CVE-2026-88772: Memory overflow vulnerability leading to Remote Code Execution or Denial of Service
Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service
Other sources
Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Citrix NetScaler ADC and NetScaler Gateway, including ADC FIPSto a version that resolves this vulnerability.Fixed in 14.1-73.37 - Upgrade
Upgrade
Citrix NetScaler ADC and NetScaler Gatewayto a version that resolves this vulnerability.Fixed in 13.1-64.23 - Upgrade
Upgrade
Citrix NetScaler ADC FIPS and NDcPPto a version that resolves this vulnerability.Fixed in 13.1.37.279
Event History
Frequently Asked Questions
Which NetScaler deployments are listed as affected?
NetScaler ADC releases before 14.1-73.37 or 13.1-64.23 are affected. ADC FIPS and NDcPP releases before 14.1-73.37 FIPS or 13.1.37.279 FIPS and NDcPP are also affected; NetScaler Gateway releases before 14.1-73.37 or 13.1-64.23 are affected.
What should be prioritized during remediation?
Prioritize updating affected ADC and Gateway instances to a release that is not listed as affected. The reported outcomes include remote code execution and denial of service, so both compromise risk and service availability should be considered.