Skip to content

Citrix NetScaler ADC/Gateway

exploitbulletin.com • September 29, 2026

Unauthenticated memory-corruption RCE in Citrix NetScaler ADC and Gateway (CVE-2026-88772)

Citrix shipped fixes in CTX697096 on 2026-09-27 and CISA added CVE-2026-88771 and CVE-2026-88772 to KEV the same day with a 2026-09-30 remediation deadline after confirming attacks on unpatched appliances, so a team that leaves an internet-facing NetScaler on a vulnerable build is exposed to compromise of its remote-access gateway.

An improper restriction of operations within the bounds of a memory buffer in NetScaler ADC and NetScaler Gateway lets a remote, unauthenticated attacker execute code on the appliance or crash it. Citrix fixed it in bulletin CTX697096 alongside a second exploited zero-day, CVE-2026-88771 (improper input validation), and six further issues.

Affected: Citrix NetScaler ADC < 14.1-73.37; Citrix NetScaler ADC < 13.1-64.23; Citrix NetScaler ADC < 14.1-73.37 FIPS; Citrix NetScaler ADC < 13.1-37.279 FIPS and NDcPP; Citrix NetScaler Gateway < 14.1-73.37; Citrix NetScaler Gateway < 13.1-64.23

Check the running NetScaler build on every ADC and Gateway appliance (including FIPS/NDcPP builds) against the fixed releases 14.1-73.37, 13.1-64.23 and 13.1-37.279 FIPS/NDcPP; anything older is vulnerable. Because exploitation preceded the patch, treat exposed appliances as potentially compromised: follow Citrix's CTX694799 'Steps to Take if NetScaler ADC is Suspected to be Compromised' and CISA's Forensics Triage Requirements referenced in the KEV entry, review appliance logs for unexpected crashes or restarts and unfamiliar files or accounts, and rotate credentials and sessions terminated through the gateway if anything looks off.

Upgrade NetScaler ADC and NetScaler Gateway to 14.1-73.37 or later, 13.1-64.23 or later, 14.1-73.37 FIPS, or 13.1-37.279 FIPS/NDcPP per CTX697096. If an upgrade cannot happen immediately, CISA's required action is to discontinue use of the product, i.e. take the appliance offline or remove its internet exposure until it is patched.