Executive Summary
Facts Only
* CVE-2026-88771 is an improper input validation flaw allowing unauthenticated attackers to run arbitrary commands on all NetScaler ADC and Gateway deployments.
* CVE-2026-88772 is a memory overflow that can lead to remote code execution or denial-of-service when DTLS is enabled on the appliances.
* Exploits of these two flaws were observed on unmitigated NetScaler deployments.
* The fixes are available for NetScaler ADC and Gateway versions including 14.1-73.37 and later, and specific 13.1 releases.
* The bulletin does not provide a workaround or indicators of compromise.
* Six other flaws were also identified: CVE-2026-88773 (HTTP request smuggling), CVE-2026-88774 (policy bypass), CVE-2026-88775 (memory overflow in specific virtual servers), CVE-2026-88776 (memory overflow in Oracle load balancing), CVE-2026-88777 (memory overflow with specific protocols enabled), and CVE-2026-88778 (TCP ISN prediction flaw).
* Appliances on builds 14.1-73.32 and 13.1-63.21 fall within the affected range.
Full Take
From the original · The Hacker News
Two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway that allow remote code execution have been exploited in the wild, Citrix confirmed on September 27. It released fixes for both, along with six other flaws.Read the full story at thehackernews.com
Sentinel — Human
The text reads like a factual summary synthesized from multiple real-world security reports, showing evidence of human aggregation and contextual framing rather than pure generative output.
