CVSS 9.3)
An HTTP request smuggling vulnerability affecting appliances with HTTP configuration enabled, including Load Balancing, Content Switching, VPN, or Authentication virtual servers of type HTTP or SSL.
CVE-2026-88774 (CVSS 7.0)
A feature policy bypass caused by improper handling of HTTP URL-based expressions. It applies to the same HTTP/SSL virtual server configurations as CVE-2026-88773.
CVE-2026-88775 (CVSS 8.8)
A memory overflow vulnerability leading to unpredictable behavior or denial-of-service, affecting appliances configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or as an AAA virtual server.
CVE-2026-88776 (CVSS 8.8)
A memory overflow vulnerability leading to unpredictable behavior or denial-of-service, affecting Load Balancing virtual servers configured with type Oracle.
CVE-2026-88777 (CVSS 8.8)
A memory overflow vulnerability affecting LB/CS or CGNAT-LSN/NAT64 deployments with a non-HTTP Layer 7 protocol feature enabled, such as FTP, RTSP, DNS64, or NAT64.
CVE-2026-88778 (CVSS 8.8)
A TCP Initial Sequence Number prediction vulnerability affecting appliances with TCP-type virtual servers where Enhanced ISN Generation is disabled.
Cloud Software Group has confirmed exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments. The remaining six CVEs have no confirmed exploitation reported as of this writing, but given how quickly attention concentrates on NetScaler once a bulletin like this drops, all eight should be assessed and closed out together.
What Alchemy Recommends
1. Confirm your current NetScaler version
If you're running builds before the following, your systems are at risk:
- NetScaler ADC and NetScaler Gateway 14.1 BEFORE 14.1-73.37
- NetScaler ADC and NetScaler Gateway 13.1 BEFORE 13.1-64.23
- NetScaler ADC FIPS BEFORE 14.1-73.37 FIPS
- NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.279
Note: The vulnerabilities also affect Secure Private Access Hybrid deployments using NetScaler instances. Customers must upgrade these NetScaler instances to the recommended builds to address the vulnerabilities.
This bulletin only applies to customer-managed NetScaler ADC and NetScaler Gateway. Cloud Software Group has already patched the Citrix-managed cloud services and Adaptive Authentication platforms, so no action is needed there.
2. Identify which of the eight CVEs actually apply to you
CVE-2026-88771 applies to every NetScaler ADC and Gateway deployment by default, no configuration check needed. Exposure to the remaining seven depends on how each appliance is configured. Customers can check their NetScaler configuration for the following strings to determine applicability:
CVE-2026-88772: DTLS enabled (default on VPN vServers unless explicitly disabled)
add vpn vserver .* SSL .* # DTLS on by default unless -dtls OFF is set
add vpn vserver .* DTLS .*
add lb vserver .* DTLS .*CVE-2026-88773 and CVE-2026-88774: HTTP or SSL virtual servers configured
add lb vserver <name> <HTTP or SSL>
add cs vserver <name> <HTTP or SSL>
add vpn vserver <name> <HTTP or SSL>
add authentication vserver <name> <HTTP or SSL>CVE-2026-88775: Gateway or AAA virtual server
add vpn vserver .*
add authentication vserver .*CVE-2026-88776: Load Balancing virtual server of type Oracle
add lb vserver.*ORACLE.*CVE-2026-88777: Non-HTTP L7 features on LB/CS or CGNAT-LSN/NAT64 (FTP, RTSP, DNS64, NAT64)
add (lb|cs) vserver .* FTP
add service .* FTP
add lsn group .* # FTP ALG enabled by default unless "-ftp DISABLED" is also present
add lb monitor .* FTP
add lb monitor .* FTP-EXTENDED
set lsn group .* -rtspalg ENABLED
add lb vserver .* DNS .* -dns64 ENABLED
add dns policy64
add nat64CVE-2026-88778: TCP-type virtual server with Enhanced ISN Generation disabled
show ns tcpparam | grep "Enhanced ISN Generation"If this returns DISABLED and any TCP-family virtual server type is configured, treat the appliance as exposed.
If any of these strings return matches in your running configuration, treat that CVE as applicable to your environment and prioritize patching accordingly.
3. Restrict exposure while you plan the upgrade
Given that CVE-2026-88771 requires no special configuration and CVE-2026-88772 is exposed on most default VPN vServer setups, and both are already being actively exploited, appliances that cannot be patched immediately should have management interface and, where feasible, data-plane access restricted to trusted networks until the upgrade is complete. For CVE-2026-88778, apply the documented TCP configuration change to enable Enhanced ISN Generation as an immediate compensating control.
4. Patch on an emergency basis
Given confirmed in-the-wild exploitation of two unauthenticated, network-reachable vulnerabilities, one of which requires zero special configuration, Alchemy recommends treating this bulletin as an emergency patch across all customer-managed NetScaler ADC and Gateway appliances, not just those matching the higher-severity preconditions.
How Alchemy Can Help
If you're unsure whether your NetScaler environment is affected, or need help planning and executing the upgrade, Alchemy's NetScaler Health Check service can assess your current configuration, confirm exposure to all eight CVEs in this bulletin, and guide you through remediation with minimal disruption to production traffic.
Author