Communiqué

Multiple Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway

CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, CVE-2026-88778

The CSSF has been made aware of multiple critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway (CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, CVE-2026-88778). The vulnerabilities include unauthenticated remote code execution, memory corruption, HTTP request smuggling, security-policy bypass, denial of service and TCP Initial Sequence Number (ISN) prediction issues.

Two of them, CVE-2026-88771 and CVE-2026-88772, can result in remote code execution and are currently observed exploited in the wild.

CIRCL, the Computer Incident Center Luxembourg, published a report on this subject, including recommendations, available at this URL: https://www.circl.lu/pub/tr-100/.

The CSSF strongly recommends all supervised entities concerned to duly take note of this report and to take appropriate actions.

In addition, as the unauthenticated remote code execution consists of an unauthorised malicious access, the CSSF reminds all supervised entities that this constitutes a major ICT-related incident that needs to be notified, according to either Circulars CSSF 25/893 (DORA) or CSSF 24/847, depending on the type of entity.