Skip to content
Sunday, 4 October 2026
Tenesys AI News
Subscribe

Critical Citrix NetScaler Vulnerabilities Actively Exploited

In short: Citrix disclosed 8 vulnerabilities affecting customer-managed NetScaler ADC and NetScaler Gateway, including 2 critical unauthenticated RCE flaws with CVSS 9.5 that Citrix confirms are being actively exploited. CERT-EU urges immediate patching and compromise assessment for internet-facing appliances. Other flaws include HTTP request smuggling, memory overflow bugs leading to RCE/DoS, a policy bypass, and a TCP ISN prediction issue.

Source: CERT-EUCitrixOriginal article ↗

This summary was generated automatically by AI from CERT-EU's publication. It is our own text, not a copy of the original — facts, figures and quotes belong to the source, linked above and below.

What changed?

  • 1CVE-2026-88771 (CVSS 9.5): unauthenticated RCE via improper input validation, affects all deployments, exploited in the wild
  • 2CVE-2026-88772 (CVSS 9.5): memory overflow RCE/DoS, affects deployments with DTLS enabled (default on VPN vServer), exploited in the wild
  • 3CVE-2026-88773 (CVSS 9.3): HTTP Request Smuggling, affects deployments with HTTP URL-based policy expressions configured
  • 4CVE-2026-88774 (CVSS 7.0): feature policy bypass via HTTP URL-based expression
  • 5CVE-2026-88775/88776/88777 (CVSS 8.8 each): memory overflow causing erroneous behaviour or DoS in gateway/AAA, Oracle LB, and LB/CS/CGNAT-LSN/NAT64 configurations
  • 6CVE-2026-88778 (CVSS 8.8): TCP ISN prediction vulnerability where Enhanced ISN Generation is disabled
  • 7Affected: NetScaler ADC/Gateway 13.1 before 13.1-64.23, 14.1 before 14.1-73.37, FIPS 14.1 before 14.1-73.37 FIPS, FIPS/NDcPP 13.1 before 13.1-37.279
  • 8Fix: update to patched versions immediately; enable Enhanced ISN Generation; run compromise assessment on internet-facing appliances

Why it matters

NetScaler ADC/Gateway appliances are widely deployed as VPN and application delivery gateways; unauthenticated RCE being exploited in the wild on internet-facing systems poses an immediate, high-severity risk of full compromise.

What it means for AI agents and contact centers

If your company uses Citrix NetScaler ADC/Gateway for VPN access, load balancing, or SIP/VoIP traffic delivery, these appliances should be checked and patched immediately, as they are not part of your core stack (Asterisk/Linux/Node.js/nginx) but could be used in network perimeter infrastructure; run a compromise assessment if any such appliance is internet-facing.

Sources

  • CERT-EUOfficialPrimary source
    „2026-014: Critical Vulnerabilities in Citrix NetScaler ADC and Gateway“
    Licence: CC BY 4.0 (CERT-EU legal notice; Commission Decision 2011/833/EU) · our summary (content changed)
    Original article →
  • NCSC UKOfficial
    „Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway“
    28 Sept 2026, 15:00
    Licence: UK government publication (Open Government Licence)
    Original article →
  • CERT-EUOfficial
    „2026-010: Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway“
    Licence: CC BY 4.0 (CERT-EU legal notice; Commission Decision 2011/833/EU)
    Original article →
Published by source
—
Found by our system
2 Oct 2026, 22:23
Summary generated
2 Oct 2026, 22:24

This article was written by AI from the original source. Facts, numbers and prices come from the source; missing values are marked “Not specified”. Legal notice, copyright and privacy