Overview
Citrix has disclosed CVE-2026-88775, a memory overflow vulnerability affecting Citrix NetScaler ADC and Citrix NetScaler Gateway appliances configured as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy) or as an AAA virtual server. NVD rates the flaw CVSS 3.1: 9.8 (Critical), reflecting a network-exploitable, unauthenticated, no-interaction bug that can trigger "unpredictable or erroneous behavior or Denial of Service" per the vendor's own description.
The CVE was published alongside seven other NetScaler flaws in Citrix Security Bulletin CTX697096 on September 27, 2026 — the same bulletin that disclosed two actively exploited remote-code-execution zero-days, CVE-2026-88771 and CVE-2026-88772, which CosmicBytez Labs covered separately the same day. CVE-2026-88775 is not currently listed by CISA as a Known Exploited Vulnerability and no public proof-of-concept has surfaced as of this writing, but it shares the same underlying bug class — and the same remediation window — as the confirmed zero-days, so it should not be treated as a lower priority simply because it lacks headlines.
Technical Details
| Field | Value |
|---|---|
| CVE ID | CVE-2026-88775 |
| Severity | Critical |
| CVSS Score | 9.8 (CVSS 3.1, NVD) — Citrix's own native score is 8.8 (CVSS 4.0); see note below |
| CWE | CWE-120 — Buffer Copy without Checking Size of Input |
| Attack Vector | Network |
| Authentication | Not required |
| Privileges Required | None |
| User Interaction | None |
| Impact | Memory overflow leading to unpredictable/erroneous behavior or Denial of Service; precondition is NetScaler configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server |
A note on the score gap: NVD's published CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) assumes full confidentiality, integrity, and availability impact — the standard conservative treatment NVD applies to unauthenticated, network-reachable memory-corruption bugs. Citrix's own CVSS 4.0 vector (AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N) scores confidentiality and integrity impact as Low and availability impact as High — i.e., the vendor, with access to the actual crash behavior, assesses the primary consequence as service disruption rather than full compromise. Treat the higher NVD score as the worst-case planning number and the vendor's own vector as the more technically grounded read of what the bug actually does.
How It Works
CVE-2026-88775 is a classic buffer-overflow-class bug (CWE-120): a code path copies attacker-influenced input into a fixed-size buffer without adequately validating that the input fits. On a network appliance like NetScaler, these bugs typically live in the packet-engine or request-parsing logic that handles a specific protocol feature — in this case, traffic hitting a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or an AAA virtual server, both of which sit in the pre- or peri-authentication path for remote-access and identity flows.
Because the precondition is a specific virtual server type rather than "any NetScaler deployment," CVE-2026-88775 has a narrower blast radius than CVE-2026-88771 (which Citrix says affects all default NetScaler deployments). It is, however, still reachable by an unauthenticated attacker who can send crafted traffic to the exposed Gateway or AAA listener — no credentials or session state are needed to trigger the overflow.
Publicly available detail on the exact overflow mechanics (which parser, which field, which protocol message) has not been released by Citrix or independent researchers as of this writing. In the absence of a public technical write-up, the safest working assumption for a memory-overflow bug on a network-facing appliance is: guaranteed crash/DoS at minimum, with the possibility of further memory corruption — and therefore RCE — depending on heap/stack layout, compiler mitigations (stack canaries, ASLR, DEP/NX), and exactly how much of the overflow an attacker can control. Citrix's own CVSS 4.0 vector, which rates the vulnerable-system availability impact as High but confidentiality/integrity impact as only Low, suggests the vendor's internal analysis leans toward "reliable crash" rather than "reliable code execution" — but that is not a guarantee, and historically several NetScaler memory-corruption bugs first disclosed as "DoS" have later been shown to be exploitable for code execution once researchers had time to study them.
Impact Assessment
Who Is at Risk
Any organization running NetScaler ADC or NetScaler Gateway with a virtual server configured as:
- Gateway mode — SSL VPN, ICA Proxy, CVPN, or RDP Proxy (i.e., any NetScaler doing remote-access duty), or
- AAA virtual server — used for authentication, authorization, and auditing in front of published applications
is potentially exposed. These are exactly the configurations most likely to be internet-facing, since their entire purpose is to broker remote access — which also means they are the configurations most attractive to opportunistic scanning once a bug class like this becomes public.
Potential Attack Chains
- Reconnaissance — an attacker fingerprints NetScaler build version via banner, TLS certificate, or behavioral probing to confirm a pre-patch build.
- Trigger — a crafted request is sent to the exposed Gateway or AAA virtual server, forcing the vulnerable code path to copy oversized input into an undersized buffer.
- Immediate impact — at minimum, the targeted worker process or the packet engine crashes, producing a denial-of-service condition on that virtual server (and potentially the whole appliance, depending on process architecture).
- Escalation (unconfirmed) — if the overflow is exploitable beyond a crash, an attacker with enough control over the overwritten memory could pursue code execution. No public research currently demonstrates this for CVE-2026-88775 specifically.
Relationship to the Confirmed Zero-Days
CVE-2026-88775 shipped in the same CTX697096 bulletin as two other memory-overflow bugs — CVE-2026-88776 (Oracle-type load-balancing virtual servers) and CVE-2026-88777 (non-HTTP Layer 7 features such as FTP, RTSP, or DNS64 on load-balancing/content-switching/CGNAT-LSN/NAT64 setups) — none of which are currently KEV-listed. That's a meaningfully different exploitation status than CVE-2026-88771 (unauthenticated RCE, all default deployments, CISA KEV) and CVE-2026-88772 (memory overflow leading to RCE/DoS via DTLS, CISA KEV), both confirmed under active exploitation and covered in CosmicBytez Labs' separate coverage of the confirmed zero-days. Administrators should not let the absence of a KEV listing for CVE-2026-88775 create a false sense of priority — it shares a root-cause class and a patch cycle with bugs that are already being weaponized.
Mitigation
Immediate Actions
- Patch to a fixed build now: NetScaler ADC/Gateway 14.1-73.37 or later, 13.1-64.23 or later, 14.1-73.37 FIPS or later, or 13.1.37.279 (FIPS/NDcPP) or later.
- Builds that only fixed the August authentication-bypass CVE (CVE-2026-19490) — 14.1-73.32 and 13.1-63.21 — do not remediate CVE-2026-88775. Confirm the exact build number on every instance; don't assume last month's patch cycle covers this bulletin.
- Watch for the known 13.1-64.23 upgrade issue: Citrix documents a known problem where upgrading to 13.1-64.23 under a specific configuration can cause the appliance to enter a reboot loop. Stage the upgrade on a non-production or HA-paired unit first, and have a rollback plan ready.
- If immediate patching isn't feasible, evaluate whether the affected Gateway/AAA virtual server can be temporarily restricted at the network layer (ACL to known-good source ranges) as a stopgap — not a substitute for patching.
Detection Opportunities
Because no public technical write-up or IOC list exists for this specific CVE, detection is necessarily generic:
- Monitor for unexpected crashes or restarts of NetScaler worker processes, the packet engine (
nsppe), or AAA daemons — an unexplained crash on a Gateway/AAA virtual server after this disclosure date warrants investigation, not just a restart. - Review NetScaler system logs (
ns.log) and crash dumps around the disclosure window for anomalous process terminations. - Given the active-exploitation context of sibling CVEs in the same bulletin, treat any NetScaler appliance that was internet-facing before patching as warranting the same forensic caution Citrix and CISA are recommending for CVE-2026-88771/88772 — preserve a technical support bundle and packet-engine core dump before applying the update if compromise is suspected.
Defence-in-Depth
- Limit exposure of Gateway/AAA virtual servers to only the source ranges that need them; avoid unnecessary internet-wide exposure of remote-access infrastructure.
- Keep NetScaler management interfaces off the data plane and restricted to a dedicated management network.
- Maintain an accurate, current inventory of every NetScaler ADC/Gateway instance and its exact build number — this is the second NetScaler bulletin in six weeks, and inventory drift is the most common reason patch cycles slip.
- Feed NetScaler crash/restart telemetry into your SIEM so a spike in packet-engine restarts across the fleet is visible, not just alerting per-device.
Background
Citrix Security Bulletin CTX697096, published September 27, 2026, disclosed eight NetScaler ADC/Gateway CVEs in one bulletin: CVE-2026-88771 through CVE-2026-88778. Two of them — CVE-2026-88771 (unauthenticated RCE affecting all default deployments) and CVE-2026-88772 (memory overflow leading to RCE/DoS via DTLS on VPN virtual servers) — were confirmed as actively exploited zero-days and added to CISA's Known Exploited Vulnerabilities catalog; CosmicBytez Labs covered that story in detail in Citrix Confirms Two NetScaler RCE Zero-Days.
CVE-2026-88775 is a distinct, lower-profile finding from the same bulletin — disclosed at the same time, sharing the same fixed-build remediation path, but not (as of publication) confirmed as exploited. It sits alongside two other memory-overflow bugs in the bulletin, CVE-2026-88776 and CVE-2026-88777, each scoped to a different NetScaler feature. This is the second NetScaler security bulletin in roughly six weeks, following August's fix for CVE-2026-19490, reinforcing NetScaler ADC/Gateway as a persistent, high-value target for both vulnerability researchers and threat actors.