DIRAS TAKE
Urgent: apply vendor fixes immediately because this is remotely reachable without authentication and Citrix has published fixed firmware versions.
What is CVE-2026-88777?
An unauthenticated attacker with network access can trigger a memory overflow in Citrix ADC and Citrix Gateway, tracked as CVE-2026-88777, which can cause unpredictable behavior or denial of service. The issue affects ADC 14.x before 14.1-73.37 and 13.x before 13.1-64.23 (including FIPS/NDcPP builds as listed), and Gateway 13.x/14.x before the same fixed releases. No user interaction or valid credentials are required; vulnerable appliances exposed to untrusted networks are at the highest risk.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Citrix ADC are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| ADC 14.x | before 14.1-73.37 | 14.1-73.37 |
| ADC 13.x | before 13.1-64.23 | 13.1-64.23 |
| ADC 14.x | before 14.1-73.37 FIPS | 14.1-73.37 FIPS |
| ADC 13.x | before 13.1.37.279 FIPS and NDcPP | 13.1.37.279 FIPS and NDcPP |
| Gateway 14.x | before 14.1-73.37 | 14.1-73.37 |
| Gateway 13.x | before 13.1-64.23 | 13.1-64.23 |
Is CVE-2026-88777 being exploited?
There are no public reports of exploitation or public exploit code as of 2026-09-29.
How to fix CVE-2026-88777
- Upgrade ADC 14.x to 14.1-73.37 or later and ADC 13.x to 13.1-64.23 (use the FIPS/NDcPP fixed builds where applicable).
- Upgrade Gateway 14.x/13.x to the matching fixed releases listed by Citrix.
- Restrict network exposure of appliance management and service interfaces to trusted networks.
- Monitor appliance logs and network telemetry for crashes, reboots, or unusual traffic and follow Citrix guidance.
Frequently asked questions
Is CVE-2026-88777 being actively exploited?
There are no public reports of active exploitation or public exploit code for CVE-2026-88777 as of 2026-09-29.
Which Citrix ADC versions are affected by CVE-2026-88777?
Citrix ADC 14.x before 14.1-73.37 and 13.x before 13.1-64.23 are affected, including the FIPS and NDcPP builds noted in vendor advisories.
Is there a patch for CVE-2026-88777?
Yes. Citrix published fixed releases: 14.1-73.37 for ADC/Gateway 14.x and 13.1-64.23 (and 13.1.37.279 for FIPS/NDcPP) for affected 13.x builds.
Does CVE-2026-88777 require authentication?
No. The vulnerability can be triggered by an unauthenticated actor with network access to vulnerable Citrix ADC or Gateway instances.
References
- nvd.nist.gov/vuln/detail/CVE-2026-88777
- cve.org/CVERecord?id=CVE-2026-88777
- support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096&articleTitle=Citrix_NetScaler_ADC_and_Citrix_NetScaler_Gateway_Security_Bulletin_for_CVE_2026_88771_CVE_2026_88772_CVE_2026_88773_CVE_2026_88774_CVE_2026_88775_CVE_2026_88776_CVE_2026_88777_and_CVE_2026_88778
- All Citrix CVEs on CVE Radar
- CVEs published in September 2026