CVE-2026-88779

HIGH CISA KEV TTE Zero-Day Pub 04/10 Upd 05/10

Overview

This vulnerability is a stack-based buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway components. The root cause lies in improper bounds checking of input data processed by certain internal functions, leading to memory corruption. Affected versions include NetScaler ADC before 14.1-73.41, 13.1-64.28, and corresponding FIPS releases, as well as NetScaler Gateway before 14.1-73.41 and 13.1-64.28.

Vulnerability Description

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.

Impact

An unauthenticated attacker can exploit this vulnerability remotely to execute arbitrary code on the affected NetScaler ADC or Gateway devices. This can lead to complete system compromise, allowing the attacker to control the device, intercept or manipulate network traffic, and potentially move laterally within the network. No user interaction or credentials are required to trigger the exploit, increasing the risk of widespread exploitation in exposed environments.

Solution

Citrix has released security updates addressing this vulnerability in NetScaler ADC and Gateway versions 14.1-73.41, 13.1-64.28, and corresponding FIPS releases. Administrators should apply these patches promptly in accordance with Citrix advisory CTX697174 available at https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697174. No alternative mitigations or workarounds are documented in the advisory.

EPSS vs KEV Prediction — Evolution (30 days)

Affected Products

No CPE information available.

Exploits

No exploits found for this CVE.

Exploited in Wild CONFIRMED
Ransomware NOT ASSOCIATED
Attacker Interest VERY HIGH
Sightings Extensive activity

Threat Feed

7 events
2026-10-05
Threat Sensor Sighting — Extensive activity

Sighting activity recorded

2026-10-04
Threat Sensor Sighting — Considerable activity

Sighting activity recorded

2026-10-04
Added to CISA KEV Catalog

CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog

2026-10-04
Detected as Exploited in the Wild

Active exploitation confirmed — vendor: Citrix, product: NetScaler ADC and NetScaler Gateway

2026-10-03
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-09-27
Threat Sensor Sighting — Few sightings

Sighting activity recorded

Detected as Exploited in the Wild (293 sightings)

Active exploitation confirmed with 293 sighting(s)

Likely Kill Chain

Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.

Applicable Out of scope
Initial Access
TA0001
Execution
TA0002
Persistence
TA0003
Priv. Escalation
TA0004
Defense Evasion
TA0005
Credential Access
TA0006
Lateral Movement
TA0008
Collection
TA0009
Impact
TA0040

Highlighted stages are those attackers typically reach when exploiting this CVE. Heuristic based on CWE families — refined by ML classifier when available.

Attack Vectors ML

Buffer Overflow
58% buffer_overflow
Remote Code Execution
55% rce

MITRE ATT&CK Techniques (0)

ATT&CK techniques pending

Techniques are derived from this CVE's kill chains once ML classification completes.

CAPEC Attack Patterns ML

ID Name ML Conf. Likelihood Severity Link
CAPEC-9 Buffer Overflow in Local Command-Line Utilities
46%
High High
CAPEC-14 Client-side Injection-induced Buffer Overflow
46%
Medium High
CAPEC-44 Overflow Binary Resource File
39%
High Very High
CAPEC-100 Overflow Buffers
37%
High Very High
CAPEC-45 Buffer Overflow via Symbolic Links
36%
High High

Red Team Playbook

AtomicRedTeam integration in progress

Executable commands will be auto-mapped to each ATT&CK technique of this CVE.

Detection & Response Rules

No detection or response rules found for this CVE.

No news articles found for this CVE.

References (4)

Title Tags URL
nvd.nist.gov
NVD reference
https://nvd.nist.gov/vuln/detail/CVE-2026-88779
support.citrix.com
GitHub CVE
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697174
community.citrix.com
NVD API
https://community.citrix.com/techzone-blogs/110_security-updates/understanding-and-addressing-cve-2026-88779-in-citrix-netscaler-adc-and-citrix-netscaler-gateway/
cisa.gov
NVD API
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-88779