Skip to content
VulniPulse

NetScaler (Citrix) NetScaler Gateway Vulnerabilities & Security Advisories

18 advisories tracked · NetScaler / Cloud Software Group Security Bulletins · 9 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published NetScaler (Citrix) advisory that VulniPulse classified as NetScaler Gateway, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 7 critical, 7 high, 1 medium.

Android app · Google Play

Monitor NetScaler CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Source

NetScaler / Cloud Software Group Security Bulletins

NetScaler CVE disclosures now live in Citrix Community Security Updates. VulniPulse polls the official Tech Zone RSS feed and keeps NetScaler-specific security-category bulletins and CTX guidance, including affected and fixed build details.

Latest NetScaler NetScaler Gateway advisories

High8.7NetScaler Exploited CISA KEV

High [CVE-2026-88779] Understanding and Addressing CVE-2026-88779 in Citrix NetScaler ADC and Citrix NetScaler Gateway

CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to denial of service under specific deployment conditions. The issue affects customer-managed NetScaler deployments running affected supported versions when the required preconditions are met. Customers should review their deployed versions and configurations, then install the relevant updated versions as soon as possible. Affected Versions The following supported versions are affected when the CVE preconditions (see the section “How to Determine Whether a NetScaler deployment Meets the Preconditions” below) apply: NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.41 NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.28 NetScaler ADC FIPS before 14.1-73.41 FIPS NetScaler ADC FIPS and NDcPP before 13.1-37.282 What Is the Issue? CVE-2026-88779 is categorized as CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer. The vulnerability has a CVSS v4.0 base score of 8.7. Citrix has observed targeted attacks on unmitigated NetScaler deployments which can lead to Denial of Service. If the condition is triggered repeatedly, the service may remain unavailable. Our analysis indicates that this issue affects service availability, and we have not identified an impact on the integrity of customer data.

CVE-2026-88779
NetScaler Gateway
Oct 4, 2026
High8.8NetScaler

High [CVE-2026-88778] TCP Initial Sequence Number (ISN) prediction

Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23.

CVE-2026-88778
NetScaler Gateway
Sep 27, 2026
High8.8NetScaler

High [CVE-2026-88777] Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service

Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to unpredictable or erroneous behavior or Denial of Service

CVE-2026-88777
NetScaler Gateway
Sep 27, 2026
High8.8NetScaler

High [CVE-2026-88775] Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service

CVE-2026-88775
NetScaler Gateway
Sep 27, 2026
High7.0NetScaler

High [CVE-2026-88774] Feature policy bypass due to improper HTTP URL based expression usage

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to a feature policy bypass due to improper HTTP URL based expression usage.

CVE-2026-88774
NetScaler Gateway
Sep 27, 2026
High8.8NetScaler

High [CVE-2026-19489] Vulnerability in NetScaler ADC and NetScaler Gateway

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

CVE-2026-19489
NetScaler Gateway
Aug 19, 2026
High8.8NetScaler Exploited CISA KEV

High [CVE-2026-8452] Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service

Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server

CVE-2026-8452
NetScaler Gateway
Jun 30, 2026

← All NetScaler advisories