Sceawere
Vulnerability Detail
CVE-2026-88772UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Citrix ADC/Gateway RCE/DoS Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.1
- Creation Date
- 23h ago
- Vendor
- Citrix NetScaler
- Product
- ADC
- Attack Type
- N/A
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.1",
"pubDate": "2026-09-27T17:16:56.390Z",
"pubdate": "2026-09-27T17:16:56.390Z",
"executiveSummary": "This vulnerability impacts Citrix NetScaler ADC and Citrix NetScaler Gateway, enabling unauthenticated remote attackers to achieve Remote Code Execution (RCE) or initiate a Denial of Service (DoS) condition. The flaw resides in the core management and gateway infrastructure of the affected products, presenting a critical risk to organizational perimeter security. Exploitation allows for the complete compromise of the appliance, potentially granting an attacker persistent access to the underlying operating system. The vulnerability necessitates immediate remediation as it bypasses standard security controls, allowing unauthorized code execution without prior authentication or user interaction. Affected products include Citrix NetScaler ADC and Gateway versions prior to 14.1-73.37 and 13.1-64.23, as well as specific FIPS and NDcPP-compliant builds. Given the exposure of these appliances in internet-facing configurations, the risk of automated exploitation by malicious actors is significant, potentially leading to unauthorized data exfiltration, lateral movement, or total service disruption.",
"technicalDetails": "The vulnerability manifests within the Citrix NetScaler ADC and Gateway architecture, involving a flaw in how the system processes incoming network requests at the application level. The issue stems from insufficient input validation and memory safety mechanisms, which allows an attacker to trigger either arbitrary code execution or a crash of the affected process.\nThe exploitation flow typically begins with an attacker sending a maliciously crafted payload to the exposed network port of the Citrix appliance. Because the vulnerability affects the gateway or ADC management stack, the attacker does not require valid credentials to deliver the initial exploit vector. Upon reaching the vulnerable component, the payload exploits memory corruption, such as buffer overflows or heap mismanagement, to hijack the control flow of the executing process.\nWhen successfully exploited for RCE, the attacker gains the ability to execute system-level commands with the privileges of the underlying service account. This allows for the installation of web shells, the exfiltration of sensitive configuration files, or the pivot into internal network segments protected by the ADC. If the attacker chooses to induce a Denial of Service, the payload is designed to trigger an unhandled exception or critical fault in the core service, resulting in a system panic or process restart loop, thereby rendering the appliance unavailable for legitimate traffic.\nThe affected versions include ADC before 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, and 13.1.37.279 FIPS and NDcPP; and Gateway before 14.1-73.37 and 13.1-64.23. The lack of authentication requirements at the attack surface makes this a high-priority vulnerability, as the appliance handles TLS termination and traffic inspection, often placing it in a position of high trust within the network perimeter. Post-exploitation impact varies depending on the attacker’s objectives; however, the ability to control an edge gateway provides an ideal vantage point for advanced persistent threats to monitor and intercept encrypted transit traffic, circumvent multi-factor authentication, or disrupt organizational communications."
}