CVE-2026-88775

Published Sep 27, 2026

Last updated 5 hours ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-88775 is a memory overflow vulnerability affecting Citrix NetScaler ADC and Citrix NetScaler Gateway appliances. This flaw can lead to unpredictable or erroneous behavior, or a Denial of Service (DoS) condition. The vulnerability specifically impacts appliances configured as a Gateway, including those utilizing SSL VPN, ICA Proxy, CVPN, or RDP Proxy. It also affects devices set up as an authentication, authorization, and auditing (AAA) virtual server.

Description
Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service
Source
50a63c94-1ea7-4568-8c11-eb79e7c5a2b5
NVD status
Modified
Products
netscaler_application_delivery_controller, netscaler_gateway

Risk scores

CVSS 4.0

Type
Secondary
Base score
8.8
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
HIGH

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

nvd@nist.gov
CWE-120
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-120

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

2

Configurations