Database/Control plane, storage & DevOps
Citrix NetScaler ADC/Gateway: unauthenticated attacker executes arbitrary commands on the appliance
Impact
An unauthenticated attacker who can reach the appliance gets arbitrary command execution on it. NetScaler typically fronts the whole environment - tenant portals, admin VPN/ICA access, and often the management path into a GPU cluster - so control of it means control of the traffic and credentials passing through, and a foothold inside the trusted network from which the fleet's control plane is reachable. CISA lists this as known exploited, so assume scanning and exploitation are already happening rather than theoretical. Compromise is at the appliance level, not per-tenant: every service published through the affected vServer is affected at once.
Who can reach it
Anyone who can reach the appliance over the network, including from the internet for an externally published Gateway. No authentication and no user interaction required.
What to do
Upgrade to ADC/Gateway 14.1-73.37 or 13.1-64.23 (FIPS: 14.1-73.37 FIPS; FIPS and NDcPP: 13.1.37.279). This is an appliance firmware upgrade with a reboot and a service interruption for everything published through it - plan an HA-pair rolling upgrade or a maintenance window. Because the flaw is known-exploited, treat an unpatched appliance as possibly already compromised: after upgrading, review configuration and sessions and rotate credentials and secrets that transited it. Citrix does not publish a configuration-only mitigation; restricting reachability of the management interface to a management VLAN reduces but does not remove exposure for published Gateway vServers.
References
Related entries
- Citrix NetScaler ADC/Gateway: unauthenticated remote code execution or denial of serviceCVE-2026-88772 · Citrix NetScaler ADC / GatewayCritical
- CyberPower PowerPanel Business Local/Remote/Management v4.8.6 and earlier (Windows and Linux): A default passwordCVE-2023-25131 · CyberPower PowerPanel Business Local/Remote/Management v4.8.6 and earlier (Windows and Linux)Critical
- Grafana: Azure AD accounts validated on the mutable, non-unique email claimCVE-2023-3128 · GrafanaCritical
- Citrix NetScaler ADC/Gateway: "CitrixBleed" - memory overread leaking valid session tokensCVE-2023-4966 · Citrix NetScaler ADC/GatewayCritical
- GitLab: an unauthenticated GraphQL directive can modify or delete public projects and user dataCVE-2026-19478 · GitLab CE/EE (GraphQL API directive handling)Critical
- CloudNativePG: a database owner escalates to PostgreSQL superuser and OS command execution in the podCVE-2026-55769 · CloudNativePG instance manager (unpinned search_path on superuser connections)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.