Citrix Product Security Update Advisory

Citrix Product Security Update Advisory

Overview

Citrix has released security updates to address vulnerabilities in NetScaler ADC and NetScaler Gateway. If you are using these products, you should update them to the latest version.

Affected Products and Scope of Impact

  • NetScaler ADC and NetScaler Gateway versions 13.1 Through 13.1-64.23.
  • NetScaler ADC and NetScaler Gateway versions 14.1 Through 14.1-73.37.
  • NetScaler ADC FIPS and NDcPP versions 13.1 Through 13.1-37.279.
  • NetScaler ADC FIPS versions 14.1 Through 14.1-73.37 FIPS.

Resolved Vulnerabilities

  • CVE-2026-88771: Pre-authentication remote code execution vulnerability in NetScaler ADC and NetScaler Gateway caused by improper input validation.
  • CVE-2026-88772: A remote code execution or denial-of-service vulnerability caused by a memory overflow.
  • CVE-2026-88773: An HTTP request smuggling vulnerability (an attack technique that causes HTTP requests to be misinterpreted).
  • CVE-2026-88774: A policy bypass vulnerability caused by improper use of HTTP URL-based expressions.
  • CVE-2026-88775, CVE-2026-88776, CVE-2026-88777: Denial-of-service vulnerabilities caused by memory overflows.
  • CVE-2026-88778: A vulnerability involving the prediction of TCP initial sequence numbers.

Recommendations

The latest Vulnerability Patches are available, and you should update to the following versions or higher, following the instructions on the reference site.

  • NetScaler ADC and NetScaler Gateway 13.1-64.23 Or later.
  • NetScaler ADC and NetScaler Gateway 14.1-73.37 Or later.
  • NetScaler ADC FIPS and NDcPP 13.1-37.279 Or later.
  • NetScaler ADC FIPS 14.1-73.37 FIPS or later.