CVE-2026-88779
Overview
This vulnerability is a stack-based buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway components. The root cause lies in improper bounds checking of input data processed by certain internal functions, leading to memory corruption. Affected versions include NetScaler ADC before 14.1-73.41, 13.1-64.28, and corresponding FIPS releases, as well as NetScaler Gateway before 14.1-73.41 and 13.1-64.28.
Vulnerability Description
Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.
Impact
An unauthenticated attacker can exploit this vulnerability remotely to execute arbitrary code on the affected NetScaler ADC or Gateway devices. This can lead to complete system compromise, allowing the attacker to control the device, intercept or manipulate network traffic, and potentially move laterally within the network. No user interaction or credentials are required to trigger the exploit, increasing the risk of widespread exploitation in exposed environments.
Solution
Citrix has released security updates addressing this vulnerability in NetScaler ADC and Gateway versions 14.1-73.41, 13.1-64.28, and corresponding FIPS releases. Administrators should apply these patches promptly in accordance with Citrix advisory CTX697174 available at https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697174. No alternative mitigations or workarounds are documented in the advisory.
EPSS vs KEV Prediction — Evolution (30 days)
Affected Products
No CPE information available.
Exploits
No exploits found for this CVE.
Threat Feed
7 eventsSighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Active exploitation confirmed — vendor: Citrix, product: NetScaler ADC and NetScaler Gateway
Sighting activity recorded
Sighting activity recorded
Active exploitation confirmed with 293 sighting(s)
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Highlighted stages are those attackers typically reach when exploiting this CVE. Heuristic based on CWE families — refined by ML classifier when available.
Attack Vectors ML
MITRE ATT&CK Techniques (0)
Techniques are derived from this CVE's kill chains once ML classification completes.
CAPEC Attack Patterns ML
Red Team Playbook
Executable commands will be auto-mapped to each ATT&CK technique of this CVE.
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2026-88779 |
| support.citrix.com |
GitHub CVE
|
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697174 |
| community.citrix.com |
NVD API
|
https://community.citrix.com/techzone-blogs/110_security-updates/understanding-and-addressing-cve-2026-88779-in-citrix-netscaler-adc-and-citrix-netscaler-gateway/ |
| cisa.gov |
NVD API
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-88779 |