CVE-2026-88778
Undergoing Analysis Undergoing Analysis - In Progress

Predictable Value Generation in Citrix NetScaler ADC and Gateway

Vulnerability report for CVE-2026-88778, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-27

Last updated on: 2026-09-28

Assigner: NetScaler

Description

Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-27
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 7 associated CPEs
Vendor Product Version / Range
citrix netscaler_application_delivery_controller From 13.1 (inc) to 13.1-64.23 (exc)
citrix netscaler_application_delivery_controller From 14.1 (inc) to 14.1-73.37 (exc)
citrix netscaler_application_delivery_controller From 13.1 (inc) to 13.1.37.279 (exc)
citrix netscaler_application_delivery_controller From 14.1-66.68 (inc) to 14.1-73.37 (inc)
citrix netscaler_application_delivery_controller From 13.1 (inc) to 13.1.37.279 (exc)
citrix netscaler_gateway From 13.1 (inc) to 13.1-64.23 (exc)
citrix netscaler_gateway From 14.1 (inc) to 14.1-73.37 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-342 An exact value or random number can be precisely predicted by observing previous values.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a predictable exact value from previous values issue in Citrix NetScaler ADC and Gateway. It allows attackers to guess or derive sensitive data due to flaws in how certain values are generated.

Detection Guidance

This vulnerability is related to Citrix NetScaler ADC and Gateway products. Detection involves checking the software version against the affected releases. Use commands like 'show version' on NetScaler CLI or check system information via GUI to verify if the installed version is before 14.1-73.37, 13.1-64.23, or their FIPS equivalents.

Impact Analysis

An attacker could exploit this to predict or manipulate system behavior, potentially leading to unauthorized access, data breaches, or disruption of services. Systems running affected versions are at risk.

Compliance Impact

The provided CVE data does not specify direct impacts on compliance with GDPR, HIPAA, or other standards. However, the vulnerability's nature (predictable values from previous data) could potentially lead to unauthorized access or data breaches, which may violate compliance requirements under GDPR (data protection) or HIPAA (protected health information). Organizations should assess the risk based on their specific deployment and data handling practices.

Mitigation Strategies

Update Citrix NetScaler ADC and Gateway to the latest patched versions (14.1-73.37 or later, 13.1-64.23 or later, or FIPS versions as specified).

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-88778. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart