<img height="1" width="1" style="display:none" src="https://www.facebook.com/tr?id=1741336722824154&amp;ev=PageView&amp;noscript=1">
Skip to the main content.
Print Solutions

Benefit from smart ideas, lower costs, greater productivity. Choose from award-winning printers, software solutions and consumables

Insights

We combine professional expertise with a human kind of partnership

Support Centre

Get the right help and advice, register a product and see why our commitment to you matters.

Kyocera_lead_Huon_IT_co branding_RGB

URGENT Security Advisory: Citrix NetScaler ADC & Gateway – Actively Exploited Vulnerabilities

URGENT Security Advisory: Citrix NetScaler ADC & Gateway – Actively Exploited Vulnerabilities

We'd like to make you aware of critical security vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway. Citrix has confirmed that two of them are being actively exploited in the wild. Every customer-managed NetScaler is affected, including those running the default configuration, so we recommend treating this as an emergency rather than routine patching.

Summary of the Vulnerabilities:
  • CVE-2026-88771 (CVSS 9.5, Critical): An input validation flaw that lets an unauthenticated attacker run arbitrary commands on the appliance. It affects all NetScaler ADC and Gateway deployments, with no extra feature or configuration required. Actively exploited.

  • CVE-2026-88772 (CVSS 9.5, Critical): A memory overflow that can lead to remote code execution or denial of service on appliances with DTLS enabled. DTLS is enabled by default on NetScaler Gateway (VPN) virtual servers. Actively exploited.

  • Six further vulnerabilities (CVE-2026-88773 to CVE-2026-88778, CVSS 7.0 to 9.3) are fixed in the same update. They include HTTP request smuggling, a policy bypass, several denial-of-service flaws, and a TCP sequence number prediction issue. Whether these apply depends on how your appliance is configured.

  •  The full Citrix advisory can be found here. 

 


What's Affected:

  • NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37

  • NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23

  • NetScaler ADC 14.1-FIPS before 14.1-73.37 FIPS

  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP before 13.1-37.279

  • Secure Private Access Hybrid deployments that use NetScaler instances.

  • Important: appliances patched in August (14.1-73.32 or 13.1-63.21) are still vulnerable and must be updated again.

  • Citrix-managed cloud services and Citrix-managed Adaptive Authentication are being updated by Citrix and need no action.

 


Recommended Action:
  1. Check for signs of compromise first. These flaws were exploited before a patch existed, so review your appliances using the indicators of compromise Citrix has published (see the advisory and NetScaler Console). If you suspect a compromise, preserve evidence before updating, because patching can remove forensic traces.

  2. Update immediately. Upgrade to 14.1-73.37, 13.1-64.23 or the matching FIPS/NDcPP build, or later. Include any HA partners, DR appliances and lab or test units.

  3. Apply the TCP configuration change. After upgrading, enable Enhanced ISN Generation as described in the Citrix advisory, to address CVE-2026-88778.

  4. Upgrade unsupported versions. If you're on an older, end-of-life version such as 13.0 or earlier, move to a supported version (13.1 or 14.1) as soon as possible.

Because these vulnerabilities are already being exploited and NetScaler appliances usually sit at the edge of your network, unpatched devices are at real and ongoing risk. Please act on this promptly.

 

At Kyocera, we understand the critical importance of securing your infrastructure. If you need assistance in reviewing or resolving this issue, please don't hesitate to contact our team. You can reach our helpdesk at help@dau.kyocera.com