Multiple vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway products

This section contains time sensitive announcements about specific cyber threats, vulnerabilities and scams. Each alert has information you need to be aware of, and what actions to take to mitigate any risk to you or your organisation.

Subscribe to our updates to be notified as soon as we publish an alert.

1:50PM, 28 September 2026

TLP Rating: Clear

Multiple vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway products

The NCSC is aware of multiple vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway. At least two of the identified vulnerabilities are under active exploitation.

  • CVE-2026-88771 (CVSS: 9.5): Unauthenticated remote code execution via improper input validation.
  • CVE-2026-88772 (CVSS: 9.5): Memory overflow vulnerability enabling remote code execution or denial of service.
  • CVE-2026-88773 (CVSS: 9.3): HTTP request smuggling vulnerability.
  • CVE-2026-88774 (CVSS: 7.0): Feature policy bypass vulnerability.
  • CVE-2026-88775, CVE-2026-88776, CVE-2026-88777 (CVSS: 8.8): Memory overflow vulnerability causing denial of service.
  • CVE-2026-88778 (CVSS: 8.8): TCP sequence number prediction vulnerability.

Citrix has provided additional patching advice for selected vulnerabilities and steps for users to determine if they are running a vulnerable instance in their advisory.

The NCSC encourages organisations in New Zealand that use the affected products to review the advisory External Link and apply the remediation as soon as possible. We also urge affected organisations to investigate unauthorised access or compromise of the affected products.

What's happening

Systems affected

The following supported versions of customer-managed Citrix NetScaler ADC and Citrix NetScaler Gateway are affected by the vulnerabilities:

  • Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 BEFORE 14.1-73.37
  • Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 BEFORE 13.1-64.23
  • Citrix NetScaler ADC FIPS BEFORE 14.1-73.37 FIPS
  • Citrix NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.279

What this means

Successful exploitation of the identified vulnerabilities could allow an attacker to achieve outcomes ranging from denial of service and security control bypass through to remote code execution. Citrix has reported that exploitation of CVE-2026-88771 and CVE-2026-88772 has been observed in the wild. Organisations using the listed Citrix products should verify their versions and refer to the vendor advisory for further guidance.

What to look for

How to tell if you're at risk

If you are running a Citrix NetScaler within the version range listed above.

How to tell if you're affected

Refer to the ‘Steps to determine if an appliance meets the CVE preconditions’ section in the vendor advisory. External Link

What to do

Prevention

To prevent exploitation, the affected Citrix products need to be upgraded to the latest versions per the vendor advisory alongside any custom configurations listed in the advisory for selected CVEs.

More information

Read more about this alert on the vendor website:

CITRIX | Support External Link

If you require more information or further support, submit a report on our website:

Report an incident External Link External Link