Skip to content
VulniPulse

NetScaler (Citrix) Security Advisories & CVEs

20 advisories tracked · NetScaler / Cloud Software Group Security Bulletins · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor NetScaler CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Check if your NetScaler device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in NetScaler's recent advisories.

Official source

NetScaler / Cloud Software Group Security Bulletins

NetScaler CVE disclosures now live in Citrix Community Security Updates. VulniPulse polls the official Tech Zone RSS feed and keeps NetScaler-specific security-category bulletins and CTX guidance, including affected and fixed build details.

Latest NetScaler advisories

Critical9.5NetScaler Updated

Critical [CVE-2026-107406] Protecting Customers: Immediate Guidance for CVE-2026-107406 in NetScaler ADC and NetScaler Gateway

Today, Citrix published a critical security bulletin for NetScaler ADC and NetScaler Gateway regarding CVE-2026-107406. CVE-2026-107406 is a memory overflow vulnerability that may lead to remote code execution or denial of service under specific configuration conditions. The issue carries a CVSS v4.0 base score of 9.5 and is rated Critical. We strongly urge affected customers to review the advisory and upgrade impacted NetScaler instances to the recommended versions as soon as possible. As of the publication of the bulletin, Citrix is not aware of any unmitigated exploits of this vulnerability.

CVE-2026-107406
NetScaler Gateway
Oct 8, 2026
High8.7NetScaler Exploited CISA KEV

High [CVE-2026-88779] Understanding and Addressing CVE-2026-88779 in Citrix NetScaler ADC and Citrix NetScaler Gateway

CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to denial of service under specific deployment conditions. The issue affects customer-managed NetScaler deployments running affected supported versions when the required preconditions are met. Customers should review their deployed versions and configurations, then install the relevant updated versions as soon as possible. Affected Versions The following supported versions are affected when the CVE preconditions (see the section “How to Determine Whether a NetScaler deployment Meets the Preconditions” below) apply: NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.41 NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.28 NetScaler ADC FIPS before 14.1-73.41 FIPS NetScaler ADC FIPS and NDcPP before 13.1-37.282 What Is the Issue? CVE-2026-88779 is categorized as CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer. The vulnerability has a CVSS v4.0 base score of 8.7. Citrix has observed targeted attacks on unmitigated NetScaler deployments which can lead to Denial of Service. If the condition is triggered repeatedly, the service may remain unavailable. Our analysis indicates that this issue affects service availability, and we have not identified an impact on the integrity of customer data.

CVE-2026-88779
NetScaler Gateway
Oct 4, 2026
UnratedNetScaler

Advisory Security Update: Guidance for NetScaler SAML Authentication Deployments

NetScaler engineering and support teams are tracking a newly observed issue related to SAML authentication in customer-managed NetScaler deployments. This post explains what customers should review, how to determine whether the relevant configuration is present, and what mitigation options are available while planning an upgrade to a fixed build. A new security bulletin and a new blog has been published. The guidance below is intended to help customers take immediate action to reduce exposure. As with any security-related issue, customers should prioritize applying the updated NetScaler builds referenced in the applicable security bulletin. What is being observed The issue is associated with NetScaler deployments that use SAML authentication in conjunction with Gateway or AAA functionality. Customers who have deployed NetScaler as a Gateway or AAA virtual server should review their NetScaler configurations to determine whether SAML authentication actions are configured. Based on the information currently available to us, this issue is configuration dependent. Customers should search for the following configuration patterns in their NetScaler configurations to determine applicability.

NetScaler Gateway
Oct 2, 2026
Critical9.3NetScaler

Critical [CVE-2026-88773] HTTP Request Smuggling

Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before 13.1-64.23.

CVE-2026-88773
NetScaler Gateway
Sep 27, 2026
Critical9.5NetScaler Exploited CISA KEV

Critical [CVE-2026-88772] Memory overflow vulnerability leading to Remote Code Execution or Denial of Service

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service

CVE-2026-88772
NetScaler Gateway
Sep 27, 2026
Critical9.5NetScaler Exploited CISA KEV

Critical [CVE-2026-88771] A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands

Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.

CVE-2026-88771
NetScaler Gateway
Sep 27, 2026
High8.8NetScaler

High [CVE-2026-88778] TCP Initial Sequence Number (ISN) prediction

Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23.

CVE-2026-88778
NetScaler Gateway
Sep 27, 2026
High8.8NetScaler

High [CVE-2026-88777] Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service

Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to unpredictable or erroneous behavior or Denial of Service

CVE-2026-88777
NetScaler Gateway
Sep 27, 2026
High8.8NetScaler

High [CVE-2026-88775] Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service

CVE-2026-88775
NetScaler Gateway
Sep 27, 2026
High7.0NetScaler

High [CVE-2026-88774] Feature policy bypass due to improper HTTP URL based expression usage

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to a feature policy bypass due to improper HTTP URL based expression usage.

CVE-2026-88774
NetScaler Gateway
Sep 27, 2026
UnratedNetScaler Exploited CISA KEV

Advisory [CVE-2026-88771 +7] Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778

Guidance for customers on newly addressed vulnerabilities and recommended updates As the cybersecurity landscape continues to evolve, organizations across the industry are seeing changes in the pace, scale, and complexity of vulnerability research, discovery, and analysis. AI-assisted research and automation may contribute to this shift by enabling faster identification and validation of certain classes of security issues. Citrix continues to invest in secure development, security testing, coordinated disclosure, and vulnerability response processes. Citrix has released updates for NetScaler ADC and NetScaler Gateway to address multiple security vulnerabilities. These vulnerabilities vary by deployment configuration and enabled features, and include issues that could allow remote code execution, denial of service, HTTP request smuggling, policy bypass, and TCP initial sequence number prediction under specific conditions. Exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments has been observed. Citrix strongly urges affected customers to install the relevant updated versions as soon as possible. Summary of Vulnerabilities CVE ID Description Preconditions CWE CVSS v4.0 CVE-2026-88771 Remote code execution due to improper input validation that can allow an unauthenticated attacker to execute arbitrary commands.

CVE-2026-88771CVE-2026-88772CVE-2026-88773+5
NetScaler ADCNetScaler Gateway
Sep 27, 2026
Critical9.3NetScaler Exploited CISA KEV

Critical [CVE-2026-19490] NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

CVE-2026-19490
NetScaler Gateway
Aug 19, 2026
High8.8NetScaler

High [CVE-2026-19489] Vulnerability in NetScaler ADC and NetScaler Gateway

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

CVE-2026-19489
NetScaler Gateway
Aug 19, 2026
High8.8NetScaler Exploited CISA KEV

High [CVE-2026-8452] Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service

Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server

CVE-2026-8452
NetScaler Gateway
Jun 30, 2026
HighNetScaler Exploited CISA KEV

High [CVE-2026-3055] Important Update: CVE Disclosures Now Live on the Citrix Community Site

All CVE disclosure blogs have moved to The Citrix Community Site Going forward, all CVE disclosure blogs will be published in the Security Updates tab on the Citrix Community website. CVE-2026-3055 & CVE 2026-4368 Cloud Software Group released builds on March 23, 2026 to address CVE-2026-3055 and CVE 2026-4368.

CVE-2026-3055
Unclassified
Mar 27, 2026
Medium5.9NetScaler

Medium Medium severity security update announced for NetScaler Gateway and NetScaler

Cloud Software Group released builds on November 11, 2025, to address one security vulnerability. NetScaler Gateway & NetScaler is affected by CVE 2025-12101, which has a CVSS score of 5.9. CVE 2025-12101 is a cross-site scripting vulnerability impacting NetScaler Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy, or AAA virtual server). Affected products named by the advisory: NetScaler ADC.

NetScaler ADCNetScaler Gateway
Nov 11, 2025
Critical9.2NetScaler Exploited CISA KEV

Critical [CVE-2025-7775 +2] Critical security update announced for NetScaler Gateway and NetScaler

Cloud Software Group released builds on August 26, 2025, to address three security vulnerabilities. NetScaler Gateway & NetScaler is affected by CVE-2025-7775, which has a CVSS score of 9.2. CVE-2025-7776 impacts NetScaler Gateway (CVSS 8.8), CVE-2025-8424 impacts NetScaler (CVSS 8.7). Affected products named by the advisory: NetScaler ADC; NetScaler Console.

CVE-2025-7775CVE-2025-7776CVE-2025-8424
NetScaler ADCNetScaler GatewayNetScaler Console
Aug 26, 2025
CriticalNetScaler

Critical Leading the Quantum-Ready Transition: How NetScaler Helps Prevent a Silent Data Breach Decades in the Making

The Quantum Threat is No Longer Theoretical Today, every sensitive piece of data you create, transmit, and store is encrypted. The algorithms that have underpinned modern encryption standards have generally been viewed as robust and “unbreakable” —- but that foundation is about to collapse. Affected product named by the advisory: NetScaler Console.

NetScaler Console
Jul 30, 2025
UnratedNetScaler Exploited CISA KEV

Advisory [CVE-2025-5777] Evaluating NetScaler logs for indicators of attempted exploitation of CVE-2025-5777

In our recent update to our announcement of CVE 2025-5777, we noted that on July 10, 2025, CISA added CVE-2025-5777 to its Known Exploited Vulnerabilities Catalog. To help customers assess their security posture, we’ve provided additional guidance below. Affected product named by the advisory: Gateway.

CVE-2025-5777
NetScaler Gateway
Jul 16, 2025
Critical9.8NetScaler Exploited CISA KEV

Critical [CVE-2023-3519] NetScaler ADC: Unauthenticated remote code execution

Unauthenticated remote code execution Affected products named by the advisory: NetScaler ADC; NetScaler Gateway.

CVE-2023-3519
NetScaler ADCNetScaler Gateway
Jul 19, 2023

← All vendors