Arctic Wolf Security Bulletin
Arctic Wolf Security Bulletin

Critical Citrix NetScaler ADC and Citrix NetScaler Gateway Vulnerabilities

Arctic Wolf Security Bulletin
6 min read

Threat Summary

On September 27th 2026, Citrix disclosed multiple vulnerabilities affecting NetScaler ADC and NetScaler Gateway. Arctic Wolf tracking indicates that CVE-2026-88771 and CVE-2026-88772 have been exploited in attacks against NetScaler devices as zero-days. Additional CVEs are also disclosed in the Citrix Security Bulletin.

CVE-2026-88771 is an unauthenticated remote code execution vulnerability caused by improper input validation that can allow arbitrary command execution. Arctic Wolf tracking indicates this vulnerability affects NetScaler ADC and NetScaler Gateway deployments without requiring an additional feature to be enabled.

CVE-2026-88772 is a memory overflow vulnerability that can lead to remote code execution or denial of service. Arctic Wolf tracking indicates this vulnerability is exploitable when DTLS is enabled, which is the default configuration for VPN servers.

Both CVE-2026-88771 and CVE-2026-88772 were added to CISA Known Exploited Vulnerabilities (KEV) catalog on September 27th, 2026, with a remediation due date of September 30th, 2026. Successful exploitation of these vulnerabilities could allow attackers to gain a foothold on internet-facing NetScaler appliances, execute commands, disrupt gateway availability, and potentially use compromised perimeter infrastructure to support credential theft, lateral movement, or further internal compromise. Citrix has confirmed exploitation on unmitigated deployments and urged affected customers to install fixed releases.

Details

CVE-ID Description Pre-conditions Impacted Versions Fixed Versions CWE CVSSv4
CVE-2026-88771 A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands. All NetScaler ADC and NetScaler Gateway deployments. Default configuration; no additional feature required. NetScaler ADC and Gateway 14.1 before 14.1-73.37; 13.1 before 13.1-64.23; NetScaler ADC FIPS before 14.1-73.37 FIPS; NetScaler ADC FIPS and NDcPP before 13.1-37.279. NetScaler ADC and Gateway 14.1-73.37 and later; 13.1-64.23 and later; NetScaler ADC 14.1-73.37 FIPS and later; NetScaler ADC 13.1-37.279 FIPS/NDcPP and later. CWE-20: Improper Input Validation (CISA KEV lists CWE-119) CVSS v4.0 Base Score: 9.5
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVE-2026-88772 Memory overflow vulnerability leading to remote code execution or denial of service. DTLS configuration enabled on NetScaler ADC or NetScaler Gateway. DTLS is enabled by default on VPN vServer. NetScaler ADC and Gateway 14.1 before 14.1-73.37; 13.1 before 13.1-64.23; NetScaler ADC FIPS before 14.1-73.37 FIPS; NetScaler ADC FIPS and NDcPP before 13.1-37.279. NetScaler ADC and Gateway 14.1-73.37 and later; 13.1-64.23 and later; NetScaler ADC 14.1-73.37 FIPS and later; NetScaler ADC 13.1-37.279 FIPS/NDcPP and later. CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CVSS v4.0 Base Score: 9.5
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Recommendations

IMMEDIATE ACTIONS:

  • Upgrade affected Citrix NetScaler ADC and NetScaler Gateway appliances to the applicable fixed releases provided in Citrix security bulletin CTX697096 as soon as possible.
    • Fixed releases include NetScaler ADC/Gateway 14.1-73.37 and later, 13.1-64.23 and later, and 13.1-37.279 for specified FIPS/NDcPP branches.
    • Customers should validate the exact fixed version for their product branch against Citrix CTX697096 before deployment.
  • Prioritize internet-facing appliances, VPN virtual servers, Gateway deployments, and systems with DTLS enabled.
  • If exploitation is suspected or patching was delayed on an internet-facing appliance, preserve logs and appliance state where operationally feasible before making major changes, and begin incident response triage. If you believe you are compromised, reach out to the Arctic Wolf Security Operations Center (SOC) or Arctic Wolf Incident Response.

HARDENING:

  • Terminate active AAA, VPN, ICA, RDP, and other gateway sessions after patching, to reduce the risk of continued use of compromised sessions.
  • Review NetScaler configuration for unexpected users, authentication changes, route or policy changes, uploaded files, web shells, or other persistence mechanisms.
  • Restrict administrative and management interfaces to trusted management networks only; do not expose NSIP, SNIP, or management services directly to the internet.
  • Limit access to Gateway and VPN services using IP allowlists, VPN segmentation, and other network controls where feasible.
  • Review authentication, VPN, and system logs for suspicious access, command execution, crashes, configuration changes, or anomalous DTLS/VPN activity.
  • Rotate credentials, session secrets, API keys, and certificates associated with affected appliances if compromise is suspected.

Temporary Workarounds

Citrix tracking referenced by Arctic Wolf does not identify a vendor-supported workaround that fully mitigates these vulnerabilities. If immediate patching cannot be completed, customers should reduce exposure by restricting access to NetScaler Gateway, VPN, and management interfaces to trusted source networks only, disabling unnecessary externally exposed services, and prioritizing emergency patch windows for internet-facing appliances.

These steps should be treated only as temporary risk-reduction measures and are not a substitute for installing Citrix fixed releases.

References

 

Share this post: