• PATCH AVAILABLE

CVE-2026-88776: remote memory overflow in Citrix ADC

An unauthenticated remote attacker can trigger a memory overflow in Citrix ADC and Gateway, potentially causing unpredictable behavior or denial of service; this is tracked as CVE-2026-88776. Affected releases include ADC 14.x before 14.1-73.37, ADC 13.x before 13.1-64.23 (and the listed FIPS/NDcPP builds), and Gateway 14.x/13.x before the same fixed builds. The flaw is reachable over the network and does not require credentials or user interaction to exploit.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00384
CWE
CWE-119
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: this can be reached over the network without credentials, so prioritize applying the vendor fixes listed for your ADC/Gateway branch or immediately restrict exposure and monitor for anomalies.

What is CVE-2026-88776?

An unauthenticated remote attacker can trigger a memory overflow in Citrix ADC and Gateway, potentially causing unpredictable behavior or denial of service; this is tracked as CVE-2026-88776. Affected releases include ADC 14.x before 14.1-73.37, ADC 13.x before 13.1-64.23 (and the listed FIPS/NDcPP builds), and Gateway 14.x/13.x before the same fixed builds. The flaw is reachable over the network and does not require credentials or user interaction to exploit.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Citrix ADC are affected?

BRANCHAFFECTEDFIXED
ADC 14.xbefore 14.1-73.3714.1-73.37
ADC 13.xbefore 13.1-64.2313.1-64.23
ADC 14.xbefore 14.1-73.37 FIPS14.1-73.37 FIPS
ADC 13.xbefore 13.1.37.279 FIPS and NDcPP13.1.37.279 FIPS and NDcPP
Gateway 14.xbefore 14.1-73.3714.1-73.37
Gateway 13.xbefore 13.1-64.2313.1-64.23

Is CVE-2026-88776 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-88776

  1. Apply the vendor updates shipped as 14.1-73.37, 13.1-64.23 or the listed FIPS/NDcPP fixed builds for your branch.
  2. If you cannot patch immediately, restrict network exposure of Citrix ADC/Gateway to trusted networks and management interfaces only.
  3. Monitor device logs and network traffic for crashes, restarts, or anomalous activity and prepare to roll back or isolate affected instances.
  4. Follow Citrix guidance and change management to deploy fixes and validate service behavior after updates.

Frequently asked questions

Is CVE-2026-88776 being actively exploited?

There are no public reports of exploitation of CVE-2026-88776 as of 2026-09-29.

Which Citrix ADC versions are affected by CVE-2026-88776?

Citrix ADC and Gateway releases are affected: ADC 14.x before 14.1-73.37, ADC 13.x before 13.1-64.23 (including the FIPS/NDcPP builds noted), and Gateway 14.x/13.x before the corresponding fixed builds.

Is there a patch for CVE-2026-88776?

Yes. Citrix published fixes: 14.1-73.37, 13.1-64.23, and the referenced FIPS/NDcPP fixed builds identified for the affected branches.

Does CVE-2026-88776 require authentication?

No. The vulnerability can be triggered over the network without authentication or user interaction against vulnerable Citrix ADC/Gateway builds.

References