Skip to content

Detection of Multiple Vulnerabilities in Citrix Products Affecting Security

Published:
Detection of Multiple Vulnerabilities in Citrix Products Affecting Security

On September 28, 2026, INCIBE-CERT published a notice regarding the detection of multiple vulnerabilities in Citrix affecting specific versions of NetScaler ADC and NetScaler Gateway. These vulnerabilities, reported by Michael Tucker, Chew Keong Tan, Alex Bernier, and Maxim Suhanov, include critical and high-severity flaws that may compromise the security of the affected systems.

Details of Identified Vulnerabilities in Citrix

A total of eight vulnerabilities have been detected, three of which are critical and five are high severity. Among the critical ones, notable issues include the possibility of remote code execution, denial of service (DoS), HTTP request smuggling, security policy evasion, and TCP sequence number prediction.

Citrix has confirmed that two of these critical vulnerabilities, CVE-2026-88771 and CVE-2026-88772, are actively being exploited in installations that have not applied the necessary updates.

The CVE-2026-88771 vulnerability corresponds to improper input validation in NetScaler ADC and NetScaler Gateway. An unauthenticated remote attacker could execute arbitrary commands on the device. This flaw affects all vulnerable configurations, including default settings.

The CVE-2026-88772 is a memory overflow that could allow remote code execution or cause a denial of service. Its exploitation requires DTLS to be enabled, which is the default setting on VPN virtual servers. This vulnerability is also actively being exploited.

Lastly, CVE-2026-88773 is related to HTTP request smuggling due to inconsistent request interpretation. An unauthenticated remote attacker could inject manipulated requests into the communications processed by the device when HTTP configuration is enabled.

Products and Versions Affected by Citrix Vulnerabilities

Detection of Multiple Vulnerabilities in Citrix Products Affecting Security

These vulnerabilities affect the following supported versions of NetScaler ADC and NetScaler Gateway:

  • NetScaler ADC and NetScaler Gateway 14.1, prior to version 14.1-73.37
  • NetScaler ADC and NetScaler Gateway 13.1, prior to version 13.1-64.23
  • NetScaler ADC 14.1-FIPS, prior to version 14.1-73.37 FIPS
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP, prior to version 13.1-37.279

Hybrid deployments of Secure Private Access using NetScaler instances are also affected. Services in the cloud directly managed by Citrix are not affected, as the vendor takes care of updating them.

Measures to Mitigate Risks and Update Affected Products

Citrix has released updated versions to address these vulnerabilities. The recommended versions are as follows or later:

  • NetScaler ADC and NetScaler Gateway 14.1: version 14.1-73.37
  • NetScaler ADC and NetScaler Gateway 13.1: version 13.1-64.23
  • NetScaler ADC 14.1-FIPS: version 14.1-73.37 FIPS
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP: version 13.1-37.279

To address the CVE-2026-88778 vulnerability, it is also necessary to enable the Enhanced ISN Generation feature, following the instructions provided by Citrix.

Before updating, it is recommended to retain available evidence and check for signs of compromise. This includes collecting logs, generating a snapshot of virtual instances, and obtaining a technical support package. If signs of compromise are detected, it is advised to isolate the device, revoke stored credentials and certificates, investigate connected systems, and rebuild the instance from a backup prior to the incident.

It is also noted that the management interfaces of NetScaler should not be directly exposed to the Internet.

Scope and Impact of Detected Vulnerabilities

The vulnerabilities in Citrix may allow remote code execution and cause service interruptions. Two critical vulnerabilities are actively being exploited in unpatched installations, as confirmed by Citrix.

The notice focuses on products installed and configured locally. It does not affect cloud services directly managed by Citrix, which receive automatic updates.

These vulnerabilities affect environments with NetScaler ADC and NetScaler Gateway in the indicated versions, including default configurations and hybrid deployments with Secure Private Access.

Conclusion

The INCIBE-CERT report highlights the presence of critical and high-severity vulnerabilities in widely used Citrix products for remote access and load balancing. There is no information available to conclude on the extent of the impact in specific environments or on specific incidents beyond the confirmed active exploitations.

The original source provides technical details and precise recommendations to mitigate the detected risks in NetScaler ADC and NetScaler Gateway. It can be consulted at the following link: original source.

Reviewed by
Published: 29/09/2026. Content reviewed using experience, authority and trustworthiness criteria (E-E-A-T).
Responsible use of AI
This article may have used artificial intelligence tools to support structure, editing, translation or review. Editorial responsibility and final review remain with Toni Berraquero. View AI policy
Photo of Toni
Article author
Toni Berraquero

Toni Berraquero has trained since the age of 12 and has experience in retail, private security, ecommerce, digital marketing, marketplaces, automation and business tools.

View Toni’s profile

☕ If this genuinely helped…

You can support the project or share this article in one click. At least this block does something useful.