CVE-2026-88779: Citrix NetScaler Zero-Day
Citrix patched CVE-2026-88779, a high-severity NetScaler memory overflow exploited as a zero-day.
Citrix patched CVE-2026-88779, a high-severity memory-overflow vulnerability in NetScaler. SOCRadar reports the flaw was exploited as a zero-day before fixes were available. The notice says the overflow affects customer deployments; further technical detail in the source is truncated.
- CVE-2026-88779 is a high-severity NetScaler memory overflow.
- Citrix says it was exploited as a zero-day before patches.
- Fixes are now available from Citrix.
Vulnerabilities mentionedAll →
- CVE-2026-887798.7<1%Unauthenticated denial of service in NetScaler ADC and Gatewaypublished · Citrix NetScaler ADC KEV
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-88779 | Unauthenticated denial of service in NetScaler ADC and Gateway CVE-2026-88779 is a high-severity vulnerability (CVSS 4.0 base score 8.7) in Citrix NetScaler ADC and NetScaler Gateway. CVSS metrics indicate it can be triggered remotely over the network with low complexity, no privileges, and no user interaction; the advisory text does not name a specific bug class or request path. Impact is limited to high loss of availability on the vulnerable appliance, with no confidentiality or integrity impact scored for the device or for subsequent systems, which is consistent with denial of service. Affected products are NetScaler ADC before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282, and NetScaler Gateway before 14.1-73.41 and before 13.1-64.28. It is not listed in CISA KEV, and no public proof-of-concept is known. |
CVE-2026-88779: Citrix NetScaler Zero-Day Citrix has patched CVE-2026-88779, a high-severity NetScaler vulnerability that was exploited as a zero-day before fixes became available. The memory overflow affects customer-ma
The full text could not be extracted from this site (paywall, bot protection or heavy scripting). Read it at socradar.io.