NetScaler (Citrix) NetScaler Gateway Vulnerabilities & Security Advisories
18 advisories tracked · NetScaler / Cloud Software Group Security Bulletins · 9 listed in the CISA Known Exploited Vulnerabilities catalog
Every row below is a published NetScaler (Citrix) advisory that VulniPulse classified as NetScaler Gateway, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 7 critical, 7 high, 1 medium.
Android app · Google Play
Monitor NetScaler CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Source
NetScaler / Cloud Software Group Security Bulletins
NetScaler CVE disclosures now live in Citrix Community Security Updates. VulniPulse polls the official Tech Zone RSS feed and keeps NetScaler-specific security-category bulletins and CTX guidance, including affected and fixed build details.
Latest NetScaler NetScaler Gateway advisories
High [CVE-2026-88779] Understanding and Addressing CVE-2026-88779 in Citrix NetScaler ADC and Citrix NetScaler Gateway
CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to denial of service under specific deployment conditions. The issue affects customer-managed NetScaler deployments running affected supported versions when the required preconditions are met. Customers should review their deployed versions and configurations, then install the relevant updated versions as soon as possible. Affected Versions The following supported versions are affected when the CVE preconditions (see the section “How to Determine Whether a NetScaler deployment Meets the Preconditions” below) apply: NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.41 NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.28 NetScaler ADC FIPS before 14.1-73.41 FIPS NetScaler ADC FIPS and NDcPP before 13.1-37.282 What Is the Issue? CVE-2026-88779 is categorized as CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer. The vulnerability has a CVSS v4.0 base score of 8.7. Citrix has observed targeted attacks on unmitigated NetScaler deployments which can lead to Denial of Service. If the condition is triggered repeatedly, the service may remain unavailable. Our analysis indicates that this issue affects service availability, and we have not identified an impact on the integrity of customer data.
High [CVE-2026-88778] TCP Initial Sequence Number (ISN) prediction
Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23.
High [CVE-2026-88777] Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service
Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to unpredictable or erroneous behavior or Denial of Service
High [CVE-2026-88775] Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service
Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service
High [CVE-2026-88774] Feature policy bypass due to improper HTTP URL based expression usage
Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to a feature policy bypass due to improper HTTP URL based expression usage.
High [CVE-2026-19489] Vulnerability in NetScaler ADC and NetScaler Gateway
Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
High [CVE-2026-8452] Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service
Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server