Full Report
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Sunday added two critical Citrix NetScaler ADC and Gateway flaws to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerabilities are listed below - CVE-2026-88771 (CVSS score: 9.5) - An improper input validation vulnerability that could allow an unauthenticated attacker to
Analysis Summary
# Vulnerability: Critical Remote Code Execution in Citrix NetScaler ADC and Gateway
## CVE Details
- **CVE ID:** CVE-2026-88771, CVE-2026-88772
- **CVSS Score:** 9.5 (Critical) for both
- **CWE:**
- CVE-2026-88771: CWE-20 (Improper Input Validation)
- CVE-2026-88772: CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer)
## Affected Systems
- **Products:**
- Citrix NetScaler ADC
- Citrix NetScaler Gateway
- **Versions:**
- Versions prior to 14.1-73.37
- Versions prior to 13.1-64.23
- Citrix NetScaler ADC 14.1-FIPS (prior to 14.1-73.37 FIPS)
- Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP (prior to 13.1.37.279)
- **Configurations:**
- **CVE-2026-88771:** Affects all deployments.
- **CVE-2026-88772:** Requires DTLS configuration to be enabled (Note: DTLS is enabled by default on VPN virtual servers).
## Vulnerability Description
- **CVE-2026-88771:** A flaw in input validation that allows an unauthenticated remote attacker to execute arbitrary commands on the target system.
- **CVE-2026-88772:** A memory buffer vulnerability (buffer overflow/over-read) that allows an unauthenticated attacker to achieve remote code execution (RCE) or trigger a Denial-of-Service (DoS) state.
## Exploitation
- **Status:** Exploited in the wild (Confirmed by CISA and threat intelligence partners).
- **Complexity:** Low
- **Attack Vector:** Network
## Impact
- **Confidentiality:** Critical (Full system access/command execution)
- **Integrity:** Critical (Modification of system files/configurations)
- **Availability:** Critical (Potential for Denial-of-Service and total system compromise)
## Remediation
### Patches
Update to the following versions or later:
- NetScaler ADC and Gateway: **14.1-73.37**
- NetScaler ADC and Gateway: **13.1-64.23**
- NetScaler ADC 14.1-FIPS: **14.1-73.37 FIPS**
- NetScaler ADC 13.1-FIPS/NDcPP: **13.1.37.279**
### Workarounds
No specific configuration workarounds were provided in the source; however, for **CVE-2026-88772**, disabling DTLS on VPN virtual servers may mitigate that specific vector, though patching remains the only comprehensive solution.
## Detection
- **Indicators of Compromise:** Generic IoCs are available through the **NetScaler Console**.
- **Incident Response:** If compromise is suspected:
1. Isolate the device and preserve the VPX instance for forensics.
2. Revoke all credentials and rotate local account passwords/Key Encryption Keys (KEK).
3. Rebuild the device and update to the latest firmware.
4. Replace all SSL certificates if restoring from backups.
## References
- CISA KEV Catalog: hxxps[://]www.cisa.gov/known-exploited-vulnerabilities-catalog
- Citrix Security Bulletin: hxxps[://]support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096
- Incident Response Steps: hxxps[://]support.citrix.com/external/article/CTX694799/steps-to-take-if-netscaler-adc-is-suspec.html
- Citrix Technical Blog: hxxps[://]community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778