Multiple vulnerabilities have been discovered in Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway).
Both flaws have been assigned a critical CVSS severity score of 9.5. A successful exploit of either vulnerability allows an unauthenticated, remote attacker to achieve remote code execution (RCE) on an affected system, effectively compromising the vulnerable gateway or ADC instance without needing login credentials.
These vulnerabilities were disclosed by Citrix as part of a larger security bulletin addressing a total of eight security flaws ranging from CVE-2026-88771 through CVE-2026-88778.
Affected Versions:
The following supported versions of Citrix NetScaler ADC and Citrix NetScaler Gateway are affected by the vulnerabilities:
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 BEFORE 14.1-73.37
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 BEFORE 13.1-64.23
Citrix NetScaler ADC FIPS BEFORE 14.1-73.37 FIPS
Citrix NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.279
Configure SPF, DKIM, and DMARC
Enable Continuous Access Evaluation (CAE) and Token Protection
Monitor and Audit Sign-In Logs
Implement Microsoft Defender for Office 365
Conduct User Awareness Training Focused on Device Code Phishing
Revoke and Rotate Tokens Immediately Upon Suspected Compromise
What Customers Should Do
Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed.
Cloud Software Group strongly urges affected customers of NetScaler ADC and NetScaler Gateway to install the relevant updated versions as soon as possible.
Helient strongly recommends that Administrators immediately assess their Citrix NetScaler deployments and upgrade to the recommended firmware as soon as possible. Should you require assistance please contact our industry-leading experts at service@helient.com.