1:50PM, 28 September 2026
TLP Rating:
Multiple vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway products
The NCSC is aware of multiple vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway. At least two of the identified vulnerabilities are under active exploitation.
- CVE-2026-88771 (CVSS: 9.5): Unauthenticated remote code execution via improper input validation.
- CVE-2026-88772 (CVSS: 9.5): Memory overflow vulnerability enabling remote code execution or denial of service.
- CVE-2026-88773 (CVSS: 9.3): HTTP request smuggling vulnerability.
- CVE-2026-88774 (CVSS: 7.0): Feature policy bypass vulnerability.
- CVE-2026-88775, CVE-2026-88776, CVE-2026-88777 (CVSS: 8.8): Memory overflow vulnerability causing denial of service.
- CVE-2026-88778 (CVSS: 8.8): TCP sequence number prediction vulnerability.
Citrix has provided additional patching advice for selected vulnerabilities and steps for users to determine if they are running a vulnerable instance in their advisory.
The NCSC encourages organisations in New Zealand that use the affected products to review the advisory External Link and apply the remediation as soon as possible. We also urge affected organisations to investigate unauthorised access or compromise of the affected products.
What's happening
Systems affected
The following supported versions of customer-managed Citrix NetScaler ADC and Citrix NetScaler Gateway are affected by the vulnerabilities:
- Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 BEFORE 14.1-73.37
- Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 BEFORE 13.1-64.23
- Citrix NetScaler ADC FIPS BEFORE 14.1-73.37 FIPS
- Citrix NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.279
What this means
Successful exploitation of the identified vulnerabilities could allow an attacker to achieve outcomes ranging from denial of service and security control bypass through to remote code execution. Citrix has reported that exploitation of CVE-2026-88771 and CVE-2026-88772 has been observed in the wild. Organisations using the listed Citrix products should verify their versions and refer to the vendor advisory for further guidance.
What to look for
How to tell if you're at risk
If you are running a Citrix NetScaler within the version range listed above.
How to tell if you're affected
Refer to the ‘Steps to determine if an appliance meets the CVE preconditions’ section in the vendor advisory. External Link
What to do
Prevention
To prevent exploitation, the affected Citrix products need to be upgraded to the latest versions per the vendor advisory alongside any custom configurations listed in the advisory for selected CVEs.
More information
Read more about this alert on the vendor website:
CITRIX | Support External Link
If you require more information or further support, submit a report on our website: