Skip to content
Critical Vulnerabilities in Citrix NetScaler ADC and Gateway Disclosed

Critical Vulnerabilities in Citrix NetScaler ADC and Gateway Disclosed

First seen 28 Sep 2026, 18:19 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 28, 2026 at 19:12 UTC

Citrix has addressed eight vulnerabilities in its NetScaler ADC and Gateway products, with three critical CVEs identified: CVE-2026-88771, CVE-2026-88772, and CVE-2026-88773. These vulnerabilities can lead to Remote Code Execution (RCE), Denial-of-Service, and HTTP Request Smuggling. CVE-2026-88771 and CVE-2026-88772 have been confirmed to be actively exploited in the wild. All versions prior to specified updates are affected, including Citrix NetScaler ADC and Gateway 14.1 before 14.1-73.37 and 13.1 before 13.1-64.23. Citrix has released patches, and the NCSC advises immediate installation to mitigate risks. The vulnerabilities pose significant risks to organizations using these systems, as they could allow attackers to gain control over internal networks. The CVSS scores for the critical vulnerabilities are notably high, indicating severe risk to affected systems.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-27
CVE-2026-88771 and CVE-2026-88772 published
Citrix disclosed critical vulnerabilities that allow remote code execution and memory overflow, with active exploitation confirmed.
Advisories.Ncsc.Nl
2026-09-27
CVE-2026-88771 added to CISA KEV
CVE-2026-88771 was added to the CISA Known Exploited Vulnerabilities catalog due to active exploitation.
Advisories.Ncsc.Nl
2026-09-27
CVE-2026-88778 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-27
CVE-2026-88776 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-27
CVE-2026-88777 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-27
CVE-2026-88774 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-27
CVE-2026-88773 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-27
CVE-2026-88775 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-28
First public PoC for CVE-2026-88771 and CVE-2026-88772
Proof-of-concept code for the critical vulnerabilities was made publicly available, increasing the urgency for patching.
www.ncsc.nl

More articles in this cluster (2)

Following this threat?

Track CVE-2026-88771 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed