{
  "id": 11140973,
  "title": "Upgrading past CVE-2026-88772: version mapping and rollout order for NetScaler ADC and Gateway",
  "url": "https://urgent.news/2026/10/01/upgrading-past-cve-2026-88772-version-mapping-and-rollout-order-for",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-01T08:00:20.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/kozhevniko/upgrading-past-cve-2026-88772-version-mapping-and-rollout-order-for-netscaler-adc-and-gateway-4plb"
  },
  "original_language": "en",
  "account": "The Citrix NetScaler bulletin CTX697096 of 27 September 2026 addresses two critical vulnerabilities, CVE-2026-88771 and CVE-2026-88772. These flaws allow unauthenticated command execution and memory overflow, leading to remote code execution or denial of service. Both vulnerabilities have been confirmed as exploited and carry a CVSS v4 score of 9.5. Citrix recommends upgrading to specific versions depending on the appliance type. For NetScaler ADC and Gateway versions before 14.1-73.37, upgrade to 14.1-73.37 or later. For NetScaler ADC and Gateway versions before 13.1-64.23, upgrade to 13.1-64.23 or later. The same applies to NetScaler ADC FIPS before 14.1-73.37 FIPS and NetScaler ADC FIPS and NDcPP before 13.1-37.279. The two most serious defects are targeted first. Internet-reachable VPN virtual servers receive priority, as they satisfy the build condition and CVE-2026-88772 precondition without additional configuration. Hybrid Secure Private Access designs, internal-only load-balancing roles, lab and standby units follow. Standby units are non-negotiable as failover during incidents will affect the standby's running configuration. Before the maintenance window, capture system and audit logs, current build string, running configuration, and any crash or memory dump material. NCSC-NL advises this due to the potential success of earlier attacks exploiting CVE-2026-88771 and CVE-2026-88772. After the window, verify the appliance reports the fixed build, not just that the update ran. Compare the preserved logs with Citrix's published indicators. Recheck DTLS and VPN virtual server configuration, as default inherited configurations may not reflect current business needs. When closing the change record, attach pre-patch evidence, including a firmware timestamp, to document the risk handled. Citrix-managed cloud services and Citrix Managed Adaptive Authentication are updated by Cloud Software Group.",
  "summary": "Upgrading past CVE-2026-88772: version mapping and rollout order for NetScaler ADC and Gateway The patching decision for the Citrix NetScaler bulletin CTX697096 of 27 September 2026 is not complicated. The sequencing is where estates get stuck, because the affected population spans four branch types with different fixed versions and the two most serious flaws are already being exploited. The…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}