Full Report
The NCSC is urging UK organisations to promptly mitigate vulnerabilities affecting Citrix NetScaler ADC and Gateway, two of which are being actively exploited.
Analysis Summary
# Vulnerability: Multiple Critical Flaws in Citrix NetScaler ADC and Gateway
## CVE Details
* **CVE-2026-88771**: Improper Input Validation (RCE) - **Critical**
* **CVE-2026-88772**: Buffer Overflow (RCE/DoS) - **Critical**
* **CVE-2026-88773**: HTTP Request/Response Smuggling (CWE-444)
* **CVE-2026-88774**: Feature Policy Bypass (CWE-20)
* **CVE-2026-88775, CVE-2026-88776, CVE-2026-88777**: Memory Overflow (CWE-119)
* **CVE-2026-88778**: Predictable Exact Value (CWE-340)
## Affected Systems
* **Products:** Citrix NetScaler ADC and Citrix NetScaler Gateway (On-premises).
* **Versions:**
* 14.1 before 14.1-73.37
* 13.1 before 13.1-64.23
* 14.1-FIPS before 14.1-73.37 FIPS
* 13.1-FIPS/NDcPP before 13.1-37.279
* **Configurations:** Customer-managed on-premises instances.
## Vulnerability Description
This suite of vulnerabilities focuses on memory safety and input validation failures. Most notably, CVE-2026-88771 allows unauthenticated remote attackers to execute arbitrary commands by failing to properly validate input. CVE-2026-88772 involves a memory buffer overflow that can lead to either Remote Code Execution (RCE) or a system crash (DoS). Other flaws include HTTP request smuggling, which allows attackers to bypass security controls by confusing how the server interprets request boundaries.
## Exploitation
* **Status:** **Exploited in the wild** (Specifically CVE-2026-88771 and CVE-2026-88772).
* **Complexity:** Low (for primary RCE vectors).
* **Attack Vector:** Network (Remote, unauthenticated).
## Impact
* **Confidentiality:** High (Full system compromise and data exfiltration possible).
* **Integrity:** High (Arbitrary command execution and security control bypass).
* **Availability:** High (System crashes via memory overflows and DoS).
## Remediation
### Patches
Citrix recommends updating to the following versions immediately:
* NetScaler ADC and NetScaler Gateway **14.1-73.37** or later.
* NetScaler ADC and NetScaler Gateway **13.1-64.23** or later.
* NetScaler ADC FIPS **14.1-73.37 FIPS** or later.
* NetScaler ADC FIPS and NDcPP **13.1-37.279** or later.
### Workarounds
* Isolate affected systems from the public internet.
* Restricting access to the management and gateway interfaces to known-good organizational IP ranges.
* Temporarily disable vulnerable components if updates cannot be applied immediately.
## Detection
* **Indicators of Compromise (IoCs):** Specific IoCs are provided in the Citrix TechZone blog (see references).
* **Detection Methods:**
* Utilize **NetScaler Console File Integrity Monitoring** to detect unauthorized changes to system files.
* Review logs for inconsistent HTTP request patterns (Smuggling).
* Audit for unusual process execution or outbound connections from NetScaler instances.
## References
* Citrix Security Bulletin: [https[:]//support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096]
* Citrix Technical Blog (IoCs): [https[:]//community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/]
* NCSC Official Alert: [https[:]//www.ncsc.gov.uk/news/exploitation-of-vulnerabilities-affecting-citrix-netscaler-adc-and-citrix-netscaler-gateway]