• PATCH AVAILABLE

CVE-2026-88775: pre-auth remote code execution in Citrix ADC

An unauthenticated remote attacker can trigger a memory overflow in Citrix ADC and Gateway, potentially causing remote code execution or denial of service. CVE-2026-88775 affects ADC and Gateway releases before the listed fixed builds: ADC 14.x before 14.1-73.37 (including FIPS), ADC 13.x before 13.1-64.23 and 13.1.37.279 FIPS/NDcPP, and Gateway 14.x/13.x before the same builds. The flaw can be reached over the network without credentials or user interaction.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00384
CWE
CWE-120
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: treat this as high priority because the flaw is remotely reachable without authentication (no login required). Apply vendor fixes promptly or restrict network exposure to management interfaces.

What is CVE-2026-88775?

An unauthenticated remote attacker can trigger a memory overflow in Citrix ADC and Gateway, potentially causing remote code execution or denial of service. CVE-2026-88775 affects ADC and Gateway releases before the listed fixed builds: ADC 14.x before 14.1-73.37 (including FIPS), ADC 13.x before 13.1-64.23 and 13.1.37.279 FIPS/NDcPP, and Gateway 14.x/13.x before the same builds. The flaw can be reached over the network without credentials or user interaction.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Citrix ADC are affected?

BRANCHAFFECTEDFIXED
ADC 14.xbefore 14.1-73.3714.1-73.37
ADC 13.xbefore 13.1-64.2313.1-64.23
ADC 14.xbefore 14.1-73.37 FIPS14.1-73.37 FIPS
ADC 13.xbefore 13.1.37.279 FIPS and NDcPP13.1.37.279 FIPS and NDcPP
Gateway 14.xbefore 14.1-73.3714.1-73.37
Gateway 13.xbefore 13.1-64.2313.1-64.23

Is CVE-2026-88775 being exploited?

There are no public reports of exploitation or public exploit code as of 2026-09-29.

How to fix CVE-2026-88775

  1. Upgrade ADC 14.x to 14.1-73.37 or later (including 14.1-73.37 FIPS where applicable)
  2. Upgrade ADC 13.x to 13.1-64.23 or 13.1.37.279 FIPS/NDcPP where applicable
  3. Upgrade Gateway 14.x/13.x to 14.1-73.37 or 13.1-64.23 respectively
  4. Until you can patch, restrict access to ADC/Gateway management and service ports and monitor logs for anomalous crashes or exploitation attempts

Frequently asked questions

Is CVE-2026-88775 being actively exploited?

There are no public reports of active exploitation or public exploit code for CVE-2026-88775 as of 2026-09-29.

Which Citrix ADC and Gateway versions are affected by CVE-2026-88775?

Affected builds include ADC 14.x before 14.1-73.37 (and 14.1-73.37 FIPS), ADC 13.x before 13.1-64.23 and before 13.1.37.279 FIPS/NDcPP, and Gateway 14.x/13.x before the same respective builds.

Is there a patch for CVE-2026-88775?

Yes. Citrix published fixes: 14.1-73.37 for ADC/Gateway 14.x (including FIPS) and 13.1-64.23 or 13.1.37.279 FIPS/NDcPP for ADC/Gateway 13.x.

Does CVE-2026-88775 require authentication?

No. The vulnerability can be exploited remotely without authentication or user interaction against Citrix ADC and Gateway.

References