
PEACH
Un cadre d’isolation des locataires
CVE-2026-88776 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to unpredictable or erroneous behavior or Denial of Service. It affects NetScaler ADC versions before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; and NetScaler Gateway versions before 14.1-73.37 and before 13.1-64.23. The vulnerability was published on September 27, 2026, and carries a CVSS v4.0 base score of 8.8 (High) (GitHub Advisory, Citrix Advisory).
The vulnerability is classified as a memory overflow (CWE not formally assigned), triggered remotely over the network without authentication, special privileges, or user interaction. An unauthenticated attacker can send crafted network requests to cause a memory overflow condition in the NetScaler ADC or Gateway service, resulting in unpredictable behavior or a service crash. No specific CWE has been assigned, and no public technical write-ups or proof-of-concept code are currently available (GitHub Advisory, Citrix Advisory).
Successful exploitation can cause the NetScaler ADC or Gateway service to crash or behave unpredictably, resulting in a Denial of Service condition that disrupts network access, load balancing, and VPN gateway functionality for dependent users and systems. The CVSS v4.0 metrics indicate a high availability impact on the vulnerable system, with low confidentiality and integrity impacts also possible. Because NetScaler ADC and Gateway are commonly deployed as critical network perimeter components, a successful DoS attack could disrupt access to enterprise applications and remote access infrastructure (GitHub Advisory).
No public proof-of-concept exploit code is known to exist, and there is no evidence of active in-the-wild exploitation at the time of disclosure. The EPSS score is 0.0, reflecting a currently low probability of exploitation in the near term. The vulnerability is exploitable by unauthenticated remote attackers with no prerequisites, which lowers the barrier for potential future exploitation. CVE-2026-88776 is part of a broader batch of NetScaler vulnerabilities (CVE-2026-88771 through CVE-2026-88778) disclosed simultaneously, some of which have been reported as actively exploited zero-days (Citrix Advisory, GitHub Advisory).
Citrix has released patched versions addressing this vulnerability. Administrators should upgrade NetScaler ADC to version 14.1-73.37 or later, or 13.1-64.23 or later; FIPS deployments require 14.1-73.37 FIPS or 13.1.37.279 FIPS and NDcPP or later. NetScaler Gateway should be updated to 14.1-73.37 or later, or 13.1-64.23 or later. Prioritize internet-facing systems and monitor for signs of exploitation such as unexpected service restarts or abnormal memory consumption. No configuration-based workarounds have been published (Citrix Advisory).
The disclosure of CVE-2026-88776 was part of a larger batch of eight NetScaler vulnerabilities (CTX697096), with some in the set (notably CVE-2026-88771 and CVE-2026-88772) reported as actively exploited zero-days, drawing significant attention from the security community. Coverage appeared rapidly across outlets including The Hacker News, CyberSecurityNews, Heise, and social media platforms such as Mastodon and X (Twitter), with researchers and threat intelligence accounts highlighting the broader zero-day context. Government CERTs including CERT-EU, Ireland's NCSC, and Canada's Cyber Centre issued advisories, and CISA published an alert on the critical zero-day vulnerabilities in the same NetScaler advisory batch (CERT-EU Advisory, CISA Alert, Heise).
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."