Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Remote Code Execution Vulnerability Discovered in Citrix NetScaler ADC and Gateway

Citrix NetScaler ADC and Gateway appliances configured as SAML IdP/SP contain critical RCE flaws (CVE‑2026‑19490, CVE‑2026‑88771, CVE‑2026‑88779, CVE‑2026‑88772). The issue underscores the need for continuous vulnerability‑management and configuration‑hardening controls to maintain audit‑ready evidence.

LiveThreat™ Intelligence · 📅 October 09, 2026· 📰 cisecurity.org
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
4 recommended
📰
Source
cisecurity.org

Remote Code Execution Vulnerability Discovered in Citrix NetScaler ADC and Gateway

What Happened — A set of CVEs affecting Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway can allow an attacker to execute arbitrary code or trigger a denial‑of‑service condition when the appliances are configured as a SAML Identity Provider (IdP) or Service Provider (SP). The flaws affect multiple firmware versions (13.1‑64.23 through 14.1‑73.41) and are listed in CISA’s Known Exploited Vulnerabilities (KEV) catalog. No public exploitation has been reported yet, but related NetScaler CVEs have seen rapid weaponisation in the wild.

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for continuous vulnerability‑management controls that detect, prioritize, and remediate critical flaws before they can be chained into an exploit.
  • Highlights the importance of configuration‑hardening checks (e.g., ensuring SAML IdP/SP settings are reviewed) as part of a defensible audit trail.
  • Aligns with Verisq’s Control Mapping capability, which helps organizations map such findings to the Verisq Common Framework (VCF) and generate evidence for multiple compliance regimes.

Who Is Affected – Enterprises that deploy Citrix NetScaler ADC or Gateway for web‑application delivery, spanning government agencies, large‑scale businesses, and service providers across cloud‑infrastructure and networking segments.

Recommended Actions

  • Verify firmware versions against the affected range and apply Citrix‑provided patches immediately.
  • Conduct a configuration review of all NetScaler instances acting as SAML IdP/SP; disable unnecessary SAML roles.
  • Integrate the CVE identifiers into your vulnerability‑management toolchain and map the remediation steps to the “Vulnerability Management” control objective in the VCF.
  • Document the remediation process and retain evidence for audit readiness.

Technical Notes – The vulnerability is exploitable via crafted SAML authentication requests that lead to remote code execution or service crash. Affected firmware spans versions 13.1‑64.23 – 14.1‑73.41 (including FIPS builds). Related CVEs under active exploitation: CVE‑2026‑19490, CVE‑2026‑88771, CVE‑2026‑88779, CVE‑2026‑88772. Source: CIS Advisory 2026‑110

📰 Original Source
https://www.cisecurity.org/advisory/a-vulnerability-in-citrix-netscaler-adc-and-citrix-netscaler-gateway-could-allow-for-remote-code-execution_2026-110 ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →