CVE-2026-88778(citrix / netscaler_application_delivery_controller)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-342

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • netscaler_application_delivery_controller
  • netscaler_gateway

Threat summary

  • 35 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 33 mentions (2026-09-27); latest day: 2
  • 35 total mentions across 2 days

Affected systems

Vendors
Products
netscaler_application_delivery_controllernetscaler_gateway

Deep dive

Activity timeline35 mentions / 2d
08172533Mentions · 2026-09-27: 33Mentions · 2026-09-28: 209-2709-28
Referenced assets12 URLs
Full discourse20 posts
  • Citrix@citrix

    Please see our latest Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778. Citrix urges affected customers to install the relevant updated versions as soon as possible. https://bit.ly/3T4RXGY

    9120252108079.1K
    197.2K followersView on X
  • Steven Lim@0x534c

    ⚠️ 𝗨𝗿𝗴𝗲𝗻𝘁: 𝗣𝗮𝘁𝗰𝗵 𝗡𝗲𝘁𝗦𝗰𝗮𝗹𝗲𝗿 𝗔𝗗𝗖/𝗚𝗮𝘁𝗲𝘄𝗮𝘆 𝗳𝗼𝗿 𝗔𝗰𝘁𝗶𝘃𝗲𝗹𝘆 𝗘𝘅𝗽𝗹𝗼𝗶𝘁𝗲𝗱 𝗩𝘂𝗹𝗻𝗲𝗿𝗮𝗯𝗶𝗹𝗶𝘁𝗶𝗲𝘀 ​ Citrix has confirmed active exploitation of 𝗖𝗩𝗘-𝟮𝟬𝟮𝟲-𝟴𝟴𝟳𝟳𝟭 and 𝗖𝗩𝗘-𝟮𝟬𝟮𝟲-𝟴𝟴𝟳𝟳𝟮 on unpatched NetScaler deployments and strongly recommends that affected customers upgrade to the latest fixed versions immediately. https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/​ To help security teams assess potential exposure, the KQL query below leverages 𝗠𝗶𝗰𝗿𝗼𝘀𝗼𝗳𝘁 𝗗𝗲𝗳𝗲𝗻𝗱𝗲𝗿 𝗳𝗼𝗿 𝗘𝗻𝗱𝗽𝗼𝗶𝗻𝘁 (𝗠𝗗𝗘) 𝗱𝗲𝘃𝗶𝗰𝗲 𝗱𝗶𝘀𝗰𝗼𝘃𝗲𝗿𝘆 𝘁𝗲𝗹𝗲𝗺𝗲𝘁𝗿𝘆 to identify NetScaler appliances within your environment, enabling faster validation and remediation actions. 🫡 https://github.com/SlimKQL/Detections.AI/blob/main/KQL/citrix-netscaler-check.kql ​ #MicrosoftDefender #CitrixNetScaler #VulnerabilityManagement #ThreatHunting #ZeroDay

    212069406.1K
    7.7K followersView on X
  • Dark Web Informer@DarkWebInformer

    ‼️ Citrix has released a security bulletin regarding zero-day attacks targeting Citrix NetScaler ADC and Citrix NetScaler Gateway. More info: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096 CVEs: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778

    3170641911.2K
    240.3K followersView on X
  • Censys@censysio

    Citrix has released a security bulletin for 8 vulnerabilities in NetScaler ADC and NetScaler Gateway (CVE-2026-88771 through CVE-2026-88778). Censys currently observes ~37K internet-facing hosts serving ~285K NetScaler web endpoints worldwide. Review Citrix's guidance and remediate: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096 #CensysARC

    317149227.1K
    12.6K followersView on X
  • Bert-Jan 🛡️@BertJanCyber

    Official comms and patches from Citrix are out! Exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments has been observed. https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/

    117144155.0K
    4.6K followersView on X
  • watchTowr@watchtowrcyber

    We hope you’ve enjoyed this episode of “no way? vulns? in SECURITY appliances? there is no proof” watchTowr Platform clients have access to this info every day - preempting, validating, mitigating exposure to emerging threats. Speak.. soon… ;-) xoxo https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/

    21104464.0K
    13.6K followersView on X
  • mRr3b00t@UK_Daniel_Card

    Citrix netscaler patches https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/

    0801942.9K
    125.8K followersView on X
  • Dark Web Intelligence@DailyDarkWeb

    🚨 CITRIX NETSCALER — OFFICIAL PATCHES FOR TWO EXPLOITED RCE ZERO-DAYS (CVE-2026-88771 / CVE-2026-88772) Cloud Software Group (Citrix) published security bulletin CTX697096 covering eight NetScaler ADC / NetScaler Gateway flaws, including two critical remote code execution vulnerabilities that the vendor says have been exploited on unmitigated deployments. Lead issues (vendor CVSS v4 Base Score 9.5 each): • CVE-2026-88771 — Improper input validation → unauthenticated remote command execution. Affects ALL NetScaler ADC and NetScaler Gateway deployments, including default configuration (no extra features required). • CVE-2026-88772 — Memory overflow → remote code execution or denial of service when DTLS is enabled (DTLS is enabled by default on VPN virtual servers unless explicitly set to OFF). Fixed builds (install ASAP): • NetScaler ADC / Gateway 14.1-73.37 and later • NetScaler ADC / Gateway 13.1-64.23 and later (13.1) • NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later • NetScaler ADC 13.1-FIPS / 13.1-NDcPP 13.1.37.279 and later Also addressed in the same bulletin: CVE-2026-88773 through CVE-2026-88778 (HTTP request smuggling, policy bypass, additional memory overflows, TCP ISN prediction). ⚠️ Analyst Note: This is the official Citrix confirmation + patch set for the weekend’s unpatched NetScaler RCE warnings. Separate from the earlier auth-bypass CVE-2026-19490 (Aug builds 14.1-73.32 / 13.1-63.21 do NOT include these new fixes). Vendor wording: “Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed.” No public attribution, victim count, or full IOC package in the bulletin at publish time. Patching alone does not prove a previously exposed appliance was clean — treat internet-facing units as potentially compromised until forensics say otherwise. CISA had not listed CVE-2026-88771 / CVE-2026-88772 in KEV as of this post (catalog still 2026.09.25). Prefer the Citrix bulletin over secondary media. Official Citrix bulletin (CTX697096): https://support.citrix.com/external/article/CTX697096/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-and-cve-2026-88772.html #Citrix #NetScaler #ZeroDay #RCE #CVE202688771 #CVE202688772 #Vulnerability #CyberSecurity #ThreatIntel #DDW

    0102135.8K
    205.1K followersView on X
  • kokumօtօ@__kokumoto

    Citrix NetScaler ADC/Gatewayのゼロデイ2件について公式情報が出た。CVE-2026-88771及びCVE-2026-88772はいずれもCVSSスコア9.5で、前者は無条件で刺さり、後者はDTLSが有効であることが条件(VPN仮想サーバでは既定で有効)。他6件も併せCVE-2026-88778までの8件が修正。 https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/

    111842.0K
    7.8K followersView on X
  • International Cyber Digest@IntCyberDigest

    Official update: https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/?utm_id=cid2026-0806&utm_source=facebook&utm_medium=social%20media%20organic&utm_campaign=citrix%20organic&utm_content=1790523126

    010913.4K
    231.0K followersView on X
  • Rıdvan Yağlı@ridvanyagli

    🚨 Citrix NetScaler ADC/Gateway: 8 kritik/yüksek güvenlik açığı için yama yayınlandı! 🔴 CVE-2026-88771 — CVSS 9.5 Unauthenticated RCE. Varsayılan yapılandırmalar dahil tüm NetScaler ADC/Gateway kurulumları etkileniyor. 🔴 CVE-2026-88772 — CVSS 9.5 Memory overflow -> RCE/DoS. DTLS etkin sistemler etkileniyor; VPN vServer'larda DTLS varsayılan olarak açık. 🟠 CVE-2026-88773 — CVSS 9.3 HTTP Request Smuggling. 🟠 CVE-2026-88774 — CVSS 7.0 Policy bypass. 🟠 CVE-2026-88775 — CVSS 8.8 Memory overflow -> DoS/öngörülemeyen davranış. 🟠 CVE-2026-88776 — CVSS 8.8 Memory overflow -> DoS. 🟠 CVE-2026-88777 — CVSS 8.8 Memory overflow -> DoS. 🟠 CVE-2026-88778 — CVSS 8.8 TCP Initial Sequence Number (ISN) prediction. ⚠️ CVE-2026-88771 ve CVE-2026-88772'nin aktif olarak istismar edildiği Citrix tarafından doğrulandı. Çözüm: 14.1-73.37+ veya 13.1-64.23+ sürümüne güncelleyin. FIPS/NDcPP sürümleri için ilgili güncel build'ler de uygulanmalı. Citrix güvenlik bülteni: https://support.citrix.com/external/article/CTX697096

    010801.1K
    2.4K followersView on X
  • KesagataMe@KesaGataMe0

    🚨Citrixよりゼロデイに関連した公式パッチリリースあり(CVE-2026-88771~88778) CVE-2026-88771 / 88772(CVSS 9.5)がRCEに繋がるもので悪用を既に観測 88771は前提条件なし、88772はDTLS有効が条件(VPN vServerはデフォルトON) https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096 https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/ https://t.co/qYoYA2iwl6

    00032853
    4.7K followersView on X
  • ExploitGrid@exploitgrid

    The disclosure is now official. Citrix has assigned CVE-2026-88771 through CVE-2026-88778 and released security updates for affected NetScaler deployments. We’re tracking the vulnerabilities and exploit intelligence on ExploitGrid.

    10021769
    127 followersView on X
  • Thomas Poppelgaard@_POPPELGAARD

    🚨 Patch your @NetScaler NOW. @citrix CTX697096: 8 new CVEs in NetScaler ADC & Gateway. Two are unauthenticated RCE and already exploited in the wild. 🧵 What you need to know 👇 #NetScaler #Citrix #PatchNow ——— 2/ The exploited two: 🔴 CVE-2026-88771 (CVSS 9.5) – RCE, affects every deployment incl. default config. No workaround. 🔴 CVE-2026-88772 (CVSS 9.5) – memory overflow → RCE via DTLS, which is ON by default on Gateway vServers. ——— 3/ Fixed builds: ✅ 14.1-73.37+ ✅ 13.1-64.23+ (64.24 if you use NS variables) ✅ 14.1-73.37 FIPS ✅ 13.1-37.279 FIPS/NDcPP ⚠️ Patched in August? You're NOT covered. ⚠️ 12.1/13.0 are EOL – no fix. ——— 4/ Before you upgrade: • On 13.1? Run "show ns variable". Any output → go to 13.1-64.24, not 64.23 (cyclic reboot risk) • SAML: unsigned assertions are no longer accepted. Make sure your IdP signs them, or logons break ——— 5/ After upgrading: • Enable Enhanced ISN Generation (CVE-2026-88778) • Assume breach – exploited before a patch existed • Save RAM + logs BEFORE reboot • Run the IoC scan in NetScaler Console (or ask Citrix Support) ——— 6/ Bulletin: https://support.citrix.com/external/article/CTX697096 Tech Zone guidance: https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/

    10021537
    4.2K followersView on X
  • mRr3b00t@UK_Daniel_Card

    @Technop54777070 https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/

    10021211
    125.8K followersView on X
  • にゃん☆たく/takumi.a@taku888infinity

    Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778 https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096 KEV↓ Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway https://www.cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway 参考 Citrix confirms two NetScaler RCE zero-days exploited in attacks https://www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/ 『(直訳)Citrixは、NetScalerのリモートコード実行に関する2つの重大な脆弱性(CVE-2026-88771およびCVE-2026-88772として追跡されている)が攻撃に悪用されていることを確認し、これらの脆弱性を修正するためのセキュリティアップデートをリリースしたことを発表しました。』

    100111.0K
    11.9K followersView on X
  • Autumn Good@autumn_good_35

    JPMorgan Chase XOR Team🤔 Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778 https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096

    10020693
    7.1K followersView on X
  • Cristian Borghello@SeguInfo

    Muuucha info de los 2 Zero-Days de Citrix NetScaler ADC y NetScaler Gateway (CVE-2026-88771 - CVE-2026-88778): https://blog.segu-info.com.ar/2026/09/explotacion-activa-de-dos-zero-day-rce.html Si tienes esos dispositivos, hoy no tienes nada más importante que hacer que PARCHEARLOS.

    00101520
    38.3K followersView on X
  • 🇩🇪🇪🇺🇺🇦 Nerdonaut @Nerdonaut_

    Neuigkeiten! Patches sind draußen: https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/

    00020298
    2.0K followersView on X
  • 🇩🇪🇪🇺🇺🇦 Nerdonaut @Nerdonaut_

    @twittaccount_ Schon entdeckt? https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/

    1001098
    2.0K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appcitrixnetscaler_application_delivery_controller---
Appcitrixnetscaler_application_delivery_controller---
Appcitrixnetscaler_application_delivery_controller---
Appcitrixnetscaler_gateway---

Explore more