
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-88776 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to unpredictable or erroneous behavior or Denial of Service. It affects NetScaler ADC versions before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; and NetScaler Gateway versions before 14.1-73.37 and before 13.1-64.23. The vulnerability was published on September 27, 2026, and carries a CVSS v4.0 base score of 8.8 (High) (GitHub Advisory, Citrix Advisory).
The vulnerability is classified as a memory overflow (CWE not formally assigned), triggered remotely over the network without authentication, special privileges, or user interaction. An unauthenticated attacker can send crafted network requests to cause a memory overflow condition in the NetScaler ADC or Gateway service, resulting in unpredictable behavior or a service crash. No specific CWE has been assigned, and no public technical write-ups or proof-of-concept code are currently available (GitHub Advisory, Citrix Advisory).
Successful exploitation can cause the NetScaler ADC or Gateway service to crash or behave unpredictably, resulting in a Denial of Service condition that disrupts network access, load balancing, and VPN gateway functionality for dependent users and systems. The CVSS v4.0 metrics indicate a high availability impact on the vulnerable system, with low confidentiality and integrity impacts also possible. Because NetScaler ADC and Gateway are commonly deployed as critical network perimeter components, a successful DoS attack could disrupt access to enterprise applications and remote access infrastructure (GitHub Advisory).
No public proof-of-concept exploit code is known to exist, and there is no evidence of active in-the-wild exploitation at the time of disclosure. The EPSS score is 0.0, reflecting a currently low probability of exploitation in the near term. The vulnerability is exploitable by unauthenticated remote attackers with no prerequisites, which lowers the barrier for potential future exploitation. CVE-2026-88776 is part of a broader batch of NetScaler vulnerabilities (CVE-2026-88771 through CVE-2026-88778) disclosed simultaneously, some of which have been reported as actively exploited zero-days (Citrix Advisory, GitHub Advisory).
Citrix has released patched versions addressing this vulnerability. Administrators should upgrade NetScaler ADC to version 14.1-73.37 or later, or 13.1-64.23 or later; FIPS deployments require 14.1-73.37 FIPS or 13.1.37.279 FIPS and NDcPP or later. NetScaler Gateway should be updated to 14.1-73.37 or later, or 13.1-64.23 or later. Prioritize internet-facing systems and monitor for signs of exploitation such as unexpected service restarts or abnormal memory consumption. No configuration-based workarounds have been published (Citrix Advisory).
The disclosure of CVE-2026-88776 was part of a larger batch of eight NetScaler vulnerabilities (CTX697096), with some in the set (notably CVE-2026-88771 and CVE-2026-88772) reported as actively exploited zero-days, drawing significant attention from the security community. Coverage appeared rapidly across outlets including The Hacker News, CyberSecurityNews, Heise, and social media platforms such as Mastodon and X (Twitter), with researchers and threat intelligence accounts highlighting the broader zero-day context. Government CERTs including CERT-EU, Ireland's NCSC, and Canada's Cyber Centre issued advisories, and CISA published an alert on the critical zero-day vulnerabilities in the same NetScaler advisory batch (CERT-EU Advisory, CISA Alert, Heise).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."