{
    "file_item": {
        "filepath": "security-advisories",
        "filename": "CERT-EU-SA2026-014.pdf"
    },
    "title": "Critical Vulnerabilities in Citrix NetScaler ADC and Gateway",
    "serial_number": "2026-014",
    "publish_date": "27-09-2026 17:40:52",
    "description": "On 27 September 2026, Citrix published a security bulletin addressing 8 vulnerabilities affecting customer-managed Citrix NetScaler ADC and Citrix NetScaler Gateway, among which 2 critical unauthenticated Remote Code Execution (RCE) vulnerabilities. Citrix has confirmed active exploitation of these 2 critical vulnerabilities in the wild.<br>\nCERT-EU recommends updating affected software and running a compromise assessment on those exposed on the internet.<br>\n",
    "url_title": "2026-014",
    "content_markdown": "---    \ntitle: 'Critical Vulnerabilities in\u00a0Citrix\u00a0NetScaler\u00a0ADC and\u00a0Gateway'\nnumber: '2026-014'\nversion: '1.0'\noriginal_date: '2026-09-27'\ndate: '2026-09-27'\n---\n\n_History:_\n\n* _27/09/2026 --- v1.0 -- Initial publication_\n\n# Summary\n\nOn 27 September 2026, Citrix published a security bulletin addressing 8 vulnerabilities affecting customer-managed Citrix NetScaler ADC and Citrix NetScaler Gateway, among which 2 critical unauthenticated Remote Code Execution (RCE) vulnerabilities. Citrix has confirmed **active exploitation** of these 2 critical vulnerabilities in the wild [1].\n\nCERT-EU recommends updating affected software and running a compromise assessment on those exposed on the internet.\n\n# Technical Details\n\n\nThe vulnerability **CVE-2026-88771**, with a CVSS score of 9.5, is an unauthenticated RCE flow due to improper input validation. As there is no precondition for the exploitation, it affects all Citrix NetScaler ADC and Citrix NetScaler Gateway deployments. It is **exploited in the wild** [1].\n\nThe vulnerability **CVE-2026-88772**, with a CVSS score of 9.5, a memory overflow vulnerability leading to RCE or Denial of Service (DoS). It affects Citrix NetScaler ADC and Citrix NetScaler Gateway deployments where DTLS is enabled (default on VPN vServer). It is **exploited in the wild** [1].\n\nThe vulnerability **CVE-2026-88773**, with a CVSS score of 9.3, is an HTTP Request Smuggling vulnerability. It affects Citrix NetScaler ADC and Citrix NetScaler Gateway deployments where an HTTP URL-based policy expression configured [1].\n\nThe vulnerability **CVE-2026-88774**, with a CVSS score of 7.0, is a feature policy bypass via HTTP URL-based expression flow. It affects Citrix NetScaler ADC and Citrix NetScaler Gateway deployments where an HTTP URL-based policy expression configured [1].\n\nThe vulnerabilities **CVE-2026-88775**, **CVE-2026-88776** and **CVE-2026-88777**, each with a CVSS score of 8.8, are memory overflow vulnerabilities leading to unpredictable or erroneous behaviour or DoS conditions. They affect Citrix NetScaler ADC and Citrix NetScaler Gateway deployments where respectively, a gateway or AAA vServer is configured, an LB vServer of type Oracle is configured, or an LB/CS or CGNAT-LSN/NAT64 with non-HTTP L7 protocol is enabled [1].\n\nThe vulnerability **CVE-2026-88778**, with a CVSS score of 8.8, is a TCP Initial Sequence Number (ISN) prediction vulnerability. It affects Citrix NetScaler ADC and Citrix NetScaler Gateway deployments where a TCP configuration is enabled with Enhanced ISN Generation disabled [1].\n\n# Affected Products\n\nThe following products and versions are affected [1]:\n\n- Citrix NetScaler ADC and NetScaler Gateway versions **13.1 before 13.1-64.23** and **14.1 before 14.1-73.37**.\n- Citrix NetScaler ADC FIPS version **14.1 before 14.1-73.37 FIPS**\n- Citrix NetScaler ADC FIPS and NDcPP version **13.1 before 13.1-37.279**\n\nThis bulletin applies to customer-managed deployments only. Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded.\n\nFor precondition verification steps, refer to the Citrix bulletin [1].\n\n# Recommendations\n\nCERT-EU recommend to update all affected customer-managed appliances to the fixed version immediately. It is also recommended to enable Enhanced ISN Generation for deployments where a TCP configuration is enabled [2].\n\nCERT-EU strongly advise to run a compromise assessment on any internet-facing appliance running an affected build.\n\n# References\n\n[1] <https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096>\n\n[2] <https://docs.netscaler.com/en-us/citrix-adc/current-release/system/tcp-configurations.html#enhanced-isn-generation>",
    "content_html": "<p><em>History:</em></p><ul><li><em>27/09/2026 --- v1.0 -- Initial publication</em></li></ul><h2 id=\"summary\">Summary</h2><p>On 27 September 2026, Citrix published a security bulletin addressing 8 vulnerabilities affecting customer-managed Citrix NetScaler ADC and Citrix NetScaler Gateway, among which 2 critical unauthenticated Remote Code Execution (RCE) vulnerabilities. Citrix has confirmed <strong>active exploitation</strong> of these 2 critical vulnerabilities in the wild [1].</p><p>CERT-EU recommends updating affected software and running a compromise assessment on those exposed on the internet.</p><h2 id=\"technical-details\">Technical Details</h2><p>The vulnerability <strong>CVE-2026-88771</strong>, with a CVSS score of 9.5, is an unauthenticated RCE flow due to improper input validation. As there is no precondition for the exploitation, it affects all Citrix NetScaler ADC and Citrix NetScaler Gateway deployments. It is <strong>exploited in the wild</strong> [1].</p><p>The vulnerability <strong>CVE-2026-88772</strong>, with a CVSS score of 9.5, a memory overflow vulnerability leading to RCE or Denial of Service (DoS). It affects Citrix NetScaler ADC and Citrix NetScaler Gateway deployments where DTLS is enabled (default on VPN vServer). It is <strong>exploited in the wild</strong> [1].</p><p>The vulnerability <strong>CVE-2026-88773</strong>, with a CVSS score of 9.3, is an HTTP Request Smuggling vulnerability. It affects Citrix NetScaler ADC and Citrix NetScaler Gateway deployments where an HTTP URL-based policy expression configured [1].</p><p>The vulnerability <strong>CVE-2026-88774</strong>, with a CVSS score of 7.0, is a feature policy bypass via HTTP URL-based expression flow. It affects Citrix NetScaler ADC and Citrix NetScaler Gateway deployments where an HTTP URL-based policy expression configured [1].</p><p>The vulnerabilities <strong>CVE-2026-88775</strong>, <strong>CVE-2026-88776</strong> and <strong>CVE-2026-88777</strong>, each with a CVSS score of 8.8, are memory overflow vulnerabilities leading to unpredictable or erroneous behaviour or DoS conditions. They affect Citrix NetScaler ADC and Citrix NetScaler Gateway deployments where respectively, a gateway or AAA vServer is configured, an LB vServer of type Oracle is configured, or an LB/CS or CGNAT-LSN/NAT64 with non-HTTP L7 protocol is enabled [1].</p><p>The vulnerability <strong>CVE-2026-88778</strong>, with a CVSS score of 8.8, is a TCP Initial Sequence Number (ISN) prediction vulnerability. It affects Citrix NetScaler ADC and Citrix NetScaler Gateway deployments where a TCP configuration is enabled with Enhanced ISN Generation disabled [1].</p><h2 id=\"affected-products\">Affected Products</h2><p>The following products and versions are affected [1]:</p><ul><li>Citrix NetScaler ADC and NetScaler Gateway versions <strong>13.1 before 13.1-64.23</strong> and <strong>14.1 before 14.1-73.37</strong>.</li><li>Citrix NetScaler ADC FIPS version <strong>14.1 before 14.1-73.37 FIPS</strong></li><li>Citrix NetScaler ADC FIPS and NDcPP version <strong>13.1 before 13.1-37.279</strong></li></ul><p>This bulletin applies to customer-managed deployments only. Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded.</p><p>For precondition verification steps, refer to the Citrix bulletin [1].</p><h2 id=\"recommendations\">Recommendations</h2><p>CERT-EU recommend to update all affected customer-managed appliances to the fixed version immediately. It is also recommended to enable Enhanced ISN Generation for deployments where a TCP configuration is enabled [2].</p><p>CERT-EU strongly advise to run a compromise assessment on any internet-facing appliance running an affected build.</p><h2 id=\"references\">References</h2><p>[1] <a rel=\"noopener\" target=\"_blank\" href=\"https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096\">https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096</a></p><p>[2] <a rel=\"noopener\" target=\"_blank\" href=\"https://docs.netscaler.com/en-us/citrix-adc/current-release/system/tcp-configurations.html#enhanced-isn-generation\">https://docs.netscaler.com/en-us/citrix-adc/current-release/system/tcp-configurations.html#enhanced-isn-generation</a></p>",
    "licence": {
        "title": "Creative Commons Attribution 4.0 International (CC-BY 4.0)",
        "link": "https://creativecommons.org/licenses/by/4.0/",
        "restrictions": "https://cert.europa.eu/legal-notice",
        "author": "The Cybersecurity Service for the Union institutions, bodies, offices and agencies"
    }
}