CVE-2026-88773(citrix / netscaler_application_delivery_controller)

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before 13.1-64.23.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-444

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • netscaler_application_delivery_controller
  • netscaler_gateway

Threat summary

  • 8 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 7 mentions (2026-09-27); latest day: 1
  • 8 total mentions across 2 days

Affected systems

Vendors
Products
netscaler_application_delivery_controllernetscaler_gateway

Deep dive

Activity timeline8 mentions / 2d
02457Mentions · 2026-09-27: 7Mentions · 2026-09-28: 109-2709-28
Referenced assets8 URLs
Full discourse8 posts
  • Dark Web Informer@DarkWebInformer

    ‼️ Citrix has released a security bulletin regarding zero-day attacks targeting Citrix NetScaler ADC and Citrix NetScaler Gateway. More info: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096 CVEs: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778

    3170641911.2K
    240.3K followersView on X
  • Dark Web Intelligence@DailyDarkWeb

    🚨 CITRIX NETSCALER — OFFICIAL PATCHES FOR TWO EXPLOITED RCE ZERO-DAYS (CVE-2026-88771 / CVE-2026-88772) Cloud Software Group (Citrix) published security bulletin CTX697096 covering eight NetScaler ADC / NetScaler Gateway flaws, including two critical remote code execution vulnerabilities that the vendor says have been exploited on unmitigated deployments. Lead issues (vendor CVSS v4 Base Score 9.5 each): • CVE-2026-88771 — Improper input validation → unauthenticated remote command execution. Affects ALL NetScaler ADC and NetScaler Gateway deployments, including default configuration (no extra features required). • CVE-2026-88772 — Memory overflow → remote code execution or denial of service when DTLS is enabled (DTLS is enabled by default on VPN virtual servers unless explicitly set to OFF). Fixed builds (install ASAP): • NetScaler ADC / Gateway 14.1-73.37 and later • NetScaler ADC / Gateway 13.1-64.23 and later (13.1) • NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later • NetScaler ADC 13.1-FIPS / 13.1-NDcPP 13.1.37.279 and later Also addressed in the same bulletin: CVE-2026-88773 through CVE-2026-88778 (HTTP request smuggling, policy bypass, additional memory overflows, TCP ISN prediction). ⚠️ Analyst Note: This is the official Citrix confirmation + patch set for the weekend’s unpatched NetScaler RCE warnings. Separate from the earlier auth-bypass CVE-2026-19490 (Aug builds 14.1-73.32 / 13.1-63.21 do NOT include these new fixes). Vendor wording: “Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed.” No public attribution, victim count, or full IOC package in the bulletin at publish time. Patching alone does not prove a previously exposed appliance was clean — treat internet-facing units as potentially compromised until forensics say otherwise. CISA had not listed CVE-2026-88771 / CVE-2026-88772 in KEV as of this post (catalog still 2026.09.25). Prefer the Citrix bulletin over secondary media. Official Citrix bulletin (CTX697096): https://support.citrix.com/external/article/CTX697096/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-and-cve-2026-88772.html #Citrix #NetScaler #ZeroDay #RCE #CVE202688771 #CVE202688772 #Vulnerability #CyberSecurity #ThreatIntel #DDW

    0102135.8K
    205.1K followersView on X
  • Rıdvan Yağlı@ridvanyagli

    🚨 Citrix NetScaler ADC/Gateway: 8 kritik/yüksek güvenlik açığı için yama yayınlandı! 🔴 CVE-2026-88771 — CVSS 9.5 Unauthenticated RCE. Varsayılan yapılandırmalar dahil tüm NetScaler ADC/Gateway kurulumları etkileniyor. 🔴 CVE-2026-88772 — CVSS 9.5 Memory overflow -> RCE/DoS. DTLS etkin sistemler etkileniyor; VPN vServer'larda DTLS varsayılan olarak açık. 🟠 CVE-2026-88773 — CVSS 9.3 HTTP Request Smuggling. 🟠 CVE-2026-88774 — CVSS 7.0 Policy bypass. 🟠 CVE-2026-88775 — CVSS 8.8 Memory overflow -> DoS/öngörülemeyen davranış. 🟠 CVE-2026-88776 — CVSS 8.8 Memory overflow -> DoS. 🟠 CVE-2026-88777 — CVSS 8.8 Memory overflow -> DoS. 🟠 CVE-2026-88778 — CVSS 8.8 TCP Initial Sequence Number (ISN) prediction. ⚠️ CVE-2026-88771 ve CVE-2026-88772'nin aktif olarak istismar edildiği Citrix tarafından doğrulandı. Çözüm: 14.1-73.37+ veya 13.1-64.23+ sürümüne güncelleyin. FIPS/NDcPP sürümleri için ilgili güncel build'ler de uygulanmalı. Citrix güvenlik bülteni: https://support.citrix.com/external/article/CTX697096

    010801.1K
    2.4K followersView on X
  • にゃん☆たく/takumi.a@taku888infinity

    Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778 https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096 KEV↓ Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway https://www.cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway 参考 Citrix confirms two NetScaler RCE zero-days exploited in attacks https://www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/ 『(直訳)Citrixは、NetScalerのリモートコード実行に関する2つの重大な脆弱性(CVE-2026-88771およびCVE-2026-88772として追跡されている)が攻撃に悪用されていることを確認し、これらの脆弱性を修正するためのセキュリティアップデートをリリースしたことを発表しました。』

    100111.0K
    11.9K followersView on X
  • Autumn Good@autumn_good_35

    JPMorgan Chase XOR Team🤔 Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778 https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096

    10020693
    7.1K followersView on X
  • Jan Guldentops@JanGuldentops

    Citrix-file 2, the revenge? In 2020 ontstond in Nederland een nieuw woord: de citrix-file. Het verwees naar de Citrix software die heel wat ambtenaren gebruikten om veilig van thuis te werken. In Citrix werd toen een zware, makkelijk uit te buiten bug ontdekt, CVE 2019 19781, door de industrie Shitrix genoemd. Snoodaards konden daarmee zonder inloggegevens een heel systeem overnemen. De Nederlandse overheid panikeerde, verbood thuiswerk en het gevolg was een reeks ellenlange files op de snelweg. Vandaag is er misschien een nieuwe citrixfile in de maak. Er zitten opnieuw meerdere ernstige fouten in NetScaler, waarvan twee met een kritieke status en een score van ( CVE-2026-88771 en 2) , samen met nog zes andere lekken CVE-2026-88773 t.e.m 8) . Het verontrustende is dat er al langer geruchten gaan dat deze exploits al actief in het wild gebruikt worden.  Hackers gebruiken het volgens NTSC actief om webshells te gaan installeren. Citrix immers de gebruiksvriendelijke voordeur van je infrastructuur. Voor wie deze software draait en rechtstreeks aan het internet heeft hangen, wacht er dus meer werk dan enkel de patches installeren. De kans is reëel dat aanvallers al binnen zitten. Het loont om grondig te controleren of er al misbruik is gemaakt voor je update. Ga actief op zoek naar sporen van inbraak ( Indicators of Compromise), er zijn intussen detectietools beschikbaar. Neem meteen ook de tijd om alle logs dubbel te controleren en sleutels en wachtwoorden te roteren. Veel sterkte en aan de arbeid. En misschien moeten jullie dan maar eens nadenken of we Netscaler niet door een veiliger alternatief kunnen vervangen.  Misschien loont het om af en toe een ezel te zijn. Meer documentatie, tools, bronnen en vooruitschrijdende inzichten vind je in de comments hieronder: 👇 https://www.linkedin.com/posts/janguldentops_citrix-file-2-the-revenge-in-2020-ontstond-activity-7510207956261638144-EhhI

    00010186
    1.9K followersView on X
  • CVE@CVEnew

    CVE-2026-88773 Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affec… https://www.cve.org/CVERecord?id=CVE-2026-88773

    000001.1K
    58.1K followersView on X
  • PJ@Npj8448

    🚨 Citrix releases patches for actively exploited Netscaler zero-days (CVE-2026-88771, CVE-2026-88772, CVE-2026-88773) allowing unauthenticated RCE. Patch now and check for webshells! #CyberSecurity #CVE #Netscaler https://pranithjain.qzz.io/threatintel/social/firehose?tab=bluesky

    00000198
    78 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appcitrixnetscaler_application_delivery_controller---
Appcitrixnetscaler_application_delivery_controller---
Appcitrixnetscaler_application_delivery_controller---
Appcitrixnetscaler_gateway---

Explore more