Desert Forge IT — Arizona IT · Field-tested tools & guidesFree consult →

Citrix NetScaler 2026: Five Exploited CVEs Including Unauthenticated RCE (CVE-2026-88771, 88772, 19490)

Critical CVE-2026-88771, CVE-2026-88772, CVE-2026-88779, CVE-2026-19490, CVE-2026-8452 — NetScaler ADC and Gateway have had five actively exploited vulnerabilities since August 2026, including unauthenticated command execution and an auth bypass. Fixed builds 14.1-73.41 and 13.1-64.28, and what to check after patching.

Published 2026-10-08 · Last updated 2026-10-08

TL;DR: If your organisation uses NetScaler ADC or NetScaler Gateway (formerly Citrix ADC/Gateway) for remote access, five bugs have been exploited since August, and two of them allow unauthenticated remote code execution (CVSS 9.5). Upgrade to 14.1-73.41 or 13.1-64.28 (the newest fix covers all five), then run Citrix's IOC checks and kill active sessions.

CVE-2026-88771Input validation → unauthenticated command execution. CVSS 4.0: 9.5. KEV 2026-09-27
CVE-2026-88772Memory overflow → RCE or DoS. CVSS 4.0: 9.5. KEV 2026-09-27
CVE-2026-19490Authentication bypass. CVSS 4.0: 9.3. KEV 2026-09-09
CVE-2026-88779Memory overflow → DoS. CVSS 4.0: 8.7. KEV 2026-10-04
CVE-2026-8452Memory overflow → DoS when configured as Gateway/AAA. CVSS 4.0: 8.8. KEV 2026-08-26
Fixed in14.1-73.41 and 13.1-64.28 (FIPS: 14.1-73.41 FIPS, 13.1-37.282) cover all five

What’s going on

NetScaler appliances sit at the edge of the network handling VPN, Citrix Workspace access and load balancing, so they’re exposed to the internet by design and are one of the most-targeted products there is. Since August 2026, CISA has added five NetScaler CVEs to its exploited list, the last on October 4:

  • CVE-2026-88771: improper input validation lets an unauthenticated attacker run arbitrary commands.
  • CVE-2026-88772: a memory overflow that can lead to code execution.
  • CVE-2026-19490: an authentication bypass through an alternate path.
  • CVE-2026-88779 and CVE-2026-8452: memory overflows causing denial of service (8452 only when configured as a Gateway: SSL VPN, ICA Proxy, CVPN, RDP Proxy, or AAA virtual server).

CISA requires forensic triage for 88771/88772, meaning it expects that some appliances were compromised before they were patched.

Am I affected?

On the appliance CLI run show ns version, or check the build on the GUI dashboard.

BranchUpgrade to at least
14.114.1-73.41
13.113.1-64.28
14.1 FIPS14.1-73.41 FIPS
13.1 FIPS / NDcPP13.1-37.282

Versions 13.0 and 12.1 are end of life. They get no fixes and need replacing or upgrading to a supported branch.

Citrix-managed cloud services are patched by Citrix; this is about appliances you run yourself (physical, VPX, or in your own cloud account).

How to patch

  1. Back up the configuration (save ns config, then download /nsconfig/ns.conf).
  2. Upgrade to the build above. For an HA pair, upgrade the secondary, fail over, then upgrade the other.
  3. After upgrading, terminate existing sessions, so a stolen session token stops working:
    kill icaconnection -all
    kill pcoipConnection -all
    kill aaa session -all
    kill rdp connection -all
    clear lb persistentSessions

Check for compromise

  • Run the indicators-of-compromise checks Citrix published with the bulletins in the NetScaler console.
  • Look for unexpected files (especially .php, .xhtml, .sh) under /var/netscaler/logon/, /var/vpn/ and /netscaler/ns_gui/, and for unknown cron jobs.
  • Review admin accounts and recent configuration changes.
  • If you find anything: rebuild the appliance from a clean image, rotate every credential and certificate it held, and treat users who logged in through it as potentially exposed.

Sources

← Back to Knowledge Base

Want this handled for you?

Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.

Get a free security check →  ·  More security advisories