Description
Vulnerability in NetScaler ADC and NetScaler Gateway.

This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.
Published: 2026-10-04
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a memory overflow in Citrix NetScaler ADC and NetScaler Gateway, leading to a denial of service condition when an attacker can cause the affected components to crash or become unresponsive. The weakness involves improper handling of memory buffers and is categorized as a buffer overflow (CWE‑119).

Affected Systems

Affected vendors include Citrix NetScaler ADC and NetScaler Gateway. The ADC is vulnerable in versions prior to 14.1‑73.41, 13.1‑64.28, 14.1‑73.41 (FIPS), and 13.1‑37.282. The Gateway is vulnerable in versions before 14.1‑73.41 and before 13.1‑64.28.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity impact. The EPSS score is not provided, and the vulnerability is not listed in the CISA KEV catalog, which suggests no public exploits are currently known. The attack vector is not explicitly stated; it is likely that an attacker would need to send crafted traffic or otherwise interact with the vulnerable component to trigger the memory overflow. The impact would be limited to crashing the affected ADC or Gateway, potentially disrupting network services for users of the Citrix environment.

Generated by OpenCVE AI on October 4, 2026 at 04:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Citrix patches for NetScaler ADC and NetScaler Gateway, ensuring versions at or above 14.1‑73.41 for ADC and 13.1‑64.28 for Gateway.
  • Upgrade the affected systems to a version that is not listed as vulnerable, following the vendor’s recommended upgrade path.
  • If an immediate patch is not available, isolate the NetScaler components from external traffic and monitor for unusual traffic patterns that could indicate an attempt to trigger the overflow.

Generated by OpenCVE AI on October 4, 2026 at 04:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 04 Oct 2026 04:45:00 +0000

Type Values Removed Values Added
First Time appeared Netscaler
Netscaler adc
Netscaler gateway
Weaknesses CWE-119
Vendors & Products Netscaler
Netscaler adc
Netscaler gateway

Sun, 04 Oct 2026 03:30:00 +0000

Type Values Removed Values Added
Description Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.
Title Memory overflow vulnerability leading to Denial of Service
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NetScaler

Published:

Updated: 2026-10-04T02:35:35.525Z

Reserved: 2026-09-10T07:14:57.370Z

Link: CVE-2026-88779

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-04T04:16:43.680

Modified: 2026-10-04T04:16:43.680

Link: CVE-2026-88779

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-04T04:30:08Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer