PT-2026-99550 · Citrix · Netscaler Adc+1

CVE-2026-88771

·

Published

2026-09-26

·

Updated

2026-10-02

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Citrix NetScaler ADC versions prior to 14.1-73.37 Citrix NetScaler ADC versions prior to 13.1-64.23 Citrix NetScaler ADC versions prior to 14.1-73.37 FIPS Citrix NetScaler ADC versions prior to 13.1.37.279 FIPS and NDcPP Citrix NetScaler Gateway versions prior to 14.1-73.37 Citrix NetScaler Gateway versions prior to 13.1-64.23
Description An improper input validation issue exists in Citrix NetScaler ADC and Citrix NetScaler Gateway. This flaw allows an unauthenticated remote attacker to execute arbitrary commands. The issue is also associated with a memory buffer overflow, which could lead to arbitrary code execution or a denial of service. Real-world exploitation of this flaw was observed throughout September, occurring several weeks before official fixes were released.
Recommendations Update Citrix NetScaler ADC to version 14.1-73.37 or later. Update Citrix NetScaler ADC to version 13.1-64.23 or later. Update Citrix NetScaler ADC FIPS to version 14.1-73.37 or later. Update Citrix NetScaler ADC FIPS and NDcPP to version 13.1.37.279 or later. Update Citrix NetScaler Gateway to version 14.1-73.37 or later. Update Citrix NetScaler Gateway to version 13.1-64.23 or later. Preserve system snapshots, logs, and memory dumps to investigate potential unauthorized administrative sessions and unknown outgoing connections, as patching does not remove existing attacker access.

Exploit

Fix

RCE

DoS

LPE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-15496
BDU:2026-15497
CVE-2026-88771

Affected Products

Netscaler Adc
Netscaler Gateway