Critical CVE-2026-88771, CVE-2026-88772, CVE-2026-88779, CVE-2026-19490, CVE-2026-8452 — NetScaler ADC and Gateway have had five actively exploited vulnerabilities since August 2026, including unauthenticated command execution and an auth bypass. Fixed builds 14.1-73.41 and 13.1-64.28, and what to check after patching.
Published 2026-10-08 · Last updated 2026-10-08
TL;DR: If your organisation uses NetScaler ADC or NetScaler Gateway (formerly Citrix ADC/Gateway) for remote access, five bugs have been exploited since August, and two of them allow unauthenticated remote code execution (CVSS 9.5). Upgrade to 14.1-73.41 or 13.1-64.28 (the newest fix covers all five), then run Citrix's IOC checks and kill active sessions.
| CVE-2026-88771 | Input validation → unauthenticated command execution. CVSS 4.0: 9.5. KEV 2026-09-27 |
|---|---|
| CVE-2026-88772 | Memory overflow → RCE or DoS. CVSS 4.0: 9.5. KEV 2026-09-27 |
| CVE-2026-19490 | Authentication bypass. CVSS 4.0: 9.3. KEV 2026-09-09 |
| CVE-2026-88779 | Memory overflow → DoS. CVSS 4.0: 8.7. KEV 2026-10-04 |
| CVE-2026-8452 | Memory overflow → DoS when configured as Gateway/AAA. CVSS 4.0: 8.8. KEV 2026-08-26 |
| Fixed in | 14.1-73.41 and 13.1-64.28 (FIPS: 14.1-73.41 FIPS, 13.1-37.282) cover all five |
NetScaler appliances sit at the edge of the network handling VPN, Citrix Workspace access and load balancing, so they’re exposed to the internet by design and are one of the most-targeted products there is. Since August 2026, CISA has added five NetScaler CVEs to its exploited list, the last on October 4:
CISA requires forensic triage for 88771/88772, meaning it expects that some appliances were compromised before they were patched.
On the appliance CLI run show ns version, or check the build on the GUI dashboard.
| Branch | Upgrade to at least |
|---|---|
| 14.1 | 14.1-73.41 |
| 13.1 | 13.1-64.28 |
| 14.1 FIPS | 14.1-73.41 FIPS |
| 13.1 FIPS / NDcPP | 13.1-37.282 |
Versions 13.0 and 12.1 are end of life. They get no fixes and need replacing or upgrading to a supported branch.
Citrix-managed cloud services are patched by Citrix; this is about appliances you run yourself (physical, VPX, or in your own cloud account).
save ns config, then download /nsconfig/ns.conf).kill icaconnection -all
kill pcoipConnection -all
kill aaa session -all
kill rdp connection -all
clear lb persistentSessions.php, .xhtml, .sh) under /var/netscaler/logon/, /var/vpn/ and /netscaler/ns_gui/, and for unknown cron jobs.Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.