rootpwn

critical · CVSS v3 9.1 · CVSS v4 8.7 · EPSS 0.00276

CVE-2026-88779

Citrix NetScaler ADC and Gateway are affected by a critical vulnerability that could allow attackers to compromise the confidentiality, inte

Overview

Citrix NetScaler ADC and Gateway are affected by a critical vulnerability that could allow attackers to compromise the confidentiality, integrity, and availability of network traffic and services. The flaw exists in versions prior to 14.1-73.41 and 13.1-64.28 for ADC, and similar pre‑release versions for Gateway. It is exploitable by remote actors with network access.

Description

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.

Impact

The vulnerability can lead to unauthorized data disclosure, tampering of traffic, and denial of service for users and administrators. Network operators and end users are directly impacted by potential service disruption and data compromise.

Remediation

Apply the latest firmware patches from Citrix (14.1-73.41 or later, 13.1-64.28 or later). If patching is delayed, isolate the affected devices from the network, restrict management access to trusted IPs, and monitor for anomalous traffic patterns.

Risk context

Severity is critical with a CVSS v3 score of 9.1 and an EPSS of 0.00276, indicating a high-impact but low-probability threat. Immediate patching is strongly recommended to mitigate potential exploitation.

Affected products

  • Citrix NetScaler ADC
  • Citrix NetScaler Gateway

Scores

Severity
critical
CVSS v2
6.4
CVSS v3
9.1
CVSS v4
8.7
EPSS
0.00276

Citrix NetScaler ADC Gateway critical patch network-security

← All CVEs