Skip to content
arrow-alt-circle-up icon

Cyber Incident?

arrow-alt-circle-up icon

Call 00800 1744 0000

arrow-alt-circle-up icon

See all Threat Responses

Dutch follows English

Citrix disclosed eight critical and high-severity vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway [1]. Active exploitation of two vulnerabilities has already been observed.
Since multiple devices are already compromised, our advice is to isolate the device from the network, to prevent any further compromise. Please reach out to the Northwave CERT to discuss further steps. After investigation, the device can be patched to the latest version to remediate the vulnerabilities.
 
Description
Eight security vulnerabilities have been discovered in Citrix NetScaler ADC and NetScaler Gateway products:
  • CVE-2026-88771
  • CVE-2026-88772
  • CVE-2026-88773
  • CVE-2026-88774
  • CVE-2026-88775
  • CVE-2026-88776
  • CVE-2026-88777
  • CVE-2026-88778
Two of these vulnerabilities (CVE-2026-88771 and CVE-2026-88772) are already actively exploited in the wild. The vulnerabilities affect NetScaler versions 14.1 before 14.1-73.37 and 13.1 before 13.1-64.23, including FIPS editions. The issues range from remote code execution flaws to memory overflow vulnerabilities and HTTP request smuggling. Several vulnerabilities affect default configurations, meaning systems are vulnerable without any special features being enabled.
 
Impact
We estimate the impact of these vulnerabilities as high, as they enable a threat actor to gain unauthenticated remote code execution.
 
Risk
We estimate the risk of these vulnerabilities as high, because of the popularity of the NetScaler ADC and the
NetScaler Gateway, the internet facing nature,
and the widespread usage of these appliances. Citrix noted that the vulnerability CVE-2026-88771 and CVE-2026-88772 are actively exploited.
 
Mitigation
Customers using NetScaler ADC and NetScaler Gateway are strongly advised to contain the device from the network, as multiple devices have already been compromised. Please contact Northwave CERT to discuss how to proceed.
After making sure your device has not been compromised, install the relevant updated versions as soon as possible.
  • NetScaler ADC and NetScaler Gateway 14.1-73.37 and later releases
  • NetScaler ADC and NetScaler Gateway 13.1-64.23 and later releases of 13.1
  • Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
  • Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.279 and later releases of 13.1-FIPS and 13.1-NDcPP
What should you do?
Start with containing the device from the network. Afterwards, contact the Northwave CERT to help identification of compromise on your device. After making sure your device is not compromised install the latest versions of the firmware.
 
What will Northwave do?
Vulnerability Management customers will be informed in case vulnerable systems are detected in their infrastructure.
We will monitor any developments regarding this vulnerability. If new critical information about this threat arises, we will reach out to you. You can call us by phone or send us an email if you would like additional information.

E-mail: soc@northwave-cybersecurity.com

Do you have an incident right now? Call our Incident Response Team: 00800 1744 0000



Disclaimer applies, see below.

Sources

[1]: https://advisories.ncsc.nl/2026/ncsc-2026-0368.html

[2]:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX

[3]:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm


 

Citrix heeft acht kritieke en ernstige kwetsbaarheden openbaar gemaakt die van invloed zijn op Citrix NetScaler ADC en NetScaler Gateway [1]. Actieve uitbuiting van twee van deze kwetsbaarheden is reeds waargenomen.
Aangezien er reeds meerdere apparaten zijn gecompromitteerd, is het advies om het betreffende apparaat onmiddellijk van het netwerk te isoleren om verdere compromittering te voorkomen. Neem contact op met het Northwave CERT om de vervolgstappen te bespreken. Na afronding van het onderzoek kan het apparaat worden bijgewerkt naar de meest recente versie om de geïdentificeerde kwetsbaarheden te verhelpen.
 
Beschrijving
Eight beveiligingskwetsbaarheden zijn ontdekt in Citrix NetScaler ADC- en NetScaler Gateway-producten:
  • CVE-2026-88771
  • CVE-2026-88772
  • CVE-2026-88773
  • CVE-2026-88774
  • CVE-2026-88775
  • CVE-2026-88776
  • CVE-2026-88777
  • CVE-2026-88778
Twee van deze kwetsbaarheden (CVE-2026-88771 en CVE-2026-88772) worden momenteel al actief misbruikt in aanvallen. De kwetsbaarheden treffen NetScaler-versies 14.1 vóór 14.1-73.37 en 13.1 vóór 13.1-64.23, inclusief de FIPS-edities.
 
De kwetsbaarheden variëren van kwetsbaarheden voor remote code execution (RCE) tot geheugenoverloopkwetsbaarheden en HTTP request smuggling. Meerdere kwetsbaarheden zijn aanwezig in de standaardconfiguratie van NetScaler, waardoor systemen kwetsbaar zijn zonder dat specifieke functies of aanvullende configuraties zijn ingeschakeld.
 
Impact
Wij schatten de impact van deze kwetsbaarheden als hoog in, omdat ze een kwaadwillende in staat stellen om ongeauthenticeerde remote code execution uit te voeren.
 
Risico
Wij schatten het risico als hoog in, vanwege de populariteit van NetScaler ADC en NetScaler Gateway, de bereikbaarheid vanaf het internet, en het brede gebruik van deze apparaten. Citrix heeft aangegeven dat CVE-2025-7775 actief wordt misbruikt.
 
Mitigatie
Klanten die gebruikmaken van NetScaler ADC en NetScaler Gateway wordt met klem geadviseerd het apparaat van het netwerk te isoleren, aangezien reeds meerdere systemen zijn gecompromitteerd. Neem contact op met het Northwave CERT om de vervolgstappen en de verdere aanpak te bespreken.
 
Nadat is vastgesteld dat het apparaat niet is gecompromitteerd, adviseren wij om zo spoedig mogelijk de relevante beveiligingsupdates en de meest recente beschikbare versie te installeren om de kwetsbaarheden te verhelpen.
  • NetScaler ADC and NetScaler Gateway 14.1-73.37 en latere versies
  • NetScaler ADC and NetScaler Gateway 13.1-64.23 en latere versies van 13.1
  • Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS en latere versies van 14.1-FIPS
  • Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.279 en latere versies van 13.1-FIPS and 13.1-NDcPP
 
Wat moet u doen?
Begin met het isoleren van het apparaat van het netwerk om verdere compromittering te voorkomen. Neem vervolgens contact op met het Northwave CERT voor ondersteuning bij het vaststellen of het apparaat is gecompromitteerd.
Nadat is bevestigd dat het apparaat niet is gecompromitteerd, adviseren wij om zo snel mogelijk de meest recente firmwareversie te installeren om de kwetsbaarheden te verhelpen.
 
Wat doet Northwave?
Klanten van Vulnerability Management worden geïnformeerd als kwetsbare systemen in hun infrastructuur worden gedetecteerd.
Wij blijven de ontwikkelingen rondom deze kwetsbaarheid volgen. Als er nieuwe kritieke informatie beschikbaar komt, nemen wij contact met u op. U kunt ons bellen of e-mailen als u aanvullende informatie wenst.
 
 

E-mail: soc@northwave-cybersecurity.com
Heeft u nu een incident? Bel ons Incident Response Team: 00800 1744 0000


Disclaimer is van toepassing, zie onder.

Bronnen

[1]: https://advisories.ncsc.nl/2026/ncsc-2026-0368.html

[2]: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX

[3]:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm

 

Disclaimer

Northwave has made every effort to make this information accurate and reliable. However, the information provided is without warranty of any kind and its use is at the sole risk of the user. Northwave does not accept any responsibility or liability for the accuracy, content, completeness, legality or reliability of the information provided. We will not be liable for any loss or damage of whatever nature, direct or indirect, consequential or other, whether arising in contract, tort or otherwise, which may arise as a result of your use of, or inability to use, this information or any additional information provided by us in direct or indirect relation to the information provided here.
.