AI analysis
CVE-2026-88778 is a CWE-342 predictable-exact-value flaw in Citrix NetScaler ADC and NetScaler Gateway, in which a later value can be determined from earlier values. It is reachable over the network with no privileges and no user interaction and is scored CVSS 4.0 8.8, with low confidentiality impact but high integrity and availability impact on the appliance and low impact on subsequent systems. Affected products are NetScaler ADC before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP, and NetScaler Gateway before 14.1-73.37 and before 13.1-64.23. No public proof of concept is recorded for this CVE and it is not listed in CISA KEV. A related headline reports that Citrix confirmed NetScaler zero-day vulnerabilities are being exploited in attacks, so exploitation against this product line should be treated as active even though that report does not name this CVE.
What to do: Upgrade NetScaler ADC to 14.1-73.37 or later, 13.1-64.23 or later, 14.1-73.37 FIPS or later, or 13.1.37.279 FIPS and NDcPP or later, and upgrade NetScaler Gateway to 14.1-73.37 or 13.1-64.23 or later. Prioritize internet-facing appliances. After patching, review authentication, session, and configuration logs for unexpected changes, since related reporting describes active NetScaler exploitation even though this CVE is not in CISA KEV and has no public PoC.
Affected
| Citrix NetScaler ADC | before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP |
| Citrix NetScaler Gateway | before 14.1-73.37 and before 13.1-64.23 |
Estimated exposure
largetens of thousands of internet-exposed appliances, plus additional internal deployments — Order-of-magnitude estimate from historical public internet scans of Citrix NetScaler ADC and Gateway, which have repeatedly shown on the order of tens of thousands of exposed appliances; this is not a current census of vulnerable builds.
Description
Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23.