threat_intelligence715 wordsRead on Arc Codex

Warning: Multiple vulnerabilities (CVE-2026) in NetScaler ADC and NetScaler Gateway

JPCERT-AT-2026-0029 JPCERT/CC 2026-09-28 All configurations, including the default configuration, are affected in versions vulnerable to CVE-2026-88771. Furthermore, CVE-2026-88772 affects configurations where DTLS is enabled. Note that DTLS is enabled by default on VPN virtual servers in NetScaler Gateway. The Cloud Software Group has observed attacks exploiting CVE-2026-88771 and CVE-2026-88772 in NetScaler environments that have not been patched. Cloud Software Group Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778 https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096 JPCERT/CC confirms that the affected products are widely used in Japan. Furthermore, observations by overseas security organizations indicate that attack attempts targeting NetScaler systems in Japan have been observed since September 24, 2026. It is not yet clear whether these attack attempts were intended to exploit these vulnerabilities. Since exploitation of CVE-2026-88771 and CVE-2026-88772 has already been confirmed, if you are using products affected by these vulnerabilities, please promptly apply countermeasures and investigate for any compromise, referring to the information provided by the developers. - NetScaler ADC and NetScaler Gateway versions prior to 14.1-73.37 - NetScaler ADC and NetScaler Gateway versions prior to 13.1-64.23 - NetScaler ADC FIPS versions prior to 14.1-73.37 FIPS - NetScaler ADC FIPS and NDcPP versions prior to 13.1-37.279 This vulnerability information applies to NetScaler ADC and NetScaler Gateway that the customer manages. The Cloud Software Group is implementing necessary updates for cloud services and Adaptive Authentication managed by Citrix. Cloud Software Group Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778 https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/#Indicators_of_Compromise__cabcb4 If you have any information regarding this matter, please contact JPCERT/CC. Japan Cybersecurity Coordination Center (JPCERT/CC) Cybersecurity Coordination Group Email: ew-info@jpcert.or.jp JPCERT/CC 2026-09-28 I. Overview The Cloud Software Group published advisories on September 27, 2026, regarding multiple vulnerabilities (CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778) in NetScaler ADC and NetScaler Gateway. If CVE-2026-88771 and CVE-2026-88772 are exploited, an unauthenticated remote attacker may be able to execute arbitrary code. In versions affected by CVE-2026-88771, all configurations, including the default configuration, are affected. Furthermore, CVE-2026-88772 affects configurations where DTLS is enabled. Note that DTLS is enabled by default on VPN virtual servers in NetScaler Gateway. The Cloud Software Group has observed attacks exploiting CVE-2026-88771 and CVE-2026-88772 in NetScaler environments that have not been patched. Cloud Software Group Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778 https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096 JPCERT/CC confirms that the affected products are widely used in Japan. Furthermore, observations by overseas security organizations indicate that attack attempts targeting NetScaler systems in Japan have been observed since September 24, 2026. It is not yet clear whether these attack attempts were intended to exploit these vulnerabilities. Since exploitation of CVE-2026-88771 and CVE-2026-88772 has already been confirmed, if you are using products affected by these vulnerabilities, please promptly apply countermeasures and investigate for any compromise, referring to the information provided by the developers. II. Scope The affected products and versions are as follows. The settings affected by each vulnerability may differ. Please check the information from the Cloud Software Group for details. - NetScaler ADC and NetScaler Gateway versions prior to 14.1-73.37 - NetScaler ADC and NetScaler Gateway versions prior to 13.1-64.23 - NetScaler ADC FIPS versions prior to 14.1-73.37 FIPS - NetScaler ADC FIPS and NDcPP versions prior to 13.1-37.279 This vulnerability information applies to NetScaler ADC and NetScaler Gateway that the customer manages. The Cloud Software Group is implementing necessary updates for cloud services and Adaptive Authentication managed by Citrix. III. Countermeasures The Cloud Software Group strongly recommends that affected users apply the patched versions as soon as possible. Please apply the patched versions promptly after conducting sufficient testing. Please check the latest information provided by the developers for details. IV. Workarounds The Cloud Software Group does not provide workarounds for CVE-2026-88771 and CVE-2026-88772. V. Investigation of Compromise We recommend investigating whether you may have been subjected to attacks exploiting the vulnerabilities by checking the latest information provided by the Cloud Software Group. Please check the latest information provided by the developers for details. VI. References Cloud Software Group Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778 https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/#Indicators_of_Compromise__cabcb4 If you have any information regarding this matter, please contact JPCERT/CC. Japan Cybersecurity Coordination Center (JPCERT/CC) Cybersecurity Coordination Group Email: ew-info@jpcert.or.jp

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.