Full Report
Citrix security advisory (AV26-965)
Analysis Summary
# Vulnerability: Multiple Vulnerabilities in Citrix NetScaler ADC and Gateway (AV26-965)
## CVE Details
- **CVE ID:** CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, CVE-2026-88778.
- **CVSS Score:** Critical/High (Specific scores vary by CVE; CVE-2026-88771/772 are prioritized due to active exploitation).
- **CWE:** Varies (Includes Unauthenticated Remote Code Execution and Authentication Bypass).
## Affected Systems
- **Products:** NetScaler ADC and NetScaler Gateway (formerly Citrix Gateway/ADC).
- **Versions:**
- NetScaler ADC and NetScaler Gateway 14.1 prior to 14.1-73.37.
- NetScaler ADC and NetScaler Gateway 13.1 prior to 13.1-63.23.
- NetScaler ADC FIPS prior to 14.1-73.37 FIPS.
- NetScaler ADC FIPS and NDcPP prior to 13.1-37.279.
- **Configurations:** Systems configured as VPN (Gateway) or Load Balancers with specific management interfaces exposed.
## Vulnerability Description
This advisory covers a cluster of eight vulnerabilities. The most critical flaws (CVE-2026-88771 and CVE-2026-88772) allow for unauthenticated remote code execution (RCE) and sensitive data disclosure. These flaws typically stem from improper handling of specific HTTP requests or memory management errors within the NetScaler packet processing engine.
## Exploitation
- **Status:** **Exploited in the wild.** CISA has added CVE-2026-88771 and CVE-2026-88772 to the Known Exploited Vulnerabilities (KEV) Catalog.
- **Complexity:** Low to Medium.
- **Attack Vector:** Network (Remote).
## Impact
- **Confidentiality:** High (Potential theft of session tokens, credentials, and configuration data).
- **Integrity:** High (Ability to modify system files or intercept traffic).
- **Availability:** High (Potential for system crashes or complete takeover).
## Remediation
### Patches
Citrix recommends upgrading to the following versions or higher:
- **NetScaler ADC / Gateway 14.1:** Upgrade to 14.1-73.37.
- **NetScaler ADC / Gateway 13.1:** Upgrade to 13.1-63.23.
- **NetScaler ADC FIPS:** Upgrade to 14.1-73.37 FIPS.
- **NetScaler ADC FIPS and NDcPP:** Upgrade to 13.1-37.279.
### Workarounds
- Restrict access to the management interface (NSIP) using ACLs or by placing it on a non-routable internal network.
- Disable unnecessary features if not in active use.
- *Note: Patches are the only definitive resolution for these flaws.*
## Detection
- **Indicators of compromise:** Monitor for unusual outbound traffic from the NetScaler management IP, unexpected shell execution in system logs, or unauthorized modifications to `/netscaler/` directory files.
- **Detection methods and tools:** Utilize Citrix's built-in logging and export logs to a SIEM for analysis of suspicious HTTP request patterns targeting the gateway.
## References
- **Vendor Advisory:** hxxps[://]support[.]citrix[.]com/article/CTX697096
- **CISA KEV Catalog:** hxxps[://]www[.]cisa[.]gov/known-exploited-vulnerabilities-catalog
- **Cyber Centre Bulletin:** hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/citrix-security-advisory-av26-965