GPU VulnDB

Database/Control plane, storage & DevOps

Citrix NetScaler ADC/Gateway: Unauthenticated remote denial of service, actively exploited

CVSS 8.7CVE-2026-88779Control plane, storage & DevOpsKnown exploitedcurated

Impact

An unauthenticated attacker who can reach the appliance can knock it offline - the CVSS 4.0 vector is availability-only (VC:N/VI:N/VA:H), so this is a service outage, not data theft or code execution. Citrix does not describe the mechanism in the record. It matters because NetScaler is typically the front door for remote access and for the management and tenant-facing interfaces of a GPU estate: when it drops, operator VPN, portal and API access go with it, and nothing on the GPU nodes themselves is broken so there is no way to work around it from inside. CISA has it in the KEV catalogue, meaning exploitation has been observed in the wild, so this is not a theoretical availability bug.

Who can reach it

Anyone who can reach the NetScaler's network-facing virtual servers. No authentication and no user interaction required (PR:N/UI:N), so internet-exposed appliances are reachable by anyone.

What to do

Upgrade to ADC 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS or 13.1-37.282, and Gateway to 14.1-73.41 or 13.1-64.28. This is an appliance firmware upgrade and reboot per node, so run it through the HA pair one node at a time; a standalone appliance means an access outage for the duration. Because the flaw is known-exploited, treat it as an emergency window rather than the next scheduled one, and restrict exposure of the affected virtual servers until the upgrade lands. Citrix's KB CTX697174 and the TechZone post are the authoritative detail.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.