Junglewise Threat Intelligence

CVE-2026-88775: Citrix NetScaler ADC memory overflow

CVE-2026-88775 · Severity: info · Published 2026-09-27

Technologies: Citrix NetScaler ADC, Citrix NetScaler Gateway. Vendors: Citrix.

Executive brief

Citrix NetScaler ADC and Gateway are load balancers and application delivery controllers used by organizations to manage network traffic and application performance. A memory overflow vulnerability in these products could lead to unpredictable behavior, service outages, or potential system crashes that disrupt business operations.

Technical details

A memory overflow vulnerability exists in Citrix NetScaler ADC and Gateway that can result in unpredictable behavior or denial of service. The vulnerability affects multiple versions across both ADC and Gateway products. The issue is fixed in patched versions 14.1-73.37, 13.1-64.23, and their respective FIPS variants.

Affected products

  • Citrix NetScaler ADC before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, before 13.1-37.279 FIPS and NDcPP
  • Citrix NetScaler Gateway before 14.1-73.37, before 13.1-64.23

Timeline

  • 2026-09-27: disclosed

References

Related threats