CVE-2026-88779
published 2026-10-04CVE-2026-88779: Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before…
PriorityP279high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-10-07
Exploited in the wild
EPSS
0.53%
43.1th percentile
Vulnerability in NetScaler ADC and NetScaler Gateway.
This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | citrix_adm | — | — |
| citrix | citrix_endpoint_management | — | — |
| citrix | citrix_netscaler_adc | — | — |
| citrix | citrix_netscaler_gateway | — | — |
| citrix | citrix_virtual_apps_and_desktops | — | — |
| citrix | citrix_workspace_app | — | — |
| citrix | endpoint_management | — | — |
| citrix | netscaler_adc | — | — |
| citrix | netscaler_application_delivery_controller | >= 13.1 < 13.1-37.282 | 13.1-37.282 |
| citrix | netscaler_application_delivery_controller | >= 13.1 < 13.1-64.28 | 13.1-64.28 |
| citrix | netscaler_application_delivery_controller | >= 14.1 < 14.1-73.41 | 14.1-73.41 |
| citrix | netscaler_application_delivery_controller | 14.1-66.68 – 14.1-73.41 | — |
| citrix | netscaler_gateway | — | — |
| citrix | netscaler_gateway | >= 13.1 < 13.1-64.28 | 13.1-64.28 |
| citrix | netscaler_gateway | >= 14.1 < 14.1-73.41 | 14.1-73.41 |
| citrix | xenmobile | — | — |
| citrix | xenserver | — | — |
| netscaler | adc | < 14.1-73.41 | 14.1-73.41 |
| netscaler | adc | < 13.1-64.28 | 13.1-64.28 |
| netscaler | adc | < 14.1-73.41 FIPS | 14.1-73.41 FIPS |
| netscaler | adc | < 13.1-37.282 | 13.1-37.282 |
| netscaler | gateway | < 14.1-73.41 | 14.1-73.41 |
| netscaler | gateway | < 13.1-64.28 | 13.1-64.28 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vulncheck8.7HIGH
cisa8.7HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
cisa·2026-10-04·CVSS 8.7
CVE-2026-88779 [HIGH] CWE-119 Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
Vulnerability: Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
Affected: Citrix NetScaler
Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for a denial of service.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluatin
Citrix
Citrix Security Bulletin CTX697174
vendor_citrix·CVSS 8.8
CVE-2026-19489 [HIGH] Citrix Security Bulletin CTX697174
Citrix Security Bulletin CTX697174
CVE References: CVE-2026-19489, CVE-2026-19490, CVE-2026-78546, CVE-2026-78547, CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, CVE-2026-88778, CVE-2026-88779
Affected Products: Citrix ADM, Citrix Endpoint Management, Citrix NetScaler ADC, Citrix NetScaler Gateway, Citrix Virtual Apps and Desktops, Citrix Workspace app, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenMobile, XenServer
VulDB
Citrix NetScaler ADC/NetScaler Gateway input validation (EUVD-2026-92065)
vuldb·2026-10-04·CVSS 8.7
CVE-2026-88779 [HIGH] Citrix NetScaler ADC/NetScaler Gateway input validation (EUVD-2026-92065)
A vulnerability identified as very critical has been detected in Citrix NetScaler ADC and NetScaler Gateway. The impacted element is an unknown function. The manipulation leads to improper input validation.
This vulnerability is uniquely identified as CVE-2026-88779. The attack is possible to be carried out remotely. Moreover, an exploit is present.
You should upgrade the affected component.
GHSA
Vulnerability in NetScaler ADC and NetScaler Gateway.
ghsa_unreviewed·2026-10-04
CVE-2026-88779 [HIGH] CWE-119 Vulnerability in NetScaler ADC and NetScaler Gateway.
Vulnerability in NetScaler ADC and NetScaler Gateway.
This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.
VulnCheck
Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
vulncheck·2026·CVSS 8.7
CVE-2026-88779 [HIGH] CWE-119 Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for a denial of service.
Affected: Citrix NetScaler ADC and NetScaler Gateway
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible f
No detection rules found.
No public exploits indexed.
Hackernews
⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests
blogs_hackernews·2026-10-05·CVSS 7.5
CVE-2026-88779 [HIGH] ⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests
A blank field. A public repo. One reply to an email. A box left exposed. None of this sounds dramatic, which is partly the problem. This week’s threats keep finding leverage in small things that were easy to overlook.
There are actively exploited bugs in the mix, cleaner intrusion paths, smarter automation, and a long patch list waiting behind them. Some attacks are getting more capable. Others are still getting in because the basics gave way first.
Here’s what mattered this week.
## ⚡ Threat of the Week
Citrix Warns of Ne
Hackernews
New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline
blogs_hackernews·2026-10-05·CVSS 7.5
CVE-2026-88779 [HIGH] New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline
Citrix has released security updates for a high-severity security flaw in NetScaler ADC and NetScaler Gateway that has been exploited as part of targeted zero-day attacks.
The vulnerability, tracked as CVE-2026-88779 , carries a CVSS score of 8.7 out of 10.0.
"CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to denial-of-service under specific deployment conditions," Citrix said . "The issue affects customer-managed NetScaler deployments running affected supported versio
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697174https://community.citrix.com/techzone-blogs/110_security-updates/understanding-and-addressing-cve-2026-88779-in-citrix-netscaler-adc-and-citrix-netscaler-gateway/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-88779
2026-10-04
Published
2026-10-04
Added to CISA KEV
Exploited in the wild