Database/Control plane, storage & DevOps
Citrix NetScaler ADC/Gateway: unauthenticated remote code execution or denial of service
Impact
A second known-exploited flaw fixed in the same Citrix bulletin, distinct from CVE-2026-88771: it yields remote code execution or a denial of service on the appliance. Citrix does not describe the mechanism beyond that, and the CVSS vector rates attack complexity as high, so exploitation likely needs specific conditions - but CISA lists it as exploited in the wild. Where NetScaler terminates tenant or operator access to a GPU environment, code execution on it exposes the sessions and credentials flowing through, and the denial-of-service outcome alone takes the published services offline.
Who can reach it
Network-reachable attacker, no authentication and no user interaction. Externally published Gateway vServers are reachable from the internet.
What to do
Same fix as the rest of bulletin CTX697096: upgrade to ADC/Gateway 14.1-73.37 or 13.1-64.23 (FIPS: 14.1-73.37 FIPS; FIPS and NDcPP: 13.1.37.279). Appliance upgrade plus reboot; use the HA pair to avoid an outage, otherwise a maintenance window for everything the appliance publishes. Given the KEV listing, audit the appliance for signs of prior compromise and rotate transited secrets. No vendor mitigation is published short of upgrading.
References
Related entries
- Citrix NetScaler ADC and Gateway: unauthenticated remote compromise of the applianceCVE-2026-19490 · Citrix NetScaler ADC / GatewayCritical
- CyberPower PowerPanel Business Local/Remote/Management v4.8.6 and earlier (Windows and Linux): A default passwordCVE-2023-25131 · CyberPower PowerPanel Business Local/Remote/Management v4.8.6 and earlier (Windows and Linux)Critical
- Grafana: Azure AD accounts validated on the mutable, non-unique email claimCVE-2023-3128 · GrafanaCritical
- Citrix NetScaler ADC/Gateway: "CitrixBleed" - memory overread leaking valid session tokensCVE-2023-4966 · Citrix NetScaler ADC/GatewayCritical
- GitLab: an unauthenticated GraphQL directive can modify or delete public projects and user dataCVE-2026-19478 · GitLab CE/EE (GraphQL API directive handling)Critical
- CloudNativePG: a database owner escalates to PostgreSQL superuser and OS command execution in the podCVE-2026-55769 · CloudNativePG instance manager (unpinned search_path on superuser connections)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.