CVE-2026-88775: 
Citrix ADC VPX Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-88775 is a memory overflow vulnerability affecting Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to unpredictable or erroneous behavior or Denial of Service. It was published on September 27, 2026, and affects NetScaler ADC versions before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; and NetScaler Gateway versions before 14.1-73.37 and before 13.1-64.23. The vulnerability carries a CVSS v4.0 base score of 8.8 (High), exploitable by unauthenticated remote attackers with no user interaction required (GitHub Advisory, Citrix Advisory).

Détails techniques

The vulnerability is a memory overflow (CWE not formally assigned) in the Citrix NetScaler ADC and Gateway products, triggered via network-accessible interfaces without authentication or special preconditions. An unauthenticated remote attacker can send crafted network requests that cause the appliance to overflow memory, resulting in unpredictable behavior or a crash. No public proof-of-concept code has been identified at the time of disclosure (GitHub Advisory, Citrix Advisory).

Impact

Successful exploitation can cause the NetScaler ADC or Gateway service to crash, resulting in a Denial of Service condition that disrupts network access, VPN connectivity, and application delivery for all dependent users and systems. The CVSS v4.0 scoring also indicates low confidentiality and integrity impacts on the vulnerable system, suggesting some potential for limited data exposure or modification alongside the primary availability impact. Given that NetScaler Gateway is commonly used as a remote access and VPN gateway, a successful DoS attack could disrupt enterprise remote access infrastructure (GitHub Advisory, Citrix Advisory).

Exploitabilité

As of the disclosure date (September 27, 2026), there is no public proof-of-concept exploit and no confirmed evidence of active in-the-wild exploitation for CVE-2026-88775 specifically (GitHub Advisory). The EPSS score is 0.0, reflecting low current exploitation probability. However, this CVE is part of a broader batch of NetScaler vulnerabilities (CVE-2026-88771 through CVE-2026-88778), some of which have been reported as actively exploited zero-days, prompting advisories from CISA, CERT-EU, the Canadian Centre for Cyber Security, and Ireland's NCSC (CISA Alert, CERT-EU, Canadian CCCS).

Atténuation et solutions de contournement

Citrix has released patched versions addressing CVE-2026-88775. Administrators should upgrade to the following fixed versions as soon as possible:

  • NetScaler ADC: 14.1-73.37 or later; 13.1-64.23 or later; 14.1-73.37 FIPS or later; 13.1.37.279 FIPS and NDcPP or later
  • NetScaler Gateway: 14.1-73.37 or later; 13.1-64.23 or later

Additionally, organizations should monitor for abnormal memory usage or unexpected service crashes on NetScaler appliances, and consider network segmentation to restrict access to NetScaler management interfaces where possible (Citrix Advisory, GitHub Advisory).

Réactions de la communauté

The disclosure of CVE-2026-88775 as part of a batch of eight NetScaler vulnerabilities generated significant attention from the security community and government agencies. CISA issued an alert on September 27, 2026, highlighting critical zero-day vulnerabilities in Citrix NetScaler ADC and Gateway being actively exploited (CISA Alert). CERT-EU, the Canadian Centre for Cyber Security, and Ireland's NCSC all published advisories urging immediate patching (CERT-EU, Canadian CCCS, NCSC Ireland). Security media outlets including The Hacker News, CyberSecurityNews, and Heise covered the broader NetScaler zero-day cluster, and social media accounts such as DarkWebInformer amplified the disclosure (The Hacker News, CyberSecurityNews).

Ressources additionnelles


Source: Ce rapport a été généré à l’aide de l’IA

Apparenté Citrix ADC VPX Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-88778HIGH8.8
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NonOuiSep 27, 2026
CVE-2026-88777HIGH8.8
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NonOuiSep 27, 2026
CVE-2026-88776HIGH8.8
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NonOuiSep 27, 2026
CVE-2026-88775HIGH8.8
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NonOuiSep 27, 2026
CVE-2026-88774HIGH7
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NonOuiSep 27, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités