Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
TL;DR 📌
- Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for a denial of service.
- Highest CVSS: 8.7 (High).
- Listed in CISA KEV (2026-10-04) — this is being exploited in the wild.
- Check the advisory for fixed releases — remediation detail is in the vendor link below.
- CVEs: CVE-2026-88779.
What it is
CVE-2026-88779 is a memory-buffer handling flaw in Citrix NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway). The CVSS 4.0 vector shows network-reachable access (AV:N), no privileges required (PR:N), no user interaction (UI:N), and impact limited to availability (VA:H, with confidentiality and integrity unaffected). In practice this means an attacker who can reach the affected service over the network, without authenticating, can trigger conditions that cause a denial of service.
The advisory does not specify which endpoint or protocol handler is responsible for the out-of-bounds buffer operation, so administrators should treat any network-facing NetScaler interface as in scope until Citrix’s own advisory is consulted for detail.
CVE-2026-88779 is listed in CISA’s Known Exploited Vulnerabilities catalogue, added 2026-10-04.
Affected versions, as stated by NVD: NetScaler ADC before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; NetScaler Gateway before 14.1-73.41 and before 13.1-64.28.
What to do
- Identify all NetScaler ADC and NetScaler Gateway instances and check their build against the version ranges above; anything below 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS, or 13.1-37.282 (depending on product and branch) is affected.
- Upgrade ADC to 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS, or 13.1-37.282 or later as appropriate for the branch in use; upgrade Gateway to 14.1-73.41 or 13.1-64.28 or later.
- Given the KEV listing, prioritise patching over other maintenance work and do not wait for a routine change window.
- Where upgrading cannot happen immediately, review exposure of the management and gateway interfaces to the internet and restrict access to trusted networks as an interim measure.
- Check NetScaler logs and availability monitoring for unexplained service interruptions or restarts that could indicate the issue has already been triggered.
For leadership 🧭
Executive summary. NetScaler ADC and Gateway appliances running unpatched builds can be knocked offline by a remote attacker with no credentials and no user interaction required. This is in CISA’s Known Exploited Vulnerabilities catalogue, so it needs to jump the queue ahead of routine patching cycles.
Why it matters:
- NetScaler ADC and Gateway typically sit at the network edge handling authentication and application delivery, so a denial-of-service here can take down VPN access or load-balanced applications for an entire organisation.
- The CVSS vector confirms no authentication or user interaction is needed and the attack is network-reachable, meaning any exposed management or gateway interface is a viable path in.
- CISA added this to its Known Exploited Vulnerabilities catalogue on 2026-10-04, indicating attackers are already using it rather than it being theoretical.
- Affected builds span both current branches (14.1 and 13.1) and the FIPS variant, so a single version check against one build number is not enough to confirm safety.
Now / Next / Later:
- Now: Check CISA KEV deadlines and immediately inventory every NetScaler ADC and Gateway instance against the affected build numbers to identify which ones are exposed today.
- Next: Upgrade affected appliances to 14.1-73.41, 13.1-64.28, the 14.1-73.41 FIPS build, or 13.1-37.282 as appropriate for ADC, and to 14.1-73.41 or 13.1-64.28 for Gateway, prioritising this ahead of other scheduled maintenance.
- Later: Restrict internet exposure of NetScaler management and gateway interfaces to trusted networks by default, and add availability monitoring that flags unexplained restarts or interruptions on these appliances.