XT.PT Edge devices → This story
Filed

Updated 06:28
Reporting
Prelo
Verified by Roger Morais
4 min · 702 words
News Edge devices

NetScaler 14.1-73.37 fixes eight CVEs, and the exploited CVE-2026-88771 needs no special configuration

CVE-2026-88771 affects default configurations, and CVE-2026-88772 needs DTLS, which is on by default for Gateway VPN virtual servers.

Filed30 Sep 2026, 12:30 UTC Length4 min · 702 words ReportingPrelo
code

Cloud Software Group published a security bulletin for Citrix NetScaler ADC and NetScaler Gateway on Sunday, September 27, covering eight CVEs, CVE-2026-88771 through CVE-2026-88778. The line that matters most is in the section headed "What Customers Should Do":

Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed.

Citrix security bulletin CTX697096

CISA added both to its Known Exploited Vulnerabilities catalog the same day, with a due date of September 30 for federal civilian agencies and forensic triage marked as required.

The two exploited bugs

CVE-2026-88771 is described as "A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands." CVSS 4.0 score: 9.5. Its precondition is the whole point: "All NetScaler ADC and NetScaler Gateway deployments (Default configuration / No additional feature required)." There is no configuration to audit for this one; the only question is the build number.

CVE-2026-88772 is a memory overflow "leading to Remote Code Execution or Denial of Service," also 9.5. It requires DTLS, and the bulletin notes DTLS is "Enabled by default on VPN vServer." Citrix gives the patterns to look for in the running configuration:

add vpn vserver vpn1 SSL 10.0.0.0 443 -Listenpolicy NONE
    (DTLS not explicitly disabled, so enabled by default)
add vpn vserver vpn1 SSL 10.0.0.0 443 -dtls OFF -Listenpolicy NONE
    (DTLS explicitly disabled: precondition not met)
add vpn vserver vs1 DTLS 10.11.1.1 443
add lb vserver vd_dtls DTLS 10.146.111.74 443 -persistenceType NONE -cltTimeout 120
    (DTLS enabled)

In other words, a Gateway is exposed to 88772 unless someone turned DTLS off on purpose. Since 88771 needs nothing at all, a Gateway that is not on a fixed build is exposed to both.

Fixed builds

The bulletin lists these as the first fixed releases:

  • NetScaler ADC and Gateway 14.1-73.37 and later
  • NetScaler ADC and Gateway 13.1-64.23 and later releases of 13.1
  • NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later

Secure Private Access hybrid deployments that use NetScaler instances are affected and need the same upgrade. The bulletin says Citrix upgrades its own managed cloud services and Citrix-managed Adaptive Authentication itself; the bulletin "only applies to customer-managed" appliances.

The other six

| CVE | Issue | CVSS 4.0 | Precondition | | --- | --- | ---: | --- | | 88773 | HTTP request smuggling | 9.3 | HTTP or SSL virtual servers | | 88774 | Policy bypass in HTTP URL expressions | 7.0 | URL-based policy expressions | | 88775 | Memory overflow, DoS | 8.8 | Gateway or AAA virtual server | | 88776 | Memory overflow, DoS | 8.8 | LB virtual server of type Oracle | | 88777 | Memory overflow, DoS | 8.8 | Non-HTTP L7 features (FTP, RTSP, DNS64, NAT64 and others) | | 88778 | TCP initial sequence number prediction | 8.8 | TCP virtual servers with Enhanced ISN Generation disabled |

The last row needs a configuration step as well as an upgrade: the bulletin says deployments impacted by 88778 "should apply the TCP configuration change" that turns on Enhanced ISN Generation, and gives the check:

show ns tcpparam | grep "Enhanced ISN Generation"

A result of DISABLED, on an appliance with at least one TCP-based virtual server, meets the precondition.

For 88777, note one default in Citrix's own patterns: on LSN/CGNAT groups, "FTP ALG is enabled by default unless explicitly disabled."

Patching is not the end of it

CISA's catalog notes say "Running the provided IOCs in the NetScaler console may help identify indicators of exploitation," and point to a separate Citrix article on steps to take if an appliance is suspected of compromise. The indicators are in a NetScaler blog post linked from the bulletin, which blocked our fetch, so we do not reproduce them here. Our inference, not Citrix's wording: nothing in the bulletin says an upgrade removes anything an attacker left on an appliance before it, and CISA's forensic-triage requirement points the same way. The IOC check belongs in the same maintenance window as the upgrade.

Citrix credits Michael Tucker, Chew Keong Tan and Alex Bernier of the JPMorgan Chase XOR Team, and Maxim Suhanov.

Primary sources: Citrix security bulletin CTX697096, CISA KEV catalog, NetScaler TCP configurations: Enhanced ISN generation, read 2026-09-29.

Corrections and source documents: contact the desk
Read next →
Read next
WordPress · 4 min

WordPress 7.1.2 fixes CVE-2026-87902, a page-template bug exploited within three days

Supply chain · 5 min

Plugin4Shell: the commit Claude Code pinned was not always the one it installed