Citrix NetScaler ADC / Gateway - Unauthenticated Authentication Bypass in AAA/VPN & Memory Corruption Remote Code Execution (RCE) or Denial of Service (DOS) & Unauthenticated Remote Code Execution (RCE) via Input Validation
Citrix NetScaler ADC and Gateway are internet-exposed edge devices providing SSL VPN, remote access, and application proxy services for enterprises. They serve as critical entry points between external users and internal network resources. CVE-2026-19490 Critical authentication bypass vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. Boasting a CVSS score of 9.3, this flaw resides in the alternative path handling of authentication mechanisms. It allows an unauthenticated remote attacker to completely circumvent authentication controls and gain unauthorized access to protected internal services without requiring legitimate user interaction or credentials. CVE-2026-88771 Extremely high-risk remote code execution (RCE) zero-day vulnerability found in Citrix NetScaler ADC and NetScaler Gateway. Rated with a critical CVSS score of 9.5, it stems from an improper input validation error (CWE-20). Because it affects all default deployment configurations without any feature prerequisites, a network-based unauthenticated attacker can exploit it to execute arbitrary commands directly on the appliance. CVE-2026-88772 Critical zero-day vulnerability affecting Citrix NetScaler ADC and Gateway instances that have Datagram Transport Layer Security (DTLS) enabled. It is caused by an improper restriction of operations within the bounds of a memory buffer, resulting in a memory overflow. With a CVSS score of 9.5, this flaw allows unauthenticated remote threat actors to trigger a total denial-of-service (DoS) condition or achieve remote code execution.






