AI analysis
CVE-2026-88776 is a memory overflow in Citrix NetScaler ADC and Citrix NetScaler Gateway. It is reachable over the network with low complexity and requires no privileges and no user interaction. The published impact is unpredictable or erroneous behavior and denial of service, matching a CVSS 4.0 score of 8.8 with low confidentiality and integrity impact and high availability impact on the vulnerable appliance and no subsequent-system impact. It affects NetScaler ADC before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP, and NetScaler Gateway before 14.1-73.37 and before 13.1-64.23. No public proof of concept is known and the CVE is not in CISA KEV; a related headline about actively exploited NetScaler RCE flaws does not identify this CVE and does not change the advisory’s memory-overflow and denial-of-service description.
What to do: Upgrade NetScaler ADC to 14.1-73.37 or later, 13.1-64.23 or later, 14.1-73.37 FIPS or later, or 13.1.37.279 FIPS and NDcPP or later, and upgrade NetScaler Gateway to 14.1-73.37 or later or 13.1-64.23 or later, starting with internet-facing appliances. Until those builds are installed, limit ADC and Gateway reachability to trusted networks and watch for crashes, restarts, and other unexpected appliance behavior.
Affected
| Citrix NetScaler ADC | before 14.1-73.37; before 13.1-64.23; before 14.1-73.37 FIPS; before 13.1.37.279 FIPS and NDcPP |
| Citrix NetScaler Gateway | before 14.1-73.37; before 13.1-64.23 |
Estimated exposure
largetens of thousands of internet-exposed appliances (roughly 10,000–100,000) — Estimate from historical public internet-scan reporting of Citrix NetScaler ADC and Gateway during earlier vulnerability waves, which typically found on the order of 10,000–100,000 internet-exposed appliances; this is not a census of…
Description
Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to unpredictable or erroneous behavior or Denial of Service