Description
Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.

This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service
Published: 2026-09-27
Score: 9.5 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution or Denial of Service
Action: Apply Patch Immediately
AI Analysis

Impact

Citrix NetScaler ADC and Gateway are subject to a memory overflow vulnerability that can allow an unauthenticated attacker to execute arbitrary code or crash the system. The flaw arises from improper bounds checking during processing of incoming data, resulting in a buffer overflow that the attacker can exploit to take control of the device or cause a denial of service. This impacts confidentiality, integrity, and availability of the affected appliance.

Affected Systems

The vulnerability affects Citrix NetScaler ADC versions prior to 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, and 13.1.37.279 FIPS and NDcPP. It also affects Citrix NetScaler Gateway versions before 14.1-73.37 and before 13.1-64.23. All older releases listed in the Citrix advisory are susceptible.

Risk and Exploitability

With a CVSS score of 9.5 the flaw is considered Critical and can be abused remotely over the network. EPSS is not available, but the lack of exploit data does not reduce the severity; the KEV catalog lists it as not yet identified, meaning no known public exploits at the time of analysis. The attack vector is inferred to be remote over the untrusted network, requiring only network connectivity to the appliance. An attacker with sufficient privileges to send crafted input can gain full control or cause a crash.

Generated by OpenCVE AI on September 27, 2026 at 17:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Citrix NetScaler ADC and Gateway to releases 14.1‑73.37 or later, 13.1‑64.23 or later, including all FIPS and NDcPP variants, as detailed in the Citrix advisory.
  • If an immediate upgrade is not feasible, isolate the NetScaler from untrusted networks, block traffic to the vulnerable ports, and use network segmentation to limit exposure.
  • Install the vendor's patch to enforce proper bounds checking (buffer overflow protection) and thereby mitigate erroneous memory access.
  • Review access controls to ensure only authorized users can interact with management interfaces and follow best practices for least‑privilege configuration.

Generated by OpenCVE AI on September 27, 2026 at 17:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 27 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Sun, 27 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service
Title Memory overflow vulnerability leading to Remote Code Execution or Denial of Service
References
Metrics cvssV4_0

{'score': 9.5, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: NetScaler

Published:

Updated: 2026-09-27T16:09:56.033Z

Reserved: 2026-09-10T07:14:57.369Z

Link: CVE-2026-88772

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-27T17:16:56.390

Modified: 2026-09-27T17:16:56.390

Link: CVE-2026-88772

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-27T17:30:17Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer