GPU VulnDB

Database/Control plane, storage & DevOps

Citrix NetScaler ADC/Gateway: unauthenticated remote code execution or denial of service

CVSS 9.5CVE-2026-88772Control plane, storage & DevOpsKnown exploitedcurated

Impact

A second known-exploited flaw fixed in the same Citrix bulletin, distinct from CVE-2026-88771: it yields remote code execution or a denial of service on the appliance. Citrix does not describe the mechanism beyond that, and the CVSS vector rates attack complexity as high, so exploitation likely needs specific conditions - but CISA lists it as exploited in the wild. Where NetScaler terminates tenant or operator access to a GPU environment, code execution on it exposes the sessions and credentials flowing through, and the denial-of-service outcome alone takes the published services offline.

Who can reach it

Network-reachable attacker, no authentication and no user interaction. Externally published Gateway vServers are reachable from the internet.

What to do

Same fix as the rest of bulletin CTX697096: upgrade to ADC/Gateway 14.1-73.37 or 13.1-64.23 (FIPS: 14.1-73.37 FIPS; FIPS and NDcPP: 13.1.37.279). Appliance upgrade plus reboot; use the HA pair to avoid an outage, otherwise a maintenance window for everything the appliance publishes. Given the KEV listing, audit the appliance for signs of prior compromise and rotate transited secrets. No vendor mitigation is published short of upgrading.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.