{"id":16765,"date":"2026-09-28T10:03:06","date_gmt":"2026-09-28T10:03:06","guid":{"rendered":"https:\/\/newestek.com\/?p=16765"},"modified":"2026-09-28T10:03:06","modified_gmt":"2026-09-28T10:03:06","slug":"netscaler-admins-told-to-patch-critical-zero-days-in-adc-and-gateway-now","status":"publish","type":"post","link":"https:\/\/newestek.com\/?p=16765","title":{"rendered":"NetScaler admins told to patch critical zero-days in ADC and Gateway now"},"content":{"rendered":"<div>\n<div id=\"remove_no_follow\">\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<section class=\"wp-block-bigbite-multi-title\">\n<div class=\"container\"><\/div>\n<\/section>\n<p class=\"wp-block-paragraph\">Citrix NetScaler ADC and NetScaler Gateway users should take their systems offline and patch them immediately, they were told over the weekend, as news emerged of two critical unauthenticated remote code execution <a href=\"https:\/\/www.csoonline.com\/article\/4155155\/the-zero-day-timeline-just-collapsed-heres-what-security-leaders-do-next.html\">zero-day<\/a> vulnerabilities in the products under active attack.<\/p>\n<p class=\"wp-block-paragraph\">\u201c<a href=\"https:\/\/www.linkedin.com\/feed\/update\/urn:li:activity:7509660925809819649\" target=\"_blank\" rel=\"noreferrer noopener\">Monday will be too late<\/a>,\u201d watchtower CEO <a href=\"https:\/\/www.linkedin.com\/in\/benjamin-harris-sg\" target=\"_blank\" rel=\"noreferrer noopener\">Benjamin Harris<\/a> wrote in a LinkedIn post on Sunday.<\/p>\n<p class=\"wp-block-paragraph\">Citrix subsequently confirmed the two remotely exploitable vulnerabilities were under attack, and released fixes for both. Affected customers should install the patched versions \u201cas soon as possible,\u201d <a href=\"https:\/\/community.citrix.com\/techzone-blogs\/110_security-updates\/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778\/\" target=\"_blank\" rel=\"noreferrer noopener\">Citrix wrote in an advisory<\/a> issued later on Sunday.<\/p>\n<p class=\"wp-block-paragraph\">NetScaler appliances are an important part of many enterprise networks, providing VPN and remote access, load balancing and other application delivery services.<\/p>\n<p class=\"wp-block-paragraph\"><a><\/a>Citrix is tracking the two exploited vulnerabilities as CVE-2026-88771 and CVE-2026-88772. It has released fixes in NetScaler ADC and Gateway 14.1-73.37 and later, 13.1-64.23 and later, with corresponding FIPS and NDcPP builds also available.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-88771\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2026-88771<\/a> is a critical remote code execution (RCE) vulnerability in Netscaler ADC and Netscaler Gateway caused by improper input validation. With a CVSS rating of 9.5, it enables unauthenticated attackers to execute arbitrary commands on the appliance.<\/p>\n<p class=\"wp-block-paragraph\">Citrix said all NetScaler ADC and NetScaler Gateway deployments are affected, including default configurations, with no additional feature required to meet the vulnerability\u2019s precondition. It\u2019s barely <a href=\"https:\/\/www.csoonline.com\/article\/4212082\/citrix-issues-critical-security-updates-for-its-netscaler-devices.html\">a month since Citrix patched two other critical security holes<\/a> in the appliances<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-88772\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2026-88772<\/a> also has a CVSS score of 9.5; it involves a memory overflow that can result in remote code execution or denial of service. It requires Datagram Transport Layer Security (DTLS) to be enabled, but Citrix notes that is the case by default on VPN virtual servers, making the condition relevant to many NetScaler Gateway deployments.<\/p>\n<p class=\"wp-block-paragraph\">Citrix said exploitation of both vulnerabilities had been observed on unmitigated deployments, while watchTowr reported the vulnerabilities had been <a href=\"https:\/\/watchtowr.com\/intelligence\/citrix-netscaler-adc-citrix-netscaler-gateway-remote-code-execution-cve-2026-88771\/\" target=\"_blank\" rel=\"noreferrer noopener\">exploited before fixes became available<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">The US Cybersecurity and Infrastructure Security Agency (CISA) added both to its Known Exploited Vulnerabilities (KEV) catalog on Sunday.<\/p>\n<h2 class=\"wp-block-heading\"><a><\/a>Six more Netscaler bugs<\/h2>\n<p class=\"wp-block-paragraph\">Citrix addressed six other vulnerabilities in Sunday\u2019s security update, although it said their exposure depends on specific configurations.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-88773\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2026-88773<\/a>, rated 9.3, is an HTTP request-smuggling vulnerability affecting deployments using HTTP or SSL virtual servers. <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-88774\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2026-88774<\/a>, rated 7.0, is a feature policy bypass related to HTTP URL handling; Citrix noted that URL normalization can prevent WAF and security rules from being bypassed.<\/p>\n<p class=\"wp-block-paragraph\">Three further memory-overflow vulnerabilities \u2014 <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-88775\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2026-88775<\/a>, <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-88776\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2026-88776<\/a> and <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-88777\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2026-88777<\/a> \u2014 are each rated 8.8 and can cause unpredictable behavior or denial of service under their respective configurations.<\/p>\n<p class=\"wp-block-paragraph\">The final flaw, <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-88778\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2026-88778<\/a>, is also rated 8.8 and involves TCP Initial Sequence Number Prediction which, Citrix said, can be handled by enabling Enhanced ISN Generation.<\/p>\n<p class=\"wp-block-paragraph\">Citrix said the advisory applies to customer-managed NetScaler appliances and recommended upgrading affected deployments immediately. The company also made generic indicators of compromise (IOCs) available through NetScaler Console to help customers assess whether their appliances may have been affected.<\/p>\n<p class=\"wp-block-paragraph\"><em>This article first appeared on <\/em><a href=\"https:\/\/www.networkworld.com\/article\/4227476\/netscaler-admins-told-to-patch-critical-zero-days-in-adc-and-gateway-now.html\">Network World<\/a><em>.<\/em><\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Citrix NetScaler ADC and NetScaler Gateway users should take their systems offline and patch them immediately, they were told over the weekend, as news emerged of two critical unauthenticated remote code execution zero-day vulnerabilities in the products under active attack. \u201cMonday will be too late,\u201d watchtower CEO Benjamin Harris wrote in a LinkedIn post on Sunday. Citrix subsequently confirmed the two remotely exploitable vulnerabilities were&#8230; <\/p>\n<p class=\"more\"><a class=\"more-link\" href=\"https:\/\/newestek.com\/?p=16765\">Read More<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-16765","post","type-post","status-publish","format-standard","hentry","category-uncategorized","is-cat-link-borders-light is-cat-link-rounded"],"_links":{"self":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts\/16765","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=16765"}],"version-history":[{"count":0,"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts\/16765\/revisions"}],"wp:attachment":[{"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=16765"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=16765"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=16765"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}