search

LEMON BLOG

CISA Warns Citrix NetScaler Vulnerabilities Are Being Exploited In Active Attacks

The U.S. Cybersecurity and Infrastructure Security Agency, or CISA, has warned organisations about multiple serious vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway products. The newly disclosed flaws range from unauthenticated remote code execution and memory overflow issues to HTTP request smuggling, policy bypass and denial-of-service vulnerabilities. Several carry critical CVSS 4.1 scores above 9.0, and exploitation of some of the vulnerabilities has already been observed in real-world attacks.

The situation is particularly serious because NetScaler appliances are commonly deployed at the edge of enterprise networks, often providing application delivery, VPN and remote-access services. A successful attack against an exposed appliance could therefore give threat actors an important entry point into an organisation. Businesses running affected NetScaler deployments should review their versions and apply the relevant updates as soon as possible.

Nine Vulnerabilities Affect NetScaler Products

The security update covers nine vulnerabilities tracked as CVE-2026-88771 through CVE-2026-88779. Their CVSS 4.1 ratings range from High to Critical, with the most severe issues receiving scores of 9.5. Exposure varies depending on how NetScaler ADC or NetScaler Gateway has been configured and which features are enabled.

The most severe vulnerability, CVE-2026-88771, is an improper input-validation flaw that can allow an unauthenticated attacker to execute arbitrary commands remotely. It carries a critical CVSS score of 9.5 and affects NetScaler ADC and NetScaler Gateway under their default configuration, with no additional feature required for exposure.

Memory Overflow Flaw Can Lead To Remote Code Execution

CVE-2026-88772 is another critical vulnerability rated 9.5. The issue involves a memory overflow condition that can potentially result in remote code execution or denial of service. It affects deployments where Datagram Transport Layer Security, or DTLS, is enabled.

The concern is especially relevant because DTLS is enabled by default on VPN virtual servers. Organisations using NetScaler Gateway to provide remote-access services should therefore pay particular attention to this vulnerability. If exploited successfully, the flaw could potentially disrupt services or allow more serious compromise depending on the attack scenario.

HTTP Request Smuggling And Policy Bypass Also Patched

CVE-2026-88773 is a critical HTTP request-smuggling vulnerability with a CVSS score of 9.3. The flaw affects systems where HTTP configuration is enabled. Request-smuggling attacks typically exploit differences in how systems interpret HTTP traffic, allowing malicious requests to be processed in unexpected ways.

Another issue, CVE-2026-88774, is a high-severity feature-policy bypass vulnerability rated 7.0. This flaw is linked to improper use of HTTP URL-based expressions and affects environments where policies rely on those expressions. Although its severity rating is lower than the critical flaws, organisations using affected policy configurations should still treat it as an important security issue.

Several High-Severity Memory Overflow Issues

CVE-2026-88775 carries a CVSS score of 8.8 and involves a memory overflow vulnerability that can result in unpredictable behaviour or denial of service. It affects NetScaler ADC or Gateway systems configured for services such as SSL VPN, ICA Proxy, CVPN, RDP Proxy or AAA virtual servers.

Two additional memory overflow vulnerabilities, CVE-2026-88776 and CVE-2026-88777, are also rated 8.8. CVE-2026-88776 affects Oracle-type load-balancing virtual servers, while CVE-2026-88777 affects LB/CS or CGNAT-LSN/NAT64 deployments where a non-HTTP Layer 7 protocol feature is enabled.

These flaws may not all lead directly to code execution, but instability and denial-of-service conditions can still create significant operational impact. For internet-facing infrastructure, even a service interruption can affect users, business systems and remote-access availability.

TCP Prediction And SAML-Related Vulnerabilities Included

CVE-2026-88778 is a TCP Initial Sequence Number, or ISN, prediction vulnerability carrying a CVSS score of 8.8. The issue affects NetScaler ADC and NetScaler Gateway deployments where TCP configuration is enabled. Predictable sequence numbers can weaken protections that rely on TCP session integrity.

CVE-2026-88779 is another high-severity memory overflow vulnerability, rated 8.7, which can result in denial of service. It affects NetScaler systems configured as either a SAML Service Provider or SAML Identity Provider. Because SAML is frequently used for authentication and identity federation, organisations using NetScaler in these roles should verify their exposure carefully.

Several Vulnerabilities Are Already Being Exploited

Citrix has confirmed that CVE-2026-88771 and CVE-2026-88772 have already been exploited against NetScaler systems that had not yet been mitigated. CISA has also added CVE-2026-88779 to its Known Exploited Vulnerabilities catalogue, confirming that this flaw has seen exploitation as well.

This means organisations should not treat the update as routine maintenance. Once exploitation is confirmed, exposed systems are likely to attract additional scanning and attack attempts from both sophisticated groups and opportunistic attackers. Internet-facing NetScaler appliances should therefore be prioritised for immediate review and remediation.

Affected NetScaler Versions

CVE-2026-88771 through CVE-2026-88778 affect several Citrix NetScaler releases. Organisations should verify whether they are running any of the following vulnerable versions:

CVE-2026-88779 requires slightly newer fixed builds and affects:

Organisations Should Update Immediately

Affected customers are strongly advised to install the relevant NetScaler updates as soon as possible. For CVE-2026-88771 through CVE-2026-88778, the fixed versions begin with NetScaler ADC and Gateway 14.1-73.37, version 13.1-64.23, NetScaler ADC 14.1-73.37 FIPS and NetScaler ADC 13.1-FIPS or NDcPP 13.1-37.279.

For CVE-2026-88779, organisations need NetScaler ADC and Gateway 14.1-73.41 or later, version 13.1-64.28 or later, NetScaler ADC 14.1-73.41 FIPS or later, or NetScaler ADC 13.1-FIPS and NDcPP 13.1-37.282 or later. Administrators should ensure they install versions that address the complete set of vulnerabilities rather than stopping at an earlier build that only fixes some of the issues.

Indicators Of Compromise Are Also Available

Citrix is also making generic indicators of compromise, or IoCs, available through NetScaler Console. These indicators are intended to help customers carry out an initial assessment of whether their systems may already have been affected before the vulnerabilities were patched.

Because active exploitation has already been confirmed, organisations should not rely on patching alone. Administrators should also review available indicators, logs and unusual activity around affected appliances. If signs of compromise are found, a broader incident-response investigation may be necessary even after the vulnerable software has been updated.

Why Internet-Facing NetScaler Systems Need Priority

NetScaler ADC and Gateway systems often sit at a highly exposed point within enterprise infrastructure. They can provide remote access, VPN connectivity and application delivery, making them attractive targets for attackers looking for a path into internal systems. A compromised edge appliance can potentially provide access that bypasses some of the protections normally applied deeper inside the network.

This is why timely patching is particularly important for these products. Organisations should maintain accurate inventories of deployed appliances, confirm whether affected features are enabled and ensure that updates are applied consistently across every instance. A single forgotten or unpatched appliance can still create significant risk.

Final Thoughts

The latest Citrix NetScaler vulnerabilities should be treated as a high-priority security issue, especially for organisations exposing NetScaler ADC or NetScaler Gateway systems to the internet. Nine vulnerabilities are involved, including critical remote code execution and memory-overflow flaws, while exploitation has already been confirmed for CVE-2026-88771, CVE-2026-88772 and CVE-2026-88779.

Administrators should verify their current NetScaler versions, install the latest applicable security updates and review available indicators of compromise through NetScaler Console. With active exploitation already underway, organisations should assume that exposed and unpatched systems may be actively scanned or targeted rather than treating these fixes as routine patching.

The Mascot That Became A Liability

Related Posts

 

Comments 0

Loading latest comments...
Wednesday, 07 October 2026

Captcha Image

LEMON VIDEO CHANNELS

Step into a world where web design & development, gaming & retro gaming, and guitar covers & shredding collide! Whether you're looking for expert web development insights, nostalgic arcade action, or electrifying guitar solos, this is the place for you. Now also featuring content on TikTok, we’re bringing creativity, music, and tech straight to your screen. Subscribe and join the ride—because the future is bold, fun, and full of possibilities!

My TikTok Video Collection