Utopia Tech
Healthcare2 min read

Citrix Patches Actively Exploited NetScaler ADC & NetScaler Gateway Vulnerabilities

Two critical zero-day vulnerabilities in Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) are under active exploitation and require immediate patching. The vulnerabilities are part of a batch of eight flaws detailed in a Citrix security bulletin issued on September 27, 2026. Six of the vulnerabilities are rated high severity, wit

UT

Utopia Tech

September 29, 2026 · 2 min read

Share

Two critical zero-day vulnerabilities in Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) are under active exploitation and require immediate patching. The vulnerabilities are part of a batch of eight flaws detailed in a Citrix security bulletin issued on September 27, 2026. Six of the vulnerabilities are rated high severity, with CVSS v4.

0 severity scores between 7. 0 and 8. 8.

The critical flaws have a CVSS base score of 9. 5. CVE-2026-88771 is a critical remote code execution vulnerability due to improper input validation.

Successful exploitation can allow an attacker to execute arbitrary commands. The vulnerability affects all Citrix NetScaler ADC and Citrix NetScaler Gateway deployments. CVE-2026-88772 is a critical memory overflow vulnerability that can lead to remote code execution or denial of service.

The vulnerability is present if DTLS configuration is enabled on NetScaler ADC or NetScaler Gateway. It is enabled by default on VPN vServer. The six remaining vulnerabilities are as follows: CVE-2026-88775; CVE-2026-88776 & CVE-2026-88777 – (CVSS 8.

  1. – Memory overflow vulnerabilities leading to unpredictable or erroneous behavior or denial of service. CVE-2026-88778 (CVSS 8. 8) – TCP Initial Sequence Number (ISN) prediction flaw.

CVE-2026-88774 (CVSS 7. 0) – Feature policy bypass (improper HTTP URL-based expression usage). The vulnerabilities affect the following Citrix NetScaler ADC and Citrix NetScaler Gateway versions: Citrix NetScaler ADC and Citrix NetScaler Gateway 14.

1 BEFORE 14. 1-73. 37 Citrix NetScaler ADC and Citrix NetScaler Gateway 13.

1 BEFORE 13. 1-64. 23 Citrix NetScaler ADC FIPS BEFORE 14.

1-73. 37 FIPS Citrix NetScaler ADC FIPS and NDcPP BEFORE 13. 1-37.

279 Software updates have already been applied to fix the vulnerabilities in Citrix-managed cloud services and Citrix-managed Adaptive Authentication. Patches need to be applied to fix the vulnerabilities in customer-managed Citrix NetScaler ADC and Citrix NetScaler Gateway deployments. Since two of the vulnerabilities are under active exploitation, customers are urged to upgrade as soon as possible.

The extent to which the flaws are being exploited has not been disclosed. Get The FREE HIPAA Compliance Checklist Immediate Delivery of Checklist Link To Your Email Address Please enable JavaScript in your browser to complete this form. Business Email * Name * First Last Number * Company Name * Get Free Checklist Please Enter Correct Email Address Your Privacy Respected HIPAA Journal Privacy Policy The updated versions with the vulnerabilities fixed are: Citrix NetScaler ADC and Citrix NetScaler Gateway 14.

1-73. 37 and later releases Citrix NetScaler ADC and Citrix NetScaler Gateway 13. 1-64.

23 and later releases of 13. 1 Citrix NetScaler ADC 14. 1-FIPS 14.

1-73. 37 FIPS and later releases of 14. 1-FIPS Citrix NetScaler ADC 13.

1-FIPS and 13. 1-NDcPP 13. 1.

  1. 279 and later releases of 13. 1-FIPS and 13.

1-NDcPP The post Citrix Patches Actively Exploited NetScaler ADC & NetScaler Gateway Vulnerabilities appeared first on The HIPAA Journal .

Originally published at hipaajournal.com

Share
▸ Want a deeper look?

Talk to an architect about applying this to your stack.

60-minute technical evaluation, no obligation. We'll map the ideas in this article to your environment.

Skip to main contentCitrix Patches Actively Exploited NetScaler ADC & NetScaler Gateway Vulnerabilities · Utopia Tech