AI description
CVE-2026-88778 is identified as a TCP Initial Sequence Number (ISN) prediction flaw affecting Citrix NetScaler ADC and NetScaler Gateway appliances. This vulnerability specifically impacts devices configured with TCP-based virtual servers, such as those handling HTTP, SSL, or generic TCP traffic, when the "Enhanced ISN Generation" feature is disabled. To address this issue, Citrix advises applying software updates and implementing a configuration change to enable Enhanced ISN Generation on affected appliances.
- Description
- Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23.
- Source
- 50a63c94-1ea7-4568-8c11-eb79e7c5a2b5
- NVD status
- Received
CVSS 4.0
- Type
- Secondary
- Base score
- 8.8
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- HIGH
- 50a63c94-1ea7-4568-8c11-eb79e7c5a2b5
- CWE-342
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
25
Citrix NetScaler ADC/Gatewayのゼロデイ2件について公式情報が出た。CVE-2026-88771及びCVE-2026-88772はいずれもCVSSスコア9.5で、前者は無条件で刺さり、後者はDTLSが有効であることが条件(VPN仮想サーバでは既定で有効)
@__kokumoto
27 Sept 2026
679 Impressions
1 Retweet
4 Likes
1 Bookmark
1 Reply
1 Quote
Please see our latest Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778. Citrix urges affected customers to install the relevant updated versions as soon as possible. https://t.co/0JS7KidPd8
@citrix
27 Sept 2026
24852 Impressions
81 Retweets
147 Likes
46 Bookmarks
9 Replies
19 Quotes