LearnCTEM.com, Best CTEM Learning Platform
CVE Watch

CVE-2026-88779: NetScaler ADC and Gateway Risk Explained

Citrix NetScaler ADC and NetScaler Gateway are affected by CVE-2026-88779, a memory buffer bounds vulnerability associated with high availability impact and confirmed exploitation in the wild. Check the vendor advisory for your exact build and deployment, then apply its mitigation instructions and validate the result.

Last updated: October 6, 2026

CVE-2026-88779 Citrix NetScaler high severity vulnerability, LearnCTEM CVE Watch cover

Quick answer

Direct answer

Citrix NetScaler ADC and NetScaler Gateway are affected by CVE-2026-88779, a memory buffer bounds vulnerability associated with high availability impact and confirmed exploitation in the wild. Check the vendor advisory for your exact build and deployment, then apply its mitigation instructions and validate the result.

What is NetScaler?

NetScaler is the Citrix product family identified in this vulnerability record, covering NetScaler Application Delivery Controller, or ADC, and NetScaler Gateway. At a product category level, application delivery controllers support application delivery, while gateways provide access paths. For you as a defender, the important starting point is understanding which applications and access workflows depend on the affected deployment.

The people who need to coordinate here include whoever operates the appliance, whoever owns the applications behind it, and whoever handles security response. Your deployment might sit on an important service path, but that dependency must be established from your own environment. Do not assume every NetScaler installation has the same exposure, configuration, or business importance.

Start with the product and its role rather than treating this as another isolated CVE. Ask what the device supports, who can reach it, and what would stop working if it became unavailable. Those answers turn a vulnerability finding into an operational decision about urgency, maintenance planning, and recovery.

CVE-2026-88779 at a glance

FieldDetail
CVE IDCVE-2026-88779
ProductCitrix NetScaler
SeverityHIGH
CVSS base score8.7
CVSS vectorCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS probability0.53 percent (percentile 43)
CISA KEVYes, added 2026-10-04
WeaknessCWE-119
Affected versionsNetscaler Application Delivery Controller from 13.1 before 13.1-37.282; Netscaler Application Delivery Controller from 13.1 before 13.1-64.28; Netscaler Application Delivery Controller from 14.1 before 14.1-73.41; Netscaler Application Delivery Controller from 14.1-66.68 up to and including 14.1-73.41; Netscaler Gateway from 13.1 before 13.1-64.28; Netscaler Gateway from 14.1 before 14.1-73.41
PublishedOctober 4, 2026

CISA required action

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

What the flaw is

CVE-2026-88779 is classified as CWE-119, which concerns operations outside the intended bounds of a memory buffer. Conceptually, software must keep memory operations within the space allocated for them. This classification indicates a failure in that boundary handling, but it does not establish the precise faulty operation, triggering request, or affected component.

The supplied assessment assigns HIGH severity and CVSS 8.7. Its vector describes a network attack path, low attack complexity, no additional attack requirements, no required privileges, and no user interaction. These characteristics support urgent exposure assessment. They do not tell you which endpoint, protocol, or deployment setting makes a particular appliance vulnerable.

The assessed impact is high for availability of the vulnerable system. Confidentiality and integrity impact are not identified in the supplied vector, nor are impacts on subsequent systems. You should therefore describe this as an availability concern supported by the record, not as confirmed remote code execution, credential theft, or data exfiltration. Memory corruption terminology alone does not justify those stronger claims.

The record was published on October 4, 2026, and modified on October 5, 2026. It is also listed in the CISA Known Exploited Vulnerabilities catalog, with an addition date of October 4, 2026. That establishes exploitation in the wild, but the supplied facts do not identify the exploit technique, attacker, campaign, or prevalence.

How an attack could happen

The following is a conceptual exposure scenario, not a reconstruction of a documented incident. It illustrates how the supplied attack characteristics could matter to your environment without assuming an undisclosed exploit mechanism.

  1. 1An attacker has network reachability to an affected NetScaler deployment. Internet exposure is an important condition to investigate, but the network attack classification does not mean every vulnerable instance is publicly accessible.
  2. 2The attacker attempts to exercise the vulnerable memory handling behavior. The supplied vector indicates that privileges and user interaction are not required. The necessary request format and exact processing path are not provided.
  3. 3Successful exploitation could impair availability of the vulnerable system, consistent with the assessment. Whether this produces a crash, restart, prolonged interruption, or another symptom is not established by the supplied facts.
  4. 4Your response team investigates any service interruption while confirming the asset's build and exposure. Those investigations should proceed together: restoring service does not, by itself, establish that the vulnerability has been addressed.

Impact

The primary supported technical impact is loss of availability. Translate that into business terms by mapping the appliance to its actual dependencies. If important application or access workflows rely on it, interruption could affect those workflows. The scale of that effect depends on your architecture and cannot be inferred from the CVE score alone.

Keep outage assessment separate from compromise assessment. The supplied record does not demonstrate data theft or an attacker gaining persistent access. Equally, a lack of obvious symptoms is not proof that an exposed device has never been targeted. Investigate using available evidence rather than treating either assumption as a conclusion.

The catalog's ransomware association is marked Unknown. That is not evidence of a ransomware campaign, and it is not evidence that ransomware involvement has been ruled out. Communicate the uncertainty explicitly when briefing leadership or deciding whether additional incident response work is needed.

Who is affected

The supplied description identifies NetScaler ADC releases before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282. For NetScaler Gateway, it identifies releases before 14.1-73.41 and before 13.1-64.28. Treat these as affected release statements requiring verification against the current vendor advisory, not as a complete upgrade decision.

The structured affected list describes ADC ranges starting at 13.1 and ending before 13.1-37.282, and separately starting at 13.1 and ending before 13.1-64.28. It also lists ADC from 14.1 before 14.1-73.41. For Gateway, it lists 13.1 before 13.1-64.28 and 14.1 before 14.1-73.41.

There is a material boundary conflict: another ADC entry covers 14.1-66.68 through and including 14.1-73.41. You therefore cannot safely declare 14.1-73.41 unaffected from these facts. The relationship between the overlapping ADC ranges is also not explained. Preserve the full build and FIPS status in your inventory, and check the vendor advisory before selecting a remediation target.

The supplied advisory reference is https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697174. Use it to resolve applicability, build boundaries, and current mitigation instructions. No independently verified fixed version is established here.

How to detect it

  • Identify every NetScaler ADC and Gateway instance within your management scope. Record the exact build, product role, FIPS status where relevant, owner, and supporting evidence. A major release label alone is insufficient to resolve the affected ranges.
  • Assess reachability from the internet and from relevant internal networks. Record the observation method and time. An inventory label such as internal does not substitute for checking the access paths that actually exist.
  • Review available operational telemetry for unexpected availability changes, process failures, restarts, or unusual traffic patterns near disruption times. These are investigative leads, not confirmed indicators for this CVE; the supplied facts provide no distinctive detection signature.
  • Correlate appliance observations with service monitoring, network telemetry, configuration changes, and maintenance records where available. Describe defensive searches in terms of timing and relationships: which events preceded an interruption, and whether an authorized change explains them.
  • Retain relevant evidence according to your response procedures and applicable forensic requirements. Avoid treating a clean log search as proof of safety, because the supplied record does not establish which evidence exploitation must leave behind.
  • Separate detection of an affected build from detection of exploitation. You may confirm vulnerability without finding attack evidence, and you may find suspicious behavior before build applicability is resolved. Track those findings as related but distinct workstreams.

How to fix and reduce risk

Do this now

  • Assign an owner to each potentially affected asset and check the vendor advisory immediately. Resolve the conflicting ADC boundary before approving a destination build. Record why the selected action applies to that particular product, release branch, and deployment.
  • Follow the vendor's mitigation instructions and the applicable CISA requirements. The supplied KEV action references BOD 26-04 guidance, asset internet exposure assessment, and CISA forensic triage requirements. Do not invent a universal remediation deadline from this record.
  • If suspicious activity or unexplained disruption is present, coordinate remediation with incident response and evidence preservation. A software change can address exposure without answering whether earlier exploitation occurred. Keep those questions visible to the responsible teams.

If you cannot patch yet

  • No specific workaround is verified in the supplied facts. Check the vendor advisory before relying on a configuration change, traffic filter, or feature restriction. Do not describe an unverified control as a complete mitigation.
  • Consider whether you can reduce unnecessary network reachability while planning remediation. Treat that as a general exposure reduction measure whose effectiveness depends on your environment, not as proof that exploitation is blocked.
  • The supplied KEV action calls for discontinuing use if mitigations are unavailable and following applicable guidance for cloud services. Plan the operational consequences with service owners rather than leaving an unresolved exposure indefinitely accepted by default.

Longer term hardening

  • Maintain an inventory that preserves complete build identifiers and meaningful deployment details. Link each appliance to an accountable owner and the services it supports so future findings do not stall while teams determine responsibility.
  • Make verification part of change completion. Confirm the running build after maintenance, check it against vendor applicability guidance, reassess reachability, and verify expected service operation. An approved change ticket is not evidence that every intended asset was updated.
  • Keep exposure management and incident response connected. Review what delayed discovery or action, improve evidence collection where necessary, and retain the rationale for any exception. Revisit exceptions when the advisory or your deployment changes.

The CTEM view

CTEM stageWhat to do for this CVE
ScopeDefine the assessment around NetScaler ADC and Gateway deployments and the services that depend on them. Include ownership, deployment role, reachable networks, and operational importance. Your scope should explain what you are protecting and which assets must receive an explicit decision, rather than merely naming the CVE.
DiscoverCollect exact builds and exposure evidence, then compare them with the supplied ranges and vendor guidance. Flag the conflicting 14.1-73.41 boundary as unresolved instead of silently interpreting it. Discovery should produce a defensible asset list, including systems that need further investigation before applicability can be determined.
PrioritizeCombine confirmed exploitation, reachability, supported availability impact, and service importance. EPSS 0.53 percent is a predictive signal, not a reason to disregard KEV membership. The supplied facts already establish exploitation in the wild. Use local exposure to decide action order without confusing a forecast with observed exploitation.
ValidateValidate remediation through vendor applicability checks, authenticated build evidence where available, and authorized exposure assessment. You do not need to reproduce an exploit to confirm a supported remediation state. Document remaining uncertainty and distinguish a successful service health check from evidence that the vulnerable condition has been removed.
MobilizeGive operations, security, service owners, and incident responders clearly separated responsibilities. Agree on the change plan, evidence handling, communications, and closure criteria. Escalate unresolved applicability or unavailable mitigation rather than allowing ownership ambiguity to become a lasting exposure. Track completion per asset, not just per maintenance window.

Key takeaways

  • CVE-2026-88779 affects NetScaler ADC and Gateway, with memory buffer bounds handling identified as the weakness.
  • CISA KEV membership confirms exploitation in the wild. Do not let a lower predictive signal override that evidence.
  • The supplied assessment supports high availability impact, not claims of confirmed data theft or remote code execution.
  • The ADC version information conflicts at 14.1-73.41. Check the vendor advisory before calling that build safe.
  • Close the finding only after confirming the applicable mitigation, the asset's resulting state, and any separate incident response obligations.

Frequently asked questions

It is a vulnerability affecting NetScaler ADC and NetScaler Gateway, classified as CWE-119 for memory buffer bounds handling. The supplied assessment is HIGH severity with CVSS 8.7 and identifies high availability impact. The exact vulnerable processing path is not provided.

Related pages

Your next credential

Earn your free CTEM certification.

Learn to scope, prioritize, validate and mobilize fixes for CVEs like this one.

Free to takePublicly verifiable

Beginner / Practitioner / Program Leader

Explore certifications

Author

LearnCTEM Editorial Team

Practitioners and educators writing plain-English guides on Continuous Threat Exposure Management.

Reviewed by

Senior CTEM Practitioner Panel

Reviewed for accuracy against public CTEM guidance and real-world program experience.