critical · CVSS v3 9.1 · CVSS v4 8.7 · EPSS 0.00276
CVE-2026-88779
Citrix NetScaler ADC and Gateway are affected by a critical vulnerability that could allow attackers to compromise the confidentiality, inte
Overview
Citrix NetScaler ADC and Gateway are affected by a critical vulnerability that could allow attackers to compromise the confidentiality, integrity, and availability of network traffic and services. The flaw exists in versions prior to 14.1-73.41 and 13.1-64.28 for ADC, and similar pre‑release versions for Gateway. It is exploitable by remote actors with network access.
Description
Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.
Impact
The vulnerability can lead to unauthorized data disclosure, tampering of traffic, and denial of service for users and administrators. Network operators and end users are directly impacted by potential service disruption and data compromise.
Remediation
Apply the latest firmware patches from Citrix (14.1-73.41 or later, 13.1-64.28 or later). If patching is delayed, isolate the affected devices from the network, restrict management access to trusted IPs, and monitor for anomalous traffic patterns.
Risk context
Severity is critical with a CVSS v3 score of 9.1 and an EPSS of 0.00276, indicating a high-impact but low-probability threat. Immediate patching is strongly recommended to mitigate potential exploitation.
Affected products
- Citrix NetScaler ADC
- Citrix NetScaler Gateway
Scores
- Severity
- critical
- CVSS v2
- 6.4
- CVSS v3
- 9.1
- CVSS v4
- 8.7
- EPSS
- 0.00276