Sceawere
Vulnerability Detail
CVE-2026-88777UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Citrix NetScaler Memory Overflow
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.8
- Creation Date
- 1d ago
- Vendor
- Citrix NetScaler
- Product
- ADC
- Attack Type
- N/A
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to unpredictable or erroneous behavior or Denial of Service
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.8",
"pubDate": "2026-09-27T17:16:56.990Z",
"pubdate": "2026-09-27T17:16:56.990Z",
"executiveSummary": "A memory overflow vulnerability has been identified within Citrix NetScaler ADC and Citrix NetScaler Gateway. This flaw pertains to improper memory management during the processing of network traffic, which can be leveraged to induce unpredictable system behavior or a Denial of Service (DoS) condition.\nThe vulnerability affects multiple versions of ADC and Gateway, including standard, FIPS, and NDcPP variants. Successful exploitation allows an unauthenticated remote attacker to compromise service availability by exhausting system resources or triggering application crashes.\nGiven the position of these appliances as critical edge infrastructure, the potential for service disruption is significant. Organizations are advised to prioritize the application of provided security updates to mitigate the risk of operational downtime caused by malicious exploitation of these memory handling flaws.",
"technicalDetails": "The vulnerability is characterized as a memory overflow condition within the underlying packet processing or management engine of the Citrix NetScaler ADC and Gateway appliances. Memory overflows occur when a process attempts to write data beyond the allocated boundaries of a buffer, leading to the corruption of adjacent memory segments, which may include sensitive control structures or application state data.\nThe root cause stems from insufficient bounds checking or improper input validation when handling specific, malformed network packets. When the appliance processes these packets, the internal buffers become saturated or corrupted, resulting in unstable system execution. The nature of this overflow frequently causes the affected service or the entire appliance kernel to enter an unrecoverable state, manifesting as a Denial of Service.\nAffected versions for ADC include those prior to 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, and 13.1.37.279 FIPS/NDcPP. Affected versions for Gateway include those prior to 14.1-73.37 and 13.1-64.23. The exploitation vector is network-based, meaning the vulnerability is remotely exploitable without requiring prior authentication or elevated privileges.\nThe attack flow initiates when an attacker sends a crafted network request—specifically designed to exceed defined buffer constraints—to the targeted appliance. The request is processed by the vulnerable component responsible for request parsing or session management. As the overflow occurs, the system's memory integrity is compromised. If the corruption overwrites critical function pointers or execution paths, it triggers a crash (DoS). In some instances, it may lead to unpredictable behavior, where the appliance stops processing traffic or exhibits erratic functionality before eventually becoming unresponsive. The primary impact is the loss of availability for the network services protected or managed by the Citrix device, effectively neutralizing the security and traffic distribution roles of the appliance."
}