Skip to content
VulniPulse

NetScaler (Citrix) Security Advisories & CVEs

8 advisories tracked · NetScaler / Cloud Software Group Security Bulletins · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor NetScaler CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Check if your NetScaler device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in NetScaler's recent advisories.

Official source

NetScaler / Cloud Software Group Security Bulletins

NetScaler CVE disclosures now live in Citrix Community Security Updates. VulniPulse polls the official Tech Zone RSS feed and keeps NetScaler-specific security-category bulletins and CTX guidance, including affected and fixed build details.

Latest NetScaler advisories

High8.7NetScaler Exploited CISA KEV

High [CVE-2026-88779] Understanding and Addressing CVE-2026-88779 in Citrix NetScaler ADC and Citrix NetScaler Gateway

CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to denial of service under specific deployment conditions. The issue affects customer-managed NetScaler deployments running affected supported versions when the required preconditions are met. Customers should review their deployed versions and configurations, then install the relevant updated versions as soon as possible. Affected Versions The following supported versions are affected when the CVE preconditions (see the section “How to Determine Whether a NetScaler deployment Meets the Preconditions” below) apply: NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.41 NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.28 NetScaler ADC FIPS before 14.1-73.41 FIPS NetScaler ADC FIPS and NDcPP before 13.1-37.282 What Is the Issue? CVE-2026-88779 is categorized as CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer. The vulnerability has a CVSS v4.0 base score of 8.7. Citrix has observed targeted attacks on unmitigated NetScaler deployments which can lead to Denial of Service. If the condition is triggered repeatedly, the service may remain unavailable. Our analysis indicates that this issue affects service availability, and we have not identified an impact on the integrity of customer data.

CVE-2026-88779
NetScaler Gateway
Oct 4, 2026
High8.8NetScaler

High [CVE-2026-88778] TCP Initial Sequence Number (ISN) prediction

Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23.

CVE-2026-88778
NetScaler Gateway
Sep 27, 2026
High8.8NetScaler

High [CVE-2026-88777] Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service

Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to unpredictable or erroneous behavior or Denial of Service

CVE-2026-88777
NetScaler Gateway
Sep 27, 2026
High8.8NetScaler

High [CVE-2026-88775] Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service

CVE-2026-88775
NetScaler Gateway
Sep 27, 2026
High7.0NetScaler

High [CVE-2026-88774] Feature policy bypass due to improper HTTP URL based expression usage

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to a feature policy bypass due to improper HTTP URL based expression usage.

CVE-2026-88774
NetScaler Gateway
Sep 27, 2026
High8.8NetScaler

High [CVE-2026-19489] Vulnerability in NetScaler ADC and NetScaler Gateway

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

CVE-2026-19489
NetScaler Gateway
Aug 19, 2026
High8.8NetScaler Exploited CISA KEV

High [CVE-2026-8452] Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service

Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server

CVE-2026-8452
NetScaler Gateway
Jun 30, 2026
HighNetScaler Exploited CISA KEV

High [CVE-2026-3055] Important Update: CVE Disclosures Now Live on the Citrix Community Site

All CVE disclosure blogs have moved to The Citrix Community Site Going forward, all CVE disclosure blogs will be published in the Security Updates tab on the Citrix Community website. CVE-2026-3055 & CVE 2026-4368 Cloud Software Group released builds on March 23, 2026 to address CVE-2026-3055 and CVE 2026-4368.

CVE-2026-3055
Unclassified
Mar 27, 2026

← All vendors