Site icon Windows Mode

NetScaler administrators urged to patch critical zero-day vulnerabilities in ADC and Gateway immediately

Citrix HQ 16z9

Netscaler administrators urged to patch critical zero day vulnerabilities in adc.jpg from NetScaler administrators urged to patch critical zero-day vulnerabilities in ADC and Gateway immediately

Key Points

What is changing

Two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, allow attackers to execute arbitrary code remotely without authentication. CVE-2026-88771 stems from improper input validation in ADC and Gateway, while CVE-2026-88772 involves a memory overflow requiring DTLS, which is enabled by default on VPN virtual servers. Both flaws have CVSS scores of 9.5 and are actively exploited in the wild.

Additionally, Citrix patched six other vulnerabilities, including CVE-2026-88773 (HTTP request smuggling) and CVE-2026-88778 (TCP sequence-number prediction). Most impact depends on configurations, though all ADC and Gateway deployments are advised to update immediately. Fixes are available in the specified versions.

Why it matters

This matters most to network engineers and system administrators managing NetScaler ADC and Gateway appliances. Attackers could exploit these flaws to gain high-privilege access, install backdoors, extract credentials, or pivot to critical systems like Active Directory. A breach could lead to persistent compromise or data exfiltration.

The impact is major, as no configuration changes are needed to exploit the flaws. CISA’s inclusion in the KEV catalog underscores urgency—organizations should patch immediately and consider taking affected systems offline. Share your patch deployment timelines in the comments.

Read the original source.

Exit mobile version