Multiple Vulnerabilities in NetScaler ADC and NetScaler Gateway Could Allow for Remote Code Execution

MS-ISACEI-ISAC

MS-ISAC ADVISORY NUMBER:

2026-103

DATE(S) ISSUED:

09/21/2026

OVERVIEW:

Multiple vulnerabilities have been discovered in NetScaler ADC and NetScaler Gateway, the most severe of which could allow for remote code execution. NetScaler ADC is a networking product that functions as an Application Delivery Controller (ADC), optimizing, securing, and ensuring reliable availability of applications for businesses. NetScaler Gateway is a secure remote access solution that provides users with single sign-on (SSO) access to applications and resources from any device. Successful exploitation of the most severe of these vulnerabilities could allow for remote code execution of commands on the system.

THREAT INTELLIGENCE:

There are reports of CVE-2026-88771 and CVE-2026-88772 being actively exploited in the wild.

SYSTEMS AFFECTED:

  • NetScaler ADC and NetScaler Gateway 14.1 versions prior to 14.1-73.37
  • NetScaler ADC and NetScaler Gateway 13.1 versions prior to 13.1-64.23
  • NetScaler ADC FIPS versions prior to 14.1-73.37 FIPS
  • NetScaler ADC FIPS and NDcPP versions prior to 13.1-37.279 FIPS and NDcPP

RISK:

Government:
Large and medium government entitiesHIGH
Small governmentMEDIUM
Businesses:
Large and medium business entitiesHIGH
Small business entitiesN/A
Home Users:
N/A

TECHNICAL SUMMARY:

Multiple vulnerabilities have been discovered in NetScaler ADC and NetScaler Gateway, the most severe of which could allow for remote code execution. Details of the vulnerabilities are as follows:

Tactic: Initial Access (TA0001):

Technique: Exploit Public-Facing Application (T1190):

 

  • A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands. All NetScaler ADC and NetScaler Gateway deployments are affected by default, with no additional feature required. (CVE-2026-88771)
  • A memory overflow vulnerability leading to remote code execution or denial of service, affecting deployments with DTLS configuration enabled (enabled by default on VPN virtual servers). (CVE-2026-88772)
  • An HTTP request smuggling vulnerability affecting deployments with HTTP configuration enabled. (CVE-2026-88773)
  • A feature policy bypass resulting from improper handling of HTTP URL-based policy expressions. (CVE-2026-88774)
  • A memory overflow vulnerability leading to unpredictable or erroneous behavior or denial of service, affecting appliances configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or as an AAA virtual server. (CVE-2026-88775)
  • A memory overflow vulnerability leading to unpredictable or erroneous behavior or denial of service, affecting Load Balancing virtual servers of type Oracle. (CVE-2026-88776)
  • A memory overflow vulnerability leading to unpredictable or erroneous behavior or denial of service, affecting LB/CS or CGNAT-LSN/NAT64 deployments with a non-HTTP Layer 7 protocol feature enabled. (CVE-2026-88777)
  • A TCP Initial Sequence Number (ISN) prediction vulnerability affecting deployments with TCP configuration enabled. (CVE-2026-88778)
  • Successful exploitation of the most severe of these vulnerabilities could allow for remote code execution of commands on the system.

RECOMMENDATIONS:

We recommend the following actions be taken:

  • Apply appropriate updates provided by Citrix to vulnerable systems immediately after appropriate testing. (M1051: Update Software)
  • Safeguard 7.1: Establish and Maintain a Vulnerability Management Process: Establish and maintain a documented vulnerability management process for enterprise assets. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.
  • Safeguard 7.2: Establish and Maintain a Remediation Process: Establish and maintain a risk-based remediation strategy documented in a remediation process, with monthly, or more frequent, reviews.
  • Safeguard 7.4: Perform Automated Application Patch Management: Perform application updates on enterprise assets through automated patch management on a monthly, or more frequent, basis.
  • Safeguard 7.5: Perform Automated Vulnerability Scans of Internal Enterprise Assets: Perform automated vulnerability scans of internal enterprise assets on a quarterly, or more frequent, basis. Conduct both authenticated and unauthenticated scans, using a SCAP-compliant vulnerability scanning tool.
  • Safeguard 7.7: Remediate Detected Vulnerabilities: Remediate detected vulnerabilities in software through processes and tooling on a monthly, or more frequent, basis, based on the remediation process.
  • Safeguard 12.1: Ensure Network Infrastructure is Up-to-Date: Ensure network infrastructure is kept up-to-date. Example implementations include running the latest stable release of software and/or using currently supported network-as-a-service (NaaS) offerings. Review software versions monthly, or more frequently, to verify software support.

 

  • Apply the Principle of Least Privilege to all systems and services. Run all software as a non-privileged user (one without administrative privileges) to diminish the effects of a successful attack. (M1026: Privileged Account Management)
  • Safeguard 4.7: Manage Default Accounts on Enterprise Assets and Software: Manage default accounts on enterprise assets and software, such as root, administrator, and other pre-configured vendor accounts. Example implementations can include: disabling default accounts or making them unusable.
  • Safeguard 5.5: Establish and Maintain an Inventory of Service Accounts: Establish and maintain an inventory of service accounts. The inventory, at a minimum, must contain department owner, review date, and purpose. Perform service account reviews to validate that all active accounts are authorized, on a recurring schedule at a minimum quarterly, or more frequently.

 

  • Vulnerability scanning is used to find potentially exploitable software vulnerabilities to remediate them. (M1016: Vulnerability Scanning)
  • Safeguard 16.13: Conduct Application Penetration Testing: Conduct application penetration testing. For critical applications, authenticated penetration testing is better suited to finding business logic vulnerabilities than code scanning and automated security testing. Penetration testing relies on the skill of the tester to manually manipulate an application as an authenticated and unauthenticated user.

 

  • Architect sections of the network to isolate critical systems, functions, or resources. Use physical and logical segmentation to prevent access to potentially sensitive systems and information. Use a DMZ to contain any internet-facing services that should not be exposed from the internal network. (M1030: Network Segmentation)
  • Safeguard 12.2: Establish and Maintain a Secure Network Architecture: Establish and maintain a secure network architecture. A secure network architecture must address segmentation, least privilege, and availability, at a minimum.

 

  • Use capabilities to detect and block conditions that may lead to or be indicative of a software exploit occurring. (M1050: Exploit Protection)

Safeguard 10.5: Enable Anti-Exploitation Features: Enable anti-exploitation features on enterprise assets and software, where possible, such as Microsoft® Data Execution Prevention (DEP), Windows® Defender Exploit Guard (WDEG), or Apple® System Integrity Protection (SIP) and Gatekeeper™.

Get Email Updates When Cyber Threats Like This Arise

Subscribe to Advisories