Security Advisory Desk
unratedQCS priority 70/100Citrix

CVE-2026-88779: Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

Citrix NetScaler ADC and Gateway have a memory buffer vulnerability that can be exploited to cause a denial of service, disrupting normal operation.

QCS published 5/10/2026, 7:58:33 pm ISTVendor disclosure 4/10/2026, 5:30:00 am ISTVerified 5/10/2026, 7:58:33 pm ISTRevision 1

In plain language

What this advisory means

Citrix NetScaler ADC and Gateway have a memory buffer vulnerability that can be exploited to cause a denial of service, disrupting normal operation.

Technical explanation

How the issue affects the environment

The vulnerability involves improper restriction of operations within memory buffer bounds in Citrix NetScaler ADC and NetScaler Gateway. This buffer issue (classified as CWE-119) can lead to denial of service by causing the application to operate outside its intended memory boundaries, risking crashes or service interruptions.

Operational impact

Why teams should care

Exploitation of this vulnerability could cause service outages, leading to downtime and affecting availability of critical network services. Organizations using affected Citrix NetScaler products may experience operational disruption.

Immediate action

Apply vendor-provided mitigations promptly according to Citrix instructions and comply with CISA's BOD 26-04 guidance on prioritizing security updates based on risk. For cloud services, follow applicable BOD 26-04 directives or discontinue product use if mitigations are unavailable. Ensure exposure evaluation and patching adherence per BOD 26-04 standards.

Affected and fixed releases

Affected versionsConfirm in the official vendor advisory
Fixed versionsConfirm in the official vendor advisory

Temporary risk reduction

No separate workaround was supplied in the source feed. Use the official vendor advisory before changing production controls.

Evidence and validation checklist

  • CVE identifier: CVE-2026-88779
  • CISA KEV Catalog listing with exploitation noted
  • Vendor advisories detailing the vulnerability and mitigations
  • CWE classification: CWE-119
  • CISA BOD 26-04 for patch prioritization and forensic triage mandates

Authoritative reference

CISA Known Exploited Vulnerabilities

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source