CVE-2026-88775: 
Citrix ADC VPX vulnerability analysis and mitigation

Overview

CVE-2026-88775 is a memory overflow vulnerability affecting Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to unpredictable or erroneous behavior or Denial of Service. It was published on September 27, 2026, and affects NetScaler ADC versions before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; and NetScaler Gateway versions before 14.1-73.37 and before 13.1-64.23. The vulnerability carries a CVSS v4.0 base score of 8.8 (High), exploitable by unauthenticated remote attackers with no user interaction required (GitHub Advisory, Citrix Advisory).

Technical details

The vulnerability is a memory overflow (CWE not formally assigned) in the Citrix NetScaler ADC and Gateway products, triggered via network-accessible interfaces without authentication or special preconditions. An unauthenticated remote attacker can send crafted network requests that cause the appliance to overflow memory, resulting in unpredictable behavior or a crash. No public proof-of-concept code has been identified at the time of disclosure (GitHub Advisory, Citrix Advisory).

Impact

Successful exploitation can cause the NetScaler ADC or Gateway service to crash, resulting in a Denial of Service condition that disrupts network access, VPN connectivity, and application delivery for all dependent users and systems. The CVSS v4.0 scoring also indicates low confidentiality and integrity impacts on the vulnerable system, suggesting some potential for limited data exposure or modification alongside the primary availability impact. Given that NetScaler Gateway is commonly used as a remote access and VPN gateway, a successful DoS attack could disrupt enterprise remote access infrastructure (GitHub Advisory, Citrix Advisory).

Exploitability

As of the disclosure date (September 27, 2026), there is no public proof-of-concept exploit and no confirmed evidence of active in-the-wild exploitation for CVE-2026-88775 specifically (GitHub Advisory). The EPSS score is 0.0, reflecting low current exploitation probability. However, this CVE is part of a broader batch of NetScaler vulnerabilities (CVE-2026-88771 through CVE-2026-88778), some of which have been reported as actively exploited zero-days, prompting advisories from CISA, CERT-EU, the Canadian Centre for Cyber Security, and Ireland's NCSC (CISA Alert, CERT-EU, Canadian CCCS).

Mitigation and workarounds

Citrix has released patched versions addressing CVE-2026-88775. Administrators should upgrade to the following fixed versions as soon as possible:

  • NetScaler ADC: 14.1-73.37 or later; 13.1-64.23 or later; 14.1-73.37 FIPS or later; 13.1.37.279 FIPS and NDcPP or later
  • NetScaler Gateway: 14.1-73.37 or later; 13.1-64.23 or later

Additionally, organizations should monitor for abnormal memory usage or unexpected service crashes on NetScaler appliances, and consider network segmentation to restrict access to NetScaler management interfaces where possible (Citrix Advisory, GitHub Advisory).

Community reactions

The disclosure of CVE-2026-88775 as part of a batch of eight NetScaler vulnerabilities generated significant attention from the security community and government agencies. CISA issued an alert on September 27, 2026, highlighting critical zero-day vulnerabilities in Citrix NetScaler ADC and Gateway being actively exploited (CISA Alert). CERT-EU, the Canadian Centre for Cyber Security, and Ireland's NCSC all published advisories urging immediate patching (CERT-EU, Canadian CCCS, NCSC Ireland). Security media outlets including The Hacker News, CyberSecurityNews, and Heise covered the broader NetScaler zero-day cluster, and social media accounts such as DarkWebInformer amplified the disclosure (The Hacker News, CyberSecurityNews).

Additional resources


Source: This report was generated using AI

Related Citrix ADC VPX vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-88778HIGH8.8
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesSep 27, 2026
CVE-2026-88777HIGH8.8
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesSep 27, 2026
CVE-2026-88776HIGH8.8
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesSep 27, 2026
CVE-2026-88775HIGH8.8
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesSep 27, 2026
CVE-2026-88774HIGH7
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesSep 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management