NetScaler (Citrix) Security Advisories & CVEs
8 advisories tracked · NetScaler / Cloud Software Group Security Bulletins · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor NetScaler CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Check if your NetScaler device is affected
Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in NetScaler's recent advisories.
Official source
NetScaler / Cloud Software Group Security Bulletins
NetScaler CVE disclosures now live in Citrix Community Security Updates. VulniPulse polls the official Tech Zone RSS feed and keeps NetScaler-specific security-category bulletins and CTX guidance, including affected and fixed build details.
Latest NetScaler advisories
High [CVE-2026-88779] Understanding and Addressing CVE-2026-88779 in Citrix NetScaler ADC and Citrix NetScaler Gateway
CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to denial of service under specific deployment conditions. The issue affects customer-managed NetScaler deployments running affected supported versions when the required preconditions are met. Customers should review their deployed versions and configurations, then install the relevant updated versions as soon as possible. Affected Versions The following supported versions are affected when the CVE preconditions (see the section “How to Determine Whether a NetScaler deployment Meets the Preconditions” below) apply: NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.41 NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.28 NetScaler ADC FIPS before 14.1-73.41 FIPS NetScaler ADC FIPS and NDcPP before 13.1-37.282 What Is the Issue? CVE-2026-88779 is categorized as CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer. The vulnerability has a CVSS v4.0 base score of 8.7. Citrix has observed targeted attacks on unmitigated NetScaler deployments which can lead to Denial of Service. If the condition is triggered repeatedly, the service may remain unavailable. Our analysis indicates that this issue affects service availability, and we have not identified an impact on the integrity of customer data.
High [CVE-2026-88778] TCP Initial Sequence Number (ISN) prediction
Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23.
High [CVE-2026-88777] Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service
Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to unpredictable or erroneous behavior or Denial of Service
High [CVE-2026-88775] Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service
Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service
High [CVE-2026-88774] Feature policy bypass due to improper HTTP URL based expression usage
Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to a feature policy bypass due to improper HTTP URL based expression usage.
High [CVE-2026-19489] Vulnerability in NetScaler ADC and NetScaler Gateway
Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
High [CVE-2026-8452] Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service
Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server
High [CVE-2026-3055] Important Update: CVE Disclosures Now Live on the Citrix Community Site
All CVE disclosure blogs have moved to The Citrix Community Site Going forward, all CVE disclosure blogs will be published in the Security Updates tab on the Citrix Community website. CVE-2026-3055 & CVE 2026-4368 Cloud Software Group released builds on March 23, 2026 to address CVE-2026-3055 and CVE 2026-4368.