NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Citrix Patches Actively Exploited NetScaler ADC & NetScaler Gateway Vulnerabilities

Two critical zero-day vulnerabilities in Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) are under active exploitation and require immediate patching. The vulnerabilities are part of a batch of eight flaws detailed in a Citrix security bulletin issued on September 27, 2026. Six of the vulnerabilities are rated high severity, with CVSS v4.0 severity scores between 7.0 and 8.8. The critical flaws have a CVSS base score of 9.5.

  • CVE-2026-88771 is a critical remote code execution vulnerability due to improper input validation. Successful exploitation can allow an attacker to execute arbitrary commands. The vulnerability affects all Citrix NetScaler ADC and Citrix NetScaler Gateway deployments.
  • CVE-2026-88772 is a critical memory overflow vulnerability that can lead to remote code execution or denial of service. The vulnerability is present if DTLS configuration is enabled on NetScaler ADC or NetScaler Gateway. It is enabled by default on VPN vServer.

The six remaining vulnerabilities are as follows:

  • CVE-2026-88775; CVE-2026-88776 & CVE-2026-88777 – (CVSS 8.8) – Memory overflow vulnerabilities leading to unpredictable or erroneous behavior or denial of service.
  • CVE-2026-88778 (CVSS 8.8) – TCP Initial Sequence Number (ISN) prediction flaw.
  • CVE-2026-88774 (CVSS 7.0) – Feature policy bypass (improper HTTP URL-based expression usage).

The vulnerabilities affect the following Citrix NetScaler ADC and Citrix NetScaler Gateway versions:

  • Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 BEFORE 14.1-73.37
  • Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 BEFORE 13.1-64.23
  • Citrix NetScaler ADC FIPS BEFORE 14.1-73.37 FIPS
  • Citrix NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.279

Software updates have already been applied to fix the vulnerabilities in Citrix-managed cloud services and Citrix-managed Adaptive Authentication. Patches need to be applied to fix the vulnerabilities in customer-managed Citrix NetScaler ADC and Citrix NetScaler Gateway deployments. Since two of the vulnerabilities are under active exploitation, customers are urged to upgrade as soon as possible. The extent to which the flaws are being exploited has not been disclosed.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The updated versions with the vulnerabilities fixed are:

  • Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later releases
  • Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
  • Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
  • Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.279 and later releases of 13.1-FIPS and 13.1-NDcPP

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist