DIRAS TAKE
Urgent: this can be reached over the network without credentials, so prioritize applying the vendor fixes listed for your ADC/Gateway branch or immediately restrict exposure and monitor for anomalies.
What is CVE-2026-88776?
An unauthenticated remote attacker can trigger a memory overflow in Citrix ADC and Gateway, potentially causing unpredictable behavior or denial of service; this is tracked as CVE-2026-88776. Affected releases include ADC 14.x before 14.1-73.37, ADC 13.x before 13.1-64.23 (and the listed FIPS/NDcPP builds), and Gateway 14.x/13.x before the same fixed builds. The flaw is reachable over the network and does not require credentials or user interaction to exploit.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Citrix ADC are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| ADC 14.x | before 14.1-73.37 | 14.1-73.37 |
| ADC 13.x | before 13.1-64.23 | 13.1-64.23 |
| ADC 14.x | before 14.1-73.37 FIPS | 14.1-73.37 FIPS |
| ADC 13.x | before 13.1.37.279 FIPS and NDcPP | 13.1.37.279 FIPS and NDcPP |
| Gateway 14.x | before 14.1-73.37 | 14.1-73.37 |
| Gateway 13.x | before 13.1-64.23 | 13.1-64.23 |
Is CVE-2026-88776 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-88776
- Apply the vendor updates shipped as 14.1-73.37, 13.1-64.23 or the listed FIPS/NDcPP fixed builds for your branch.
- If you cannot patch immediately, restrict network exposure of Citrix ADC/Gateway to trusted networks and management interfaces only.
- Monitor device logs and network traffic for crashes, restarts, or anomalous activity and prepare to roll back or isolate affected instances.
- Follow Citrix guidance and change management to deploy fixes and validate service behavior after updates.
Frequently asked questions
Is CVE-2026-88776 being actively exploited?
There are no public reports of exploitation of CVE-2026-88776 as of 2026-09-29.
Which Citrix ADC versions are affected by CVE-2026-88776?
Citrix ADC and Gateway releases are affected: ADC 14.x before 14.1-73.37, ADC 13.x before 13.1-64.23 (including the FIPS/NDcPP builds noted), and Gateway 14.x/13.x before the corresponding fixed builds.
Is there a patch for CVE-2026-88776?
Yes. Citrix published fixes: 14.1-73.37, 13.1-64.23, and the referenced FIPS/NDcPP fixed builds identified for the affected branches.
Does CVE-2026-88776 require authentication?
No. The vulnerability can be triggered over the network without authentication or user interaction against vulnerable Citrix ADC/Gateway builds.
References
- nvd.nist.gov/vuln/detail/CVE-2026-88776
- cve.org/CVERecord?id=CVE-2026-88776
- support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096
- All Citrix CVEs on CVE Radar
- CVEs published in September 2026