Updated:
Status:
CVEs:
Fortra is actively researching critical vulnerabilities in NetScaler ADC and NetScaler Gateway (CVE-2026-88771 and CVE-2026-88772) that could allow an attacker to execute code remotely. CVE-2026-88771 is an improper input validation vulnerability that does not require any additional features enabled to be exploited. CVE-2026-88772 is a memory overflow vulnerability and is exploitable on systems with a DTLS configuration enabled.
Who is affected?
Vulnerable versions of NetScaler ADC and NetScaler Gateway are:
- NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
- NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
- NetScaler ADC FIPS before 14.1-73.37 FIPS
- NetScaler ADC FIPS and NDcPP before 13.1-37.279
What can I do?
Customers should upgrade to one of the following versions or later:
- NetScaler ADC and NetScaler Gateway 14.1-73.37
- NetScaler ADC and NetScaler Gateway 13.1-64.23
- NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS
- NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.279
Mitigations:
- CVE-2026-88771 can only be mitigated by disabling the NetScaler device entirely.
- CVE-2026-88772 can be mitigated by disabling DTLS.
For additional information, refer to:
How is Fortra helping me?
Fortra is actively researching this threat to build detection capabilities in addition to those listed below.
- Fortra VM: Coverage was added for unauthenticated scans and released in Network Scanner version 4.98.0. If the vulnerabilities are detected, they are flagged under Vulnerability ID 180714.
- Tripwire IP360: Coverage was added for unauthenticated scans and released in ASPL-1226. If detected, CVE-2026-88771 is flagged under Vulnerability ID 973932, and CVE-2026-88772 is flagged under Vulnerability ID 973933.
Updates
Fortra has kicked off the Emerging Threats process for this vulnerability. This article will be updated with new information about this vulnerability and related security coverage as it becomes available.
- 09/29/2026: Fortra VM coverage released in Network Scanner 4.98.0 (Vulnerability ID 180714).
- 09/30/2026: Tripwire IP360 coverage released in ASPL-1226 (Vulnerability IDs 973932 and 973933).
