CVE-2026-88779: Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

High severity, CVSS 7.5. Actively exploited: in CISA KEV since 2026-10-04. EPSS: 0.6% chance of exploitation in the next 30 days.

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.

Affected products

  • Citrix NetScaler Application Delivery Controller: from 13.1, before 13.1-37.282 (fixed in 13.1-37.282); from 13.1, before 13.1-64.28 (fixed in 13.1-64.28); from 14.1, before 14.1-73.41 (fixed in 14.1-73.41); from 14.1-66.68, up to and including 14.1-73.41
  • Citrix NetScaler Gateway: from 13.1, before 13.1-64.28 (fixed in 13.1-64.28); from 14.1, before 14.1-73.41 (fixed in 14.1-73.41)

Published 2026-10-04. Last modified 2026-10-05.