CVE-2026-88775
9.8 CRITICALPublished 2026-09-27 · Updated 2026-09-28
AI risk analysis
- Summary
- This vulnerability allows for a memory overflow, leading to potential Denial of Service (DoS) conditions or unpredictable behavior in Citrix NetScaler ADC and Gateway versions prior to the specified patches.
- Exploitability
- Exploitation requires access to the affected Citrix NetScaler ADC or Gateway and the ability to craft specific input that triggers the memory overflow. Precondition is the presence of unpatched versions of the software.
- Blast radius
- If exploited, this vulnerability could lead to a complete denial of service for affected systems, impacting network availability and service reliability.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to Citrix NetScaler ADC versions 14.1-73.37 or later, 13.1-64.23 or later, and Citrix NetScaler Gateway versions 14.1-73.37 or later, 13.1-64.23 or later, and 13.1.37.279 FIPS or later.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-120
Vendors
citrix
Products
netscaler application delivery controller, netscaler gateway
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2026-88776
- CRITICALCVE-2026-88777
- CRITICALCVE-2026-88773
- HIGHCVE-2026-66273
- HIGHCVE-2026-67551
- HIGHCVE-2026-67589
- HIGHCVE-2026-68060
- HIGHCVE-2026-67858PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.