Advisory [CVE-2026-88771 +7] Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778
This security NetScaler (Citrix) advisory covers CVE-2026-88771 and CVE-2026-88772 and 6 more CVEs.
Aggregated and source-linked by VulniPulse. Data sources, validation and limitations. This bulletin covers 8 CVEs; its score, affected versions and guidance may apply to different issues within that bulletin.
VulniPulse record published
Android app · Google Play
Monitor future NetScaler (Citrix) CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Summary
Guidance for customers on newly addressed vulnerabilities and recommended updates As the cybersecurity landscape continues to evolve, organizations across the industry are seeing changes in the pace, scale, and complexity of vulnerability research, discovery, and analysis.
AI-assisted research and automation may contribute to this shift by enabling faster identification and validation of certain classes of security issues. Citrix continues to invest in secure development, security testing, coordinated disclosure, and vulnerability response processes.
Citrix has released updates for NetScaler ADC and NetScaler Gateway to address multiple security vulnerabilities.
These vulnerabilities vary by deployment configuration and enabled features, and include issues that could allow remote code execution, denial of service, HTTP request smuggling, policy bypass, and TCP initial sequence number prediction under specific conditions.
Exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments has been observed. Citrix strongly urges affected customers to install the relevant updated versions as soon as possible.
Summary of Vulnerabilities CVE ID Description Preconditions CWE CVSS v4.0 CVE-2026-88771 Remote code execution due to improper input validation that can allow an unauthenticated attacker to execute arbitrary commands.
CISA Known Exploited Vulnerability
- Listed:
- Sep 27, 2026 · federal remediation due Sep 30, 2026
- Required action:
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Ransomware use:
- Unknown
KEV is a prioritization signal from CISA — remediation detail still comes from the vendor advisory.
- 15.1
Official advisory · medium-confidence parse· fetched 3 days ago·verify at source
- 14.1-73.37
- 13.1-64.23
- 13.1.37.279
Official advisory · medium-confidence parse· fetched 3 days ago·verify at source
Mitigation checklist
- Upgrade to a fixed build: 14.1-73.37, 13.1-64.23, 13.1.37.279 or later for your release line.
- Citrix strongly urges affected customers to install the relevant updated versions as soon as possible.
- You are advised to retain the services of experienced forensic investigators to assess your environment.
Official advisory · medium-confidence parse· fetched 3 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.