Multiple Critical RCE Vulnerabilities Discovered in Citrix NetScaler ADC and Gateway (CVE‑2026‑88771/88772)
What Happened — CIS disclosed six vulnerabilities (CVE‑2026‑88771‑88776) in NetScaler ADC and NetScaler Gateway, the most severe of which enable unauthenticated remote code execution. Exploitation is already observed in the wild. Affected versions are ADC/Gateway 14.1 < 14.1‑73.37 and 13.1 < 13.1‑64.23 (including FIPS builds).
Why It Matters for Trust & Control Assurance —
- Continuous vulnerability monitoring and timely patching are core control‑assurance activities that prevent unauthorized code execution.
- Documented remediation provides defensible evidence for audits across multiple frameworks.
- Mapping the fix to a control‑mapping capability demonstrates due‑diligence to regulators and partners.
Who Is Affected — Large and medium enterprises, government agencies, and service providers that deploy NetScaler ADC or Gateway for application delivery or remote access.
Recommended Actions — Verify your NetScaler version, apply the Citrix patches immediately, update your asset inventory, and record remediation evidence in your control‑assurance platform. Source: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-netscaler-adc-and-netscaler-gateway-could-allow-for-remote-code-execution_2026-103
Technical Notes — The RCE stems from improper input validation (CVE‑2026‑88771) and memory overflow in DTLS‑enabled configurations (CVE‑2026‑88772). Additional issues include HTTP request smuggling and policy bypasses. Source: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-netscaler-adc-and-netscaler-gateway-could-allow-for-remote-code-execution_2026-103