Citrix has published a security bulletin detailing eight vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway. Two of these, CVE-2026-88771 and CVE-2026-88772, have been confirmed as being actively exploited.
The NCSC is working to understand the impact of these vulnerabilities on UK organisations.
- CVE-2026-88771: Improper input validation allowing an unauthenticated remote attacker to execute arbitrary commands.
- CVE-2026-88772: Improper restriction of operations within the bounds of a memory buffer, leading to remote code execution or denial of service.
- CVE-2026-88773: Inconsistent interpretation of HTTP requests (HTTP request/response smuggling), which may allow an attacker to manipulate or bypass security controls.
- CVE-2026-88774: Improper HTTP URL-based expression usage leading to a feature policy bypass.
- CVE-2026-88775: Memory overflow vulnerability that may result in unpredictable or erroneous behaviour, or denial of service.
- CVE-2026-88776: Memory overflow vulnerability that may result in unpredictable or erroneous behaviour, or denial of service.
- CVE-2026-88777: Memory overflow vulnerability that may result in unpredictable or erroneous behaviour, or denial of service.
- CVE-2026-88778: Predictable exact value vulnerability that may allow an attacker to influence integrity or availability.
