VENDOR

Citrix vulnerabilities: CVEs, exploitation and patches

Every Citrix CVE reviewed by Diras Labs analysts, newest first, with exploitation status and fixes.

  1. CVE-2026-88775 CRITICAL 9.8
  2. CVE-2026-88777 CRITICAL 9.8
  3. CVE-2026-88776
    Citrix ADC memory overflow can cause service disruption Citrix ADC ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  4. CVE-2026-88773
    Citrix ADC HTTP request/response smuggling allows pre-auth breach Citrix ADC ·
    • PATCH AVAILABLE
    CRITICAL 10
  5. CVE-2026-8452
    Citrix NetScaler ADC and Gateway memory overflow pre-auth remote code execution Citrix NetScaler ADC and NetScaler Gateway ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.8
  6. CVE-2026-88771
    Improper input validation in NetScaler ADC and Gateway allowing remote command execution Citrix NetScaler ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.8
  7. CVE-2026-88772
    stack-based memory buffer flaw in NetScaler ADC and Gateway Citrix NetScaler ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.1
7 CVEs · page 1 of 1