Organisations running Citrix NetScaler ADC or NetScaler Gateway have a security issue that needs attention now, not during the next routine patching window.
Citrix has disclosed eight vulnerabilities affecting customer-managed NetScaler deployments. Two of them, CVE-2026-88771 and CVE-2026-88772, carry CVSS 4.0 scores of 9.5 and have already been exploited against unmitigated systems.
The US Cybersecurity and Infrastructure Security Agency (CISA) has also added both vulnerabilities to its Known Exploited Vulnerabilities catalogue following reports and threat intelligence indicating active exploitation.
For Australian businesses, the practical message is straightforward: if you operate a customer-managed NetScaler ADC or NetScaler Gateway, identify the version and configuration you are running, check for possible compromise, and install the relevant Citrix security update as a priority.
What has happened with Citrix NetScaler?
Citrix has published a security bulletin covering eight vulnerabilities affecting NetScaler ADC and NetScaler Gateway:
- CVE-2026-88771
- CVE-2026-88772
- CVE-2026-88773
- CVE-2026-88774
- CVE-2026-88775
- CVE-2026-88776
- CVE-2026-88777
- CVE-2026-88778
The vulnerabilities cover several attack paths, including remote code execution, denial of service, HTTP request smuggling, policy bypass and TCP initial sequence number prediction.
Not every vulnerability applies to every configuration. Several of the flaws require particular NetScaler features or configurations to be enabled, so administrators need to assess both the firmware version and how each appliance is configured.
There is one major exception: CVE-2026-88771.
Why CVE-2026-88771 is particularly serious
CVE-2026-88771 is an improper input validation vulnerability that can allow an unauthenticated attacker to execute arbitrary commands. Citrix gives it a CVSS 4.0 base score of 9.5.
More importantly, Citrix says the vulnerability affects all NetScaler ADC and NetScaler Gateway deployments, including default configurations. No additional feature needs to be enabled for an appliance to meet the vulnerability’s preconditions.
That removes one of the usual qualifiers administrators look for when assessing a security advisory. You cannot assume an appliance is unaffected simply because you do not use a particular NetScaler feature.
Citrix has confirmed exploitation of CVE-2026-88771 on unmitigated deployments. CISA has also added the vulnerability to its Known Exploited Vulnerabilities catalogue.
CVE-2026-88772 is also being actively exploited
The second critical vulnerability, CVE-2026-88772, is a memory overflow issue that can lead to remote code execution or denial of service. It also carries a CVSS 4.0 score of 9.5.
This vulnerability does have a configuration requirement. DTLS must be enabled on the affected NetScaler ADC or Gateway.
The problem is that DTLS is enabled by default on a VPN virtual server unless it has been explicitly disabled. Organisations using NetScaler Gateway for remote access therefore should not assume this condition is unusual.
Citrix has observed exploitation of CVE-2026-88772 on unmitigated systems, and CISA has also placed it in the Known Exploited Vulnerabilities catalogue.
What are the other six NetScaler vulnerabilities?
The remaining vulnerabilities are also significant, although their exposure depends more heavily on configuration.
| Vulnerability | Issue | CVSS 4.0 |
|---|---|---|
| CVE-2026-88771 | Unauthenticated remote code execution | 9.5 |
| CVE-2026-88772 | Memory overflow resulting in remote code execution or denial of service | 9.5 |
| CVE-2026-88773 | HTTP request smuggling | 9.3 |
| CVE-2026-88774 | Feature policy bypass involving HTTP URL-based expressions | 7.0 |
| CVE-2026-88775 | Memory overflow and denial of service | 8.8 |
| CVE-2026-88776 | Memory overflow affecting certain Oracle load balancing configurations | 8.8 |
| CVE-2026-88777 | Memory overflow affecting certain non-HTTP Layer 7 configurations | 8.8 |
| CVE-2026-88778 | TCP initial sequence number prediction | 8.8 |
The practical mistake would be to look only at the two vulnerabilities known to be exploited and ignore the other six. The Citrix update addresses a broader collection of weaknesses, and administrators should assess their appliances against the complete security bulletin.
Which Citrix NetScaler versions need to be updated?
Citrix identifies the following supported versions as affected:
- NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
- NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
- NetScaler ADC FIPS 14.1 before 14.1-73.37 FIPS
- NetScaler ADC FIPS and NDcPP 13.1 before 13.1-37.279
Citrix recommends moving affected appliances to the corresponding fixed release or a later supported release.
That means organisations should be targeting 14.1-73.37 or later, 13.1-64.23 or later, or the corresponding updated FIPS and NDcPP builds where applicable.
Secure Private Access Hybrid deployments using NetScaler instances are also affected and need the relevant NetScaler instances upgraded.
Citrix says its managed cloud services and Citrix-managed Adaptive Authentication are being updated by Cloud Software Group. The security bulletin specifically concerns customer-managed NetScaler ADC and NetScaler Gateway appliances.
Do not treat this as a patch-only exercise
There is an important operational point here. Installing the fixed firmware addresses the vulnerability going forward, but it does not tell you whether an attacker accessed the appliance before it was patched.
That matters because exploitation has already been observed.
CISA recommends checking for indications of compromise before updating where possible. If compromise is suspected, organisations should preserve forensic evidence before applying updates because the update process may remove information that would otherwise help an investigation.
For an internet-facing security appliance, that distinction is significant. A team can successfully patch a vulnerable system and still miss evidence that the environment was already compromised.
What Australian businesses should do now
If your organisation uses NetScaler ADC or NetScaler Gateway, the response should start with confirming exactly what you have rather than assuming somebody else has patched it.
- Identify every NetScaler instance. Include production, disaster recovery, secondary sites, remote access gateways and appliances managed by third parties.
- Check the installed version. Compare each appliance with the affected and fixed versions published by Citrix.
- Assess the configuration. Several CVEs depend on features such as DTLS, HTTP virtual servers, Gateway or AAA configurations, Oracle load balancing, NAT64 and other services.
- Check for indicators of compromise. This is particularly important for internet-exposed appliances and systems that remained vulnerable after the disclosure.
- Preserve evidence if compromise is suspected. Do this before upgrading where appropriate so potentially useful forensic information is not lost.
- Install the relevant Citrix update. Do not leave an affected internet-facing appliance waiting for a normal monthly maintenance cycle simply because it is currently functioning normally.
- Review monitoring after the update. Watch authentication activity, system logs, network activity and other security telemetry for behaviour that could indicate earlier compromise.
If an MSP manages your NetScaler, verify the work
Businesses that outsource infrastructure management still need confirmation that affected appliances have been assessed.
A useful question is not simply, “Are we patched?”
Ask which NetScaler instances were identified, which versions they were running, whether they met the preconditions for the individual vulnerabilities, whether compromise checks were performed, what version is installed now and whether anything suspicious was found.
This is particularly relevant for appliances sitting at the network edge. NetScaler Gateway can provide remote access into business systems, so a compromised device can have consequences beyond the appliance itself.
Why edge devices keep demanding attention
Firewalls, VPN gateways, application delivery controllers and similar edge devices have an awkward security role. They exist specifically to accept network traffic and often provide a bridge between the public internet and valuable internal resources.
That makes vulnerabilities in these systems attractive to attackers.
It also explains why vulnerability management cannot stop at Windows PCs and servers. Network appliances need an accurate inventory, current firmware, centralised logging and somebody responsible for reviewing vendor security advisories.
One problem we commonly see in business IT environments is much better visibility over endpoints than network appliances. A firewall or gateway was installed years ago, it still works, and over time it quietly becomes part of the furniture.
That is exactly the sort of device that can be overlooked when a critical security update appears.
What if you do not know whether your business uses NetScaler?
Ask whoever manages your network infrastructure or remote access environment.
For businesses with outsourced IT, your managed service provider should be able to confirm whether NetScaler is present and whether any affected customer-managed instances exist.
If nobody can provide a clear inventory of your internet-facing infrastructure, that is a separate security issue worth fixing. Responding quickly to a critical vulnerability becomes much harder when the first task is working out what equipment the business owns.
For Melbourne businesses that need help assessing vulnerable infrastructure, Accel IT can assist with identifying affected systems, reviewing patch status and determining the appropriate next steps. If you are unsure whether your organisation has an affected NetScaler deployment, establishing exactly what is deployed is the right place to start.
Frequently asked questions
Are the new Citrix NetScaler vulnerabilities being actively exploited?
Yes. Citrix has observed exploitation of CVE-2026-88771 and CVE-2026-88772 against unmitigated NetScaler deployments. CISA has added both vulnerabilities to its Known Exploited Vulnerabilities catalogue.
What is CVE-2026-88771?
CVE-2026-88771 is a critical improper input validation vulnerability in NetScaler ADC and NetScaler Gateway that can allow an unauthenticated attacker to execute arbitrary commands. Citrix assigns it a CVSS 4.0 score of 9.5 and says all deployments meet the vulnerability’s precondition.
What is CVE-2026-88772?
CVE-2026-88772 is a critical memory overflow vulnerability that can result in remote code execution or denial of service. It affects deployments where DTLS is enabled, including NetScaler Gateway VPN virtual servers where DTLS has not been explicitly disabled.
Which NetScaler version fixes these vulnerabilities?
Citrix recommends NetScaler ADC and Gateway 14.1-73.37 or later, or 13.1-64.23 or later. Corresponding updated FIPS and NDcPP builds are also available. Administrators should check the current Citrix security bulletin before upgrading.
Should affected NetScaler appliances be patched immediately?
Affected organisations should prioritise the update because active exploitation has been confirmed. Where compromise is suspected, organisations should also consider preserving forensic evidence and checking for indicators of compromise before applying updates where appropriate.
Does patching prove the appliance was not compromised?
No. Patching fixes the vulnerable software but does not establish whether exploitation occurred beforehand. Organisations with exposed vulnerable appliances should consider a compromise assessment and review available logs and security telemetry.
Are Citrix-managed cloud services affected?
Citrix’s bulletin applies to customer-managed NetScaler ADC and NetScaler Gateway. Cloud Software Group states that it upgrades Citrix-managed cloud services and Citrix-managed Adaptive Authentication with the necessary software updates.
