Several critical vulnerabilities in "Citrix NetScaler" have been disclosed. "Citrix" has released security updates that address several critical vulnerabilities in "NetScaler ADC" and "NetScaler Gateway". Two of them – CVE-2026-88771 and CVE-2026-88772 – can allow attackers to perform remote code execution. It is noted that these vulnerabilities are already being actively exploited in systems.
CVE-2026-88771 also affects devices with default configurations – their use does not require the additional feature to be enabled. Meanwhile, CVE-2026-88772 relates to systems where DTLS; "VPN vServer" configuration is enabled by default unless explicitly disabled.
We urge organizations to check the used versions and install the appropriate security updates as soon as possible:
| Product | Version with security fixes |
|---|---|
| NetScaler ADC and NetScaler Gateway 14.1 | 14.1-73.37 or newer |
| NetScaler ADC and NetScaler Gateway 13.1 | 13.1-64.23 or newer |
| NetScaler ADC 14.1-FIPS | 14.1-73.37 FIPS or newer |
| NetScaler ADC 13.1-FIPS and 13.1-NDcPP | 13.1-37.279 or newer |
These vulnerabilities also affect "NetScaler" devices used in "Secure Private Access Hybrid" solutions. We ask you to familiarize yourselves with the official recommendations regarding these vulnerabilities and take the necessary actions.
More information:
