Description
Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.

This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23  leading to unpredictable or erroneous behavior or Denial of Service
Published: 2026-09-27
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a memory overflow in Citrix NetScaler ADC and Gateway that can cause unpredictable or erroneous behavior, including a denial of service. The flaw stems from improper validation of buffer boundaries, classified as CWE-119, and can allow an attacker to disrupt services without taking direct control of the device.

Affected Systems

Affected are Citrix NetScaler ADC versions earlier than 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, and 13.1.37.279 FIPS or NDcPP; and Citrix NetScaler Gateway versions earlier than 14.1-73.37 and 13.1-64.23.

Risk and Exploitability

The CVSS score is 8.8, indicating high severity. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog. Attackers could exploit the memory overflow by sending crafted traffic to the affected NetScaler devices over the network, leading to service interruption. The lack of a public exploit or listed KEV status does not reduce the risk, as the high CVSS and common network entry surface suggest a realistic threat.

Generated by OpenCVE AI on September 27, 2026 at 17:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Citrix NetScaler ADC or Gateway to the latest firmware that includes the fix for CVE-2026-88777.
  • If an immediate upgrade is not possible, restrict inbound traffic to the NetScaler component to only trusted IP ranges by applying strict ACLs or firewall rules.
  • Disable unused services on the device and monitor logs for abnormal packet handling or repeated errors to detect potential exploitation attempts.

Generated by OpenCVE AI on September 27, 2026 at 17:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 27 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Sun, 27 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23  leading to unpredictable or erroneous behavior or Denial of Service
Title Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service
References
Metrics cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: NetScaler

Published:

Updated: 2026-09-27T16:37:44.345Z

Reserved: 2026-09-10T07:14:57.370Z

Link: CVE-2026-88777

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-27T17:16:56.990

Modified: 2026-09-27T17:16:56.990

Link: CVE-2026-88777

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-27T17:30:17Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer