CVE-2026-88775(citrix / netscaler_application_delivery_controller)

LOWCVSS 9.8 · CRITICAL

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-120

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • netscaler_application_delivery_controller
  • netscaler_gateway

Threat summary

  • 5 mentions across 1 observed day

What's happening

  • 5 total mentions across 1 day

Affected systems

Vendors
Products
netscaler_application_delivery_controllernetscaler_gateway

Deep dive

Activity timeline5 mentions / 1d
01345Mentions · 2026-09-27: 509-27
Referenced assets5 URLs
Full discourse5 posts
  • Dark Web Informer@DarkWebInformer

    ‼️ Citrix has released a security bulletin regarding zero-day attacks targeting Citrix NetScaler ADC and Citrix NetScaler Gateway. More info: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096 CVEs: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778

    3170641911.2K
    240.3K followersView on X
  • Rıdvan Yağlı@ridvanyagli

    🚨 Citrix NetScaler ADC/Gateway: 8 kritik/yüksek güvenlik açığı için yama yayınlandı! 🔴 CVE-2026-88771 — CVSS 9.5 Unauthenticated RCE. Varsayılan yapılandırmalar dahil tüm NetScaler ADC/Gateway kurulumları etkileniyor. 🔴 CVE-2026-88772 — CVSS 9.5 Memory overflow -> RCE/DoS. DTLS etkin sistemler etkileniyor; VPN vServer'larda DTLS varsayılan olarak açık. 🟠 CVE-2026-88773 — CVSS 9.3 HTTP Request Smuggling. 🟠 CVE-2026-88774 — CVSS 7.0 Policy bypass. 🟠 CVE-2026-88775 — CVSS 8.8 Memory overflow -> DoS/öngörülemeyen davranış. 🟠 CVE-2026-88776 — CVSS 8.8 Memory overflow -> DoS. 🟠 CVE-2026-88777 — CVSS 8.8 Memory overflow -> DoS. 🟠 CVE-2026-88778 — CVSS 8.8 TCP Initial Sequence Number (ISN) prediction. ⚠️ CVE-2026-88771 ve CVE-2026-88772'nin aktif olarak istismar edildiği Citrix tarafından doğrulandı. Çözüm: 14.1-73.37+ veya 13.1-64.23+ sürümüne güncelleyin. FIPS/NDcPP sürümleri için ilgili güncel build'ler de uygulanmalı. Citrix güvenlik bülteni: https://support.citrix.com/external/article/CTX697096

    010801.1K
    2.4K followersView on X
  • にゃん☆たく/takumi.a@taku888infinity

    Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778 https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096 KEV↓ Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway https://www.cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway 参考 Citrix confirms two NetScaler RCE zero-days exploited in attacks https://www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/ 『(直訳)Citrixは、NetScalerのリモートコード実行に関する2つの重大な脆弱性(CVE-2026-88771およびCVE-2026-88772として追跡されている)が攻撃に悪用されていることを確認し、これらの脆弱性を修正するためのセキュリティアップデートをリリースしたことを発表しました。』

    100111.0K
    11.9K followersView on X
  • Autumn Good@autumn_good_35

    JPMorgan Chase XOR Team🤔 Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778 https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096

    10020693
    7.1K followersView on X
  • CVE@CVEnew

    CVE-2026-88775 Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 F… https://www.cve.org/CVERecord?id=CVE-2026-88775

    00000773
    58.1K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appcitrixnetscaler_application_delivery_controller---
Appcitrixnetscaler_application_delivery_controller---
Appcitrixnetscaler_application_delivery_controller---
Appcitrixnetscaler_gateway---

Explore more