Full Report
Multiple vulnerabilities have been discovered in NetScaler ADC and NetScaler Gateway, the most severe of which could allow for remote code execution. NetScaler ADC is a networking product that functions as an Application Delivery Controller (ADC), optimizing, securing, and ensuring reliable availability of applications for businesses. NetScaler Gateway is a secure remote access solution that provides users with single sign-on (SSO) access to applications and resources from any device. Successful exploitation of the most severe of these vulnerabilities could allow for remote code execution of commands on the system.
Analysis Summary
# Vulnerability: Multiple Vulnerabilities in NetScaler ADC and Gateway (RCE Focus)
## CVE Details
- **CVE ID:** CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, CVE-2026-88778.
- **CVSS Score:** Not explicitly listed, but rated **High/Critical** (Allows unauthenticated RCE).
- **CWE:** Improper Input Validation, Memory Overflow, Improper Handling of HTTP URL-based policy expressions.
## Affected Systems
- **Products:** NetScaler ADC and NetScaler Gateway.
- **Versions:**
- 14.1 versions prior to 14.1-73.37
- 13.1 versions prior to 13.1-64.23
- 14.1 FIPS versions prior to 14.1-73.37 FIPS
- 13.1 FIPS and NDcPP versions prior to 13.1-37.279
- **Configurations:**
- **CVE-2026-88771:** All deployments (Default).
- **CVE-2026-88772:** DTLS enabled (Default on VPN virtual servers).
- **CVE-2026-88775:** Configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.
- **CVE-2026-88776:** Load Balancing virtual servers of type Oracle.
- **CVE-2026-88777:** LB/CS or CGNAT-LSN/NAT64 with non-HTTP Layer 7 protocol features.
## Vulnerability Description
The most critical flaws (CVE-2026-88771 and CVE-2026-88772) involve improper input validation and memory overflows. An unauthenticated remote attacker can exploit these to execute arbitrary commands or cause a Denial of Service (DoS). Other vulnerabilities in the set include HTTP request smuggling, policy bypasses, and TCP sequence number prediction.
## Exploitation
- **Status:** **Exploited in the wild** (Specifically CVE-2026-88771 and CVE-2026-88772).
- **Complexity:** Low (CVE-2026-88771 affects default deployments).
- **Attack Vector:** Network.
## Impact
- **Confidentiality:** High (Full system compromise/Command execution).
- **Integrity:** High (Modification of system files/settings).
- **Availability:** High (Denial of service/System crash).
## Remediation
### Patches
Citrix has released the following updated versions to address these flaws:
- NetScaler ADC and NetScaler Gateway **14.1-73.37**
- NetScaler ADC and NetScaler Gateway **13.1-64.23**
- NetScaler ADC FIPS **14.1-73.37 FIPS**
- NetScaler ADC FIPS and NDcPP **13.1-37.279 FIPS and NDcPP**
### Workarounds
No specific configuration workarounds were provided in the advisory; immediate patching is the recommended course of action due to active exploitation.
## Detection
- **Indicators of Compromise:** Monitor for unusual outbound traffic from NetScaler appliances and unauthorized administrative logins. Check for exploit attempts matching MITRE Tactic TA0001 (Initial Access) and Technique T1190 (Exploit Public-Facing Application).
- **Detection methods and tools:** Utilize SCAP-compliant vulnerability scanners (Safeguard 7.5) and perform both authenticated and unauthenticated scans to identify outdated firmware versions.
## References
- **Vendor Advisory:** [https://support.citrix.com/external/article/CTX697096/citrix-netscaler-adc-and-citrix-netscale.html](https://support.citrix.com/external/article/CTX697096/citrix-netscaler-adc-and-citrix-netscale.html)
- **MITRE CVE-2026-88771:** [https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-88771](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-88771)
- **MS-ISAC Advisory:** [https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-netscaler-adc-and-netscaler-gateway-could-allow-for-remote-code-execution_2026-103](https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-netscaler-adc-and-netscaler-gateway-could-allow-for-remote-code-execution_2026-103)