Critical Citrix NetScaler Vulnerabilities Actively Exploited
In short: Citrix disclosed 8 vulnerabilities affecting customer-managed NetScaler ADC and NetScaler Gateway, including 2 critical unauthenticated RCE flaws with CVSS 9.5 that Citrix confirms are being actively exploited. CERT-EU urges immediate patching and compromise assessment for internet-facing appliances. Other flaws include HTTP request smuggling, memory overflow bugs leading to RCE/DoS, a policy bypass, and a TCP ISN prediction issue.
This summary was generated automatically by AI from CERT-EU's publication. It is our own text, not a copy of the original — facts, figures and quotes belong to the source, linked above and below.
What changed?
- 1CVE-2026-88771 (CVSS 9.5): unauthenticated RCE via improper input validation, affects all deployments, exploited in the wild
- 2CVE-2026-88772 (CVSS 9.5): memory overflow RCE/DoS, affects deployments with DTLS enabled (default on VPN vServer), exploited in the wild
- 3CVE-2026-88773 (CVSS 9.3): HTTP Request Smuggling, affects deployments with HTTP URL-based policy expressions configured
- 4CVE-2026-88774 (CVSS 7.0): feature policy bypass via HTTP URL-based expression
- 5CVE-2026-88775/88776/88777 (CVSS 8.8 each): memory overflow causing erroneous behaviour or DoS in gateway/AAA, Oracle LB, and LB/CS/CGNAT-LSN/NAT64 configurations
- 6CVE-2026-88778 (CVSS 8.8): TCP ISN prediction vulnerability where Enhanced ISN Generation is disabled
- 7Affected: NetScaler ADC/Gateway 13.1 before 13.1-64.23, 14.1 before 14.1-73.37, FIPS 14.1 before 14.1-73.37 FIPS, FIPS/NDcPP 13.1 before 13.1-37.279
- 8Fix: update to patched versions immediately; enable Enhanced ISN Generation; run compromise assessment on internet-facing appliances
Why it matters
NetScaler ADC/Gateway appliances are widely deployed as VPN and application delivery gateways; unauthenticated RCE being exploited in the wild on internet-facing systems poses an immediate, high-severity risk of full compromise.
What it means for AI agents and contact centers
If your company uses Citrix NetScaler ADC/Gateway for VPN access, load balancing, or SIP/VoIP traffic delivery, these appliances should be checked and patched immediately, as they are not part of your core stack (Asterisk/Linux/Node.js/nginx) but could be used in network perimeter infrastructure; run a compromise assessment if any such appliance is internet-facing.
Sources
- CERT-EUOfficialPrimary sourceOriginal article →„2026-014: Critical Vulnerabilities in Citrix NetScaler ADC and Gateway“Licence: CC BY 4.0 (CERT-EU legal notice; Commission Decision 2011/833/EU) · our summary (content changed)
- NCSC UKOfficialOriginal article →„Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway“28 Sept 2026, 15:00Licence: UK government publication (Open Government Licence)
- CERT-EUOfficialOriginal article →„2026-010: Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway“Licence: CC BY 4.0 (CERT-EU legal notice; Commission Decision 2011/833/EU)
- Published by source
- —
- Found by our system
- 2 Oct 2026, 22:23
- Summary generated
- 2 Oct 2026, 22:24
This article was written by AI from the original source. Facts, numbers and prices come from the source; missing values are marked “Not specified”. Legal notice, copyright and privacy