{"id":"CVE-2026-88777","published":"2026-09-27T17:16:56.990","lastModified":"2026-09-29T22:19:03.363","description":"Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.\n\nThis issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23  leading to unpredictable or erroneous behavior or Denial of Service","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-119"],"vendors":["citrix"],"products":["netscaler application delivery controller","netscaler gateway"],"references":[{"url":"https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096&articleTitle=Citrix_NetScaler_ADC_and_Citrix_NetScaler_Gateway_Security_Bulletin_for_CVE_2026_88771_CVE_2026_88772_CVE_2026_88773_CVE_2026_88774_CVE_2026_88775_CVE_2026_88776_CVE_2026_88777_and_CVE_2026_88778","tags":["Vendor Advisory"]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"A memory overflow vulnerability exists in Citrix NetScaler ADC and Gateway versions prior to 14.1-73.37 and 13.1-64.23, leading to potential Denial of Service (DoS) conditions.","exploitability":"Exploitation is relatively straightforward given the memory overflow, requiring only the sending of a crafted payload to the affected NetScaler instances.","blast_radius":"If exploited, this vulnerability could result in a complete denial of service for affected NetScaler ADC and Gateway services, impacting network availability and service delivery.","remediation":"Upgrade to Citrix NetScaler ADC version 14.1-73.37 or later, and Citrix NetScaler Gateway version 14.1-73.37 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["dos","memory-overflow","citrix","adc","gateway"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-29T08:51:59.290Z"}}