
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-88779 is a denial-of-service vulnerability affecting NetScaler ADC and NetScaler Gateway products. It allows unauthenticated remote attackers to cause a high-impact availability disruption with no user interaction required. Affected versions include NetScaler ADC before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; and NetScaler Gateway before 14.1-73.41 and before 13.1-64.28. The vulnerability was published on October 4, 2026, and carries a CVSS v4.0 base score of 8.7 (High) (GitHub Advisory, ENISA EUVD).
The vulnerability's precise root cause has not been publicly detailed, and no CWE classification has been assigned as of the time of publication. Based on the CVSS v4.0 metrics, exploitation requires no authentication, no user interaction, no special privileges, and no attack requirements, indicating a remotely triggerable flaw in the network-facing components of NetScaler ADC or Gateway. The impact is limited to availability (VA:H), with no confidentiality or integrity impact on either the vulnerable or subsequent systems, suggesting a crash, resource exhaustion, or similar denial-of-service condition. A proof-of-exploit reference was noted on Infosec.Exchange, though no detailed technical write-up or public PoC code has been confirmed (GitHub Advisory, Feedly).
Successful exploitation results in a denial-of-service condition against the vulnerable NetScaler ADC or Gateway system, causing high availability impact with no effect on confidentiality or integrity. Because NetScaler ADC and Gateway are commonly deployed as critical network infrastructure — handling load balancing, SSL offloading, and remote access — an outage could disrupt enterprise VPN access, application delivery, and authentication services for large numbers of users. There is no evidence of lateral movement or data exfiltration risk based on current scoring (GitHub Advisory, ENISA EUVD).
A proof-of-exploit reference has been identified on Infosec.Exchange, suggesting early-stage weaponization activity, though no formal PoC code repository has been confirmed (Feedly). Community discussion references "multiple Citrix NetScaler 0-days exploited," indicating possible in-the-wild exploitation activity around the time of disclosure (ifin.network). The EPSS score is currently 0.0, and no CISA KEV catalog listing has been confirmed at this time (ENISA EUVD). No specific threat actor attribution is available.
nsppe, nsnetsvc); system availability alerts or health-check failures on the ADC or Gateway appliance.NetScaler has released patched versions addressing this vulnerability. Administrators should upgrade NetScaler ADC to version 14.1-73.41 or later, 13.1-64.28 or later, 14.1-73.41 FIPS or later, or 13.1-37.282 or later (for FIPS environments); and NetScaler Gateway to 14.1-73.41 or later, or 13.1-64.28 or later. As an interim measure, restricting network access to NetScaler management interfaces and data-plane endpoints via firewall rules or access control lists can reduce exposure. Refer to the official Citrix support article CTX697174 for vendor-specific guidance (GitHub Advisory, Citrix Support).
Security researcher Kevin Beaumont (GossiTheDog) commented on the vulnerability via Mastodon shortly after disclosure, indicating notable community attention (cyberplace.social). Community forums referenced "multiple Citrix NetScaler 0-days exploited" in the same disclosure window, suggesting heightened concern about the broader NetScaler vulnerability landscape (ifin.network). Reddit's r/Citrix community also discussed the need to update NetScaler ADC and Gateway promptly (Reddit). The Citrix TechZone community blog published a dedicated post on understanding and addressing CVE-2026-88779 (Citrix Community).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."