← Back to CVE intelligence
CVE intelligence

CVE-2026-88776

Citrix NetScaler Oracle virtual-server memory overflow

Published Sep 27, 2026Sources checked Sep 27, 2026
8.8HIGHCVSS out of 10
What this means

Review the available evidence

CVE-2026-88776 and is rated High severity with a CVSS score of 8.8. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.

Public exploit: Not collected. Upgrade to the fixed build for your branch: 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, or 13.1-37.279 FIPS/NDcPP, or a later release listed by Citrix.

CISA KEVNot listedBased on the latest collected catalog
EPSSUnavailableNo current score collected
Ransomware useNot markedCISA KEV ransomware field
Threat actors0Source-linked actor relationships
Overview

What is CVE-2026-88776?

Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23  leading to unpredictable or erroneous behavior or Denial of Service