CVE-2026-88776
Undergoing Analysis
Undergoing Analysis - In Progress
Buffer Overflow in Citrix NetScaler ADC and Gateway
Vulnerability report for CVE-2026-88776, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-27
Last updated on: 2026-09-28
Assigner: NetScaler
Description
Description
Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23Β Β leading to unpredictable or erroneous behavior or Denial of Service
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| citrix | netscaler_application_delivery_controller | From 13.1 (inc) to 13.1-64.23 (exc) |
| citrix | netscaler_application_delivery_controller | From 14.1 (inc) to 14.1-73.37 (exc) |
| citrix | netscaler_application_delivery_controller | From 13.1 (inc) to 13.1.37.279 (exc) |
| citrix | netscaler_application_delivery_controller | From 14.1-66.68 (inc) to 14.1-73.37 (inc) |
| citrix | netscaler_application_delivery_controller | From 13.1 (inc) to 13.1.37.279 (exc) |
| citrix | netscaler_gateway | From 13.1 (inc) to 13.1-64.23 (exc) |
| citrix | netscaler_gateway | From 14.1 (inc) to 14.1-73.37 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-119 | The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data. |