• PATCH AVAILABLE

CVE-2026-88777: memory overflow in Citrix ADC

An unauthenticated attacker with network access can trigger a memory overflow in Citrix ADC and Citrix Gateway, tracked as CVE-2026-88777, which can cause unpredictable behavior or denial of service. The issue affects ADC 14.x before 14.1-73.37 and 13.x before 13.1-64.23 (including FIPS/NDcPP builds as listed), and Gateway 13.x/14.x before the same fixed releases. No user interaction or valid credentials are required; vulnerable appliances exposed to untrusted networks are at the highest risk.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00384
CWE
CWE-119
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: apply vendor fixes immediately because this is remotely reachable without authentication and Citrix has published fixed firmware versions.

What is CVE-2026-88777?

An unauthenticated attacker with network access can trigger a memory overflow in Citrix ADC and Citrix Gateway, tracked as CVE-2026-88777, which can cause unpredictable behavior or denial of service. The issue affects ADC 14.x before 14.1-73.37 and 13.x before 13.1-64.23 (including FIPS/NDcPP builds as listed), and Gateway 13.x/14.x before the same fixed releases. No user interaction or valid credentials are required; vulnerable appliances exposed to untrusted networks are at the highest risk.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Citrix ADC are affected?

BRANCHAFFECTEDFIXED
ADC 14.xbefore 14.1-73.3714.1-73.37
ADC 13.xbefore 13.1-64.2313.1-64.23
ADC 14.xbefore 14.1-73.37 FIPS14.1-73.37 FIPS
ADC 13.xbefore 13.1.37.279 FIPS and NDcPP13.1.37.279 FIPS and NDcPP
Gateway 14.xbefore 14.1-73.3714.1-73.37
Gateway 13.xbefore 13.1-64.2313.1-64.23

Is CVE-2026-88777 being exploited?

There are no public reports of exploitation or public exploit code as of 2026-09-29.

How to fix CVE-2026-88777

  1. Upgrade ADC 14.x to 14.1-73.37 or later and ADC 13.x to 13.1-64.23 (use the FIPS/NDcPP fixed builds where applicable).
  2. Upgrade Gateway 14.x/13.x to the matching fixed releases listed by Citrix.
  3. Restrict network exposure of appliance management and service interfaces to trusted networks.
  4. Monitor appliance logs and network telemetry for crashes, reboots, or unusual traffic and follow Citrix guidance.

Frequently asked questions

Is CVE-2026-88777 being actively exploited?

There are no public reports of active exploitation or public exploit code for CVE-2026-88777 as of 2026-09-29.

Which Citrix ADC versions are affected by CVE-2026-88777?

Citrix ADC 14.x before 14.1-73.37 and 13.x before 13.1-64.23 are affected, including the FIPS and NDcPP builds noted in vendor advisories.

Is there a patch for CVE-2026-88777?

Yes. Citrix published fixed releases: 14.1-73.37 for ADC/Gateway 14.x and 13.1-64.23 (and 13.1.37.279 for FIPS/NDcPP) for affected 13.x builds.

Does CVE-2026-88777 require authentication?

No. The vulnerability can be triggered by an unauthenticated actor with network access to vulnerable Citrix ADC or Gateway instances.

References