AI analysis
CVE-2026-88775 is a memory overflow in Citrix NetScaler ADC and Citrix NetScaler Gateway. CVSS 4.0 rates it 8.8 (high): it is reachable over the network with low complexity and requires no privileges and no user interaction. Successful exploitation can cause unpredictable or erroneous behavior or denial of service, with low confidentiality and integrity impact and high availability impact on the vulnerable appliance and no documented impact on subsequent systems. It affects ADC builds before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP, and Gateway builds before 14.1-73.37 and before 13.1-64.23. The CVE is not in CISA KEV and no public proof-of-concept is known; a related headline describes actively exploited NetScaler zero-day remote-code-execution issues, but that claim is not confirmed for this CVE in the supplied record.
What to do: Upgrade NetScaler ADC to 14.1-73.37 or later, 13.1-64.23 or later, 14.1-73.37 FIPS or later, or 13.1.37.279 FIPS/NDcPP or later, and NetScaler Gateway to 14.1-73.37 or later or 13.1-64.23 or later. Until patched, restrict exposure of ADC and Gateway services to trusted networks and watch for crashes, restarts, or other availability failures. This CVE is not in CISA KEV and has no known public PoC; still treat unpatched internet-facing appliances as high priority.
Affected
| Citrix NetScaler ADC | before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP |
| Citrix NetScaler Gateway | before 14.1-73.37 and before 13.1-64.23 |
Estimated exposure
largeon the order of tens of thousands of internet-exposed appliances (not all unpatched) — Citrix NetScaler ADC and Gateway are widely deployed enterprise appliances; public internet scans have historically found on the order of tens of thousands of reachable instances, though the share still on vulnerable builds is not stated…
Description
Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service