2026-014: Critical Vulnerabilities in Citrix NetScaler ADC and Gateway

Imported from official source

Advisory

Cybersecurity Classified by Officially

Critical Vulnerabilities in Citrix NetScaler ADC and Gateway

  • 27/09/2026 --- v1.0 -- Initial publication
  • On 27 September 2026, Citrix published a security bulletin addressing 8 vulnerabilities affecting customer-managed Citrix NetScaler ADC and Citrix NetScaler Gateway, among which 2 critical unauthenticated Remote Code Execution (RCE) vulnerabilities. Citrix has confirmed active exploitation of these 2 critical vulnerabilities in the wild [1].

    CERT-EU recommends updating affected software and running a compromise assessment on those exposed on the internet.

    The vulnerability CVE-2026-88771, with a CVSS score of 9.5, is an unauthenticated RCE flow due to improper input validation. As there is no precondition for the exploitation, it affects all Citrix NetScaler ADC and Citrix NetScaler Gateway deployments. It is exploited in the wild [1].

    The vulnerability CVE-2026-88772, with a CVSS score of 9.5, a memory overflow vulnerability leading to RCE or Denial of Service (DoS). It affects Citrix NetScaler ADC and Citrix NetScaler Gateway deployments where DTLS is enabled (default on VPN vServer). It is exploited in the wild [1].

    The vulnerability CVE-2026-88773, with a CVSS score of 9.3, is an HTTP Request Smuggling vulnerability. It affects Citrix NetScaler ADC and Citrix NetScaler Gateway deployments where an HTTP URL-based policy expression configured [1].

    The vulnerability CVE-2026-88774, with a CVSS score of 7.0, is a feature policy bypass via HTTP URL-based expression flow. It affects Citrix NetScaler ADC and Citrix NetScaler Gateway deployments where an HTTP URL-based policy expression configured [1].

    This is an extract. The publication continues at the source.

    Source: CERT-EU.

    Read the original at the source: https://cert.europa.eu/publications/security-advisories/2026-014/

    Officially imported this from CERT-EU’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

    Provenance

    Organization
    CERT-EU — imported from official source
    Official source
    https://www.cert.europa.eu/publications/security-advisories-rss RSS
    Imported
    September 27, 2026 18:00
    Versions
    1 recorded
    Identity
    security-advisories-10951

    Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.