CVE-2026-88779

Executive Summary

CVE-2026-88779 is a critical vulnerability affecting Citrix NetScaler ADC and Gateway firmware versions prior to 14.1-73.41, 13.1-64.28, and earlier FIPS and 13.1-37.282 releases. The flaw allows attackers to execute arbitrary code or gain unauthorized access, and is actively exploited in the wild as identified by CISA's KEV. Immediate patching or mitigation is required for all affected deployments.


Authoritative CVE Metadata - CVSS Base Score: Unknown (Unknown) - Published: 2026-10-04T04:16:43.680 - Last Modified: 2026-10-04T21:16:35.903

[!CAUTION] Known Exploited Vulnerability: YES (CISA KEV Added: 2026-10-04)

Original Description: Vulnerability in NetScaler ADC and NetScaler Gateway.

This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.

"Self-complacency is fatal to progress."

— Margaret Sangster
Source: NVD