Key Points
- CVE-2026-88771 and CVE-2026-88772, both with CVSS scores of 9.5, enable unauthenticated remote code execution on NetScaler ADC and Gateway.
- Citrix released patches in versions 14.1-73.37 and 13.1-64.23 after confirming active exploitation of both vulnerabilities.
- All NetScaler deployments, including default configurations, are affected. CISA added these to its Known Exploited Vulnerabilities (KEV) catalog.
What is changing
Two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, allow attackers to execute arbitrary code remotely without authentication. CVE-2026-88771 stems from improper input validation in ADC and Gateway, while CVE-2026-88772 involves a memory overflow requiring DTLS, which is enabled by default on VPN virtual servers. Both flaws have CVSS scores of 9.5 and are actively exploited in the wild.
Additionally, Citrix patched six other vulnerabilities, including CVE-2026-88773 (HTTP request smuggling) and CVE-2026-88778 (TCP sequence-number prediction). Most impact depends on configurations, though all ADC and Gateway deployments are advised to update immediately. Fixes are available in the specified versions.
Why it matters
This matters most to network engineers and system administrators managing NetScaler ADC and Gateway appliances. Attackers could exploit these flaws to gain high-privilege access, install backdoors, extract credentials, or pivot to critical systems like Active Directory. A breach could lead to persistent compromise or data exfiltration.
The impact is major, as no configuration changes are needed to exploit the flaws. CISA’s inclusion in the KEV catalog underscores urgency—organizations should patch immediately and consider taking affected systems offline. Share your patch deployment timelines in the comments.
Discover more from Windows Mode
Subscribe to get the latest posts sent to your email.
Add your first comment to this post