AI analysis
CVE-2026-88777 is a memory overflow in Citrix NetScaler ADC and Citrix NetScaler Gateway that can cause unpredictable or erroneous behavior or a denial of service. It is reachable over the network with no privileges and no user interaction (CVSS 4.0 8.8); the scored impact is low confidentiality and integrity loss and high availability loss, and the advisory text does not describe remote code execution. Affected builds are ADC before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP, and Gateway before 14.1-73.37 and before 13.1-64.23. Organizations running those ADC or Gateway releases, especially internet-facing appliances, are exposed. No public proof-of-concept is known and the CVE is not in CISA KEV; a related headline about exploited NetScaler zero-day RCE does not name this CVE and is not treated as confirmation for it.
What to do: Upgrade Citrix NetScaler ADC and NetScaler Gateway to 14.1-73.37 or 13.1-64.23 (or later in those trains), ADC FIPS to 14.1-73.37 or later, and ADC FIPS/NDcPP to 13.1.37.279 or later. Until patched, limit internet exposure of ADC and Gateway services and watch for crashes, session errors, or other availability failures.
Affected
| Citrix NetScaler ADC | before 14.1-73.37 and before 13.1-64.23 |
| Citrix NetScaler ADC FIPS | before 14.1-73.37 FIPS |
| Citrix NetScaler ADC FIPS and NDcPP | before 13.1.37.279 |
| Citrix NetScaler Gateway | before 14.1-73.37 and before 13.1-64.23 |
Estimated exposure
largeon the order of tens of thousands of internet-exposed appliances (roughly 10,000–100,000) — Estimate from typical public internet-scan counts of exposed NetScaler ADC/Gateway appliances (commonly on the order of tens of thousands) and their widespread use as enterprise load balancers and remote-access gateways; not a census of…
Description
Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to unpredictable or erroneous behavior or Denial of Service