Search

Find a vulnerability

Search criteria

    890 vulnerabilities by Citrix

    CERTFR-2026-AVI-1235

    Vulnerability from certfr_avis - Published: 2026-09-28 - Updated: 2026-09-28

    De multiples vulnérabilités ont été découvertes dans Citrix NetScaler ADC et Gateway. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et un contournement de la politique de sécurité.

    Citrix indique que les vulnérabilités CVE-2026-88771 et CVE-2026-88772 sont activement exploitées.

    L'éditeur indique que si les correctifs n'ont pas été installés, tous les équipements sont vulnérables dans leur configuration par défaut.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    Citrix NetScaler ADC Citrix NetScaler ADC versions 14.1-FIPS antérieures à 14.1-73.37 FIPS
    Citrix NetScaler ADC Citrix NetScaler ADC versions 13.1-FIPS antérieures à 13.1-NDcPP 13.1.37.279
    Citrix NetScaler Gateway NetScaler Gateway versions 13.1.x antérieures à 13.1-64.23
    Citrix NetScaler Gateway NetScaler Gateway versions 14.1.x antérieures à 14.1-73.37
    Citrix NetScaler ADC Citrix NetScaler ADC versions 14.1.x antérieures à 14.1-73.37
    Citrix NetScaler ADC Citrix NetScaler ADC versions 13.1.x antérieures à 13.1-64.23
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "Citrix NetScaler ADC versions 14.1-FIPS ant\u00e9rieures \u00e0 14.1-73.37 FIPS",
          "product": {
            "name": "NetScaler ADC",
            "vendor": {
              "name": "Citrix",
              "scada": false
            }
          }
        },
        {
          "description": "Citrix NetScaler ADC versions 13.1-FIPS ant\u00e9rieures \u00e0 13.1-NDcPP 13.1.37.279",
          "product": {
            "name": "NetScaler ADC",
            "vendor": {
              "name": "Citrix",
              "scada": false
            }
          }
        },
        {
          "description": "NetScaler Gateway versions 13.1.x ant\u00e9rieures \u00e0 13.1-64.23",
          "product": {
            "name": "NetScaler Gateway",
            "vendor": {
              "name": "Citrix",
              "scada": false
            }
          }
        },
        {
          "description": "NetScaler Gateway versions 14.1.x ant\u00e9rieures \u00e0 14.1-73.37",
          "product": {
            "name": "NetScaler Gateway",
            "vendor": {
              "name": "Citrix",
              "scada": false
            }
          }
        },
        {
          "description": "Citrix NetScaler ADC versions 14.1.x ant\u00e9rieures \u00e0 14.1-73.37",
          "product": {
            "name": "NetScaler ADC",
            "vendor": {
              "name": "Citrix",
              "scada": false
            }
          }
        },
        {
          "description": "Citrix NetScaler ADC versions 13.1.x ant\u00e9rieures \u00e0 13.1-64.23",
          "product": {
            "name": "NetScaler ADC",
            "vendor": {
              "name": "Citrix",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2026-88777",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-88777"
        },
        {
          "name": "CVE-2026-88776",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-88776"
        },
        {
          "name": "CVE-2026-88771",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-88771"
        },
        {
          "name": "CVE-2026-88772",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-88772"
        },
        {
          "name": "CVE-2026-88775",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-88775"
        },
        {
          "name": "CVE-2026-88774",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-88774"
        },
        {
          "name": "CVE-2026-88773",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-88773"
        },
        {
          "name": "CVE-2026-88778",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-88778"
        }
      ],
      "initial_release_date": "2026-09-28T00:00:00",
      "last_revision_date": "2026-09-28T00:00:00",
      "links": [
        {
          "title": "Billet de blogue Citrix du 27 septembre 2026",
          "url": "https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/#Indicators_of_Compromise__cabcb4"
        }
      ],
      "reference": "CERTFR-2026-AVI-1235",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-09-28T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service \u00e0 distance"
        },
        {
          "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
        },
        {
          "description": "Non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur"
        },
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans Citrix NetScaler ADC et Gateway. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire \u00e0 distance, un d\u00e9ni de service \u00e0 distance et un contournement de la politique de s\u00e9curit\u00e9.\n\nCitrix indique que les vuln\u00e9rabilit\u00e9s CVE-2026-88771 et CVE-2026-88772 sont activement exploit\u00e9es.\n\nL\u0027\u00e9diteur indique que si les correctifs n\u0027ont pas \u00e9t\u00e9 install\u00e9s, tous les \u00e9quipements sont vuln\u00e9rables dans leur configuration par d\u00e9faut.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans Citrix NetScaler ADC et Gateway",
      "vendor_advisories": [
        {
          "published_at": "2026-09-27",
          "title": "Bulletin de s\u00e9curit\u00e9 Citrix CTX697096",
          "url": "https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096\u0026articleURL=Citrix_NetScaler_ADC_and_Citrix_NetScaler_Gateway_Security_Bulletin_for_CVE_2026_88771_CVE_2026_88772_CVE_2026_88773_CVE_2026_88774_CVE_2026_88775_CVE_2026_88776_CVE_2026_88777_and_CVE_2026_88778"
        }
      ]
    }

    CERTFR-2026-AVI-1137

    Vulnerability from certfr_avis - Published: 2026-09-09 - Updated: 2026-09-09

    De multiples vulnérabilités ont été découvertes dans Citrix Workspace app. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    Citrix Workspace app Workspace app versions antérieures à 2607 LTSR pour Windows
    Citrix Workspace app Workspace app versions antérieures à 2603.11 pour Windows
    Citrix Workspace app Workspace app versions antérieures à 2507.1 LTSR CU3 pour Windows
    References
    Bulletin de sécurité Citrix CTX697034 2026-09-08 vendor-advisory

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "Workspace app versions ant\u00e9rieures \u00e0 2607 LTSR pour Windows",
          "product": {
            "name": "Workspace app",
            "vendor": {
              "name": "Citrix",
              "scada": false
            }
          }
        },
        {
          "description": "Workspace app versions ant\u00e9rieures \u00e0 2603.11 pour Windows",
          "product": {
            "name": "Workspace app",
            "vendor": {
              "name": "Citrix",
              "scada": false
            }
          }
        },
        {
          "description": "Workspace app versions ant\u00e9rieures \u00e0 2507.1 LTSR CU3 pour Windows",
          "product": {
            "name": "Workspace app",
            "vendor": {
              "name": "Citrix",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [],
      "initial_release_date": "2026-09-09T00:00:00",
      "last_revision_date": "2026-09-09T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-1137",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-09-09T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans Citrix Workspace app. Elles permettent \u00e0 un attaquant de provoquer un probl\u00e8me de s\u00e9curit\u00e9 non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans Citrix Workspace app",
      "vendor_advisories": [
        {
          "published_at": "2026-09-08",
          "title": "Bulletin de s\u00e9curit\u00e9 Citrix CTX697034",
          "url": "https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697034\u0026articleURL=Citrix_Workspace_app_for_Windows_Security_Bulletin_CVE_2026_78546_and_CVE_2026_78547"
        }
      ]
    }

    CERTFR-2026-AVI-1059

    Vulnerability from certfr_avis - Published: 2026-08-20 - Updated: 2026-08-20

    De multiples vulnérabilités ont été découvertes dans les produits Citrix. Elles permettent à un attaquant de provoquer un déni de service à distance, un contournement de la politique de sécurité et un problème de sécurité non spécifié par l'éditeur.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    Citrix NetScaler ADC NetScaler ADC versions 14.1-FIPS antérieures à 14.1-73.32 FIPS
    Citrix NetScaler ADC NetScaler ADC versions 13.1-FIPS antérieures à 13.1-NDcPP 13.1-37.277
    Citrix NetScaler ADC NetScaler ADC versions antérieures à 13.1-63.21
    Citrix NetScaler Gateway NetScaler Gateway versions antérieures à 13.1-63.21
    Citrix NetScaler Gateway NetScaler Gateway versions antérieures à 14.1-73.32
    Citrix NetScaler ADC NetScaler ADC  versions antérieures à 14.1-73.32
    References
    Bulletin de sécurité Citrix CTX696939 2026-08-19 vendor-advisory

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "NetScaler ADC versions 14.1-FIPS ant\u00e9rieures \u00e0 14.1-73.32 FIPS",
          "product": {
            "name": "NetScaler ADC",
            "vendor": {
              "name": "Citrix",
              "scada": false
            }
          }
        },
        {
          "description": "NetScaler ADC versions 13.1-FIPS ant\u00e9rieures \u00e0 13.1-NDcPP 13.1-37.277",
          "product": {
            "name": "NetScaler ADC",
            "vendor": {
              "name": "Citrix",
              "scada": false
            }
          }
        },
        {
          "description": "NetScaler ADC versions ant\u00e9rieures \u00e0 13.1-63.21",
          "product": {
            "name": "NetScaler ADC",
            "vendor": {
              "name": "Citrix",
              "scada": false
            }
          }
        },
        {
          "description": "NetScaler Gateway versions ant\u00e9rieures \u00e0 13.1-63.21",
          "product": {
            "name": "NetScaler Gateway",
            "vendor": {
              "name": "Citrix",
              "scada": false
            }
          }
        },
        {
          "description": "NetScaler Gateway versions ant\u00e9rieures \u00e0 14.1-73.32",
          "product": {
            "name": "NetScaler Gateway",
            "vendor": {
              "name": "Citrix",
              "scada": false
            }
          }
        },
        {
          "description": "NetScaler ADC\u202f versions ant\u00e9rieures \u00e0 14.1-73.32",
          "product": {
            "name": "NetScaler ADC",
            "vendor": {
              "name": "Citrix",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2026-19489",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-19489"
        },
        {
          "name": "CVE-2026-19490",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-19490"
        }
      ],
      "initial_release_date": "2026-08-20T00:00:00",
      "last_revision_date": "2026-08-20T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-1059",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-08-20T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service \u00e0 distance"
        },
        {
          "description": "Non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur"
        },
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits Citrix. Elles permettent \u00e0 un attaquant de provoquer un d\u00e9ni de service \u00e0 distance, un contournement de la politique de s\u00e9curit\u00e9 et un probl\u00e8me de s\u00e9curit\u00e9 non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits Citrix",
      "vendor_advisories": [
        {
          "published_at": "2026-08-19",
          "title": "Bulletin de s\u00e9curit\u00e9 Citrix CTX696939",
          "url": "https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939\u0026articleURL=NetScaler_ADC_and_NetScaler_Gateway_Security_Bulletin_for_CVE_2026_19489_and_CVE_2026_19490"
        }
      ]
    }

    CERTFR-2026-AVI-0941

    Vulnerability from certfr_avis - Published: 2026-07-29 - Updated: 2026-07-29

    De multiples vulnérabilités ont été découvertes dans Citrix XenServer. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et un problème de sécurité non spécifié par l'éditeur.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    Citrix XenServer XenServer versions 8.4 sans le dernier correctif de sécurité
    Citrix XenServer XenServer versions 9 sans le dernier correctif de sécurité
    References
    Bulletin de sécurité Citrix CTX696836 2026-07-28 vendor-advisory

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "XenServer versions 8.4 sans le dernier correctif de s\u00e9curit\u00e9",
          "product": {
            "name": "XenServer",
            "vendor": {
              "name": "Citrix",
              "scada": false
            }
          }
        },
        {
          "description": "XenServer versions 9 sans le dernier correctif de s\u00e9curit\u00e9",
          "product": {
            "name": "XenServer",
            "vendor": {
              "name": "Citrix",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2026-42492",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42492"
        },
        {
          "name": "CVE-2026-62428",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-62428"
        },
        {
          "name": "CVE-2026-62436",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-62436"
        },
        {
          "name": "CVE-2026-62434",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-62434"
        },
        {
          "name": "CVE-2026-62432",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-62432"
        },
        {
          "name": "CVE-2026-62435",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-62435"
        },
        {
          "name": "CVE-2026-62431",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-62431"
        }
      ],
      "initial_release_date": "2026-07-29T00:00:00",
      "last_revision_date": "2026-07-29T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-0941",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-07-29T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service \u00e0 distance"
        },
        {
          "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
        },
        {
          "description": "Non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans Citrix XenServer. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire \u00e0 distance, un d\u00e9ni de service \u00e0 distance et un probl\u00e8me de s\u00e9curit\u00e9 non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans Citrix XenServer",
      "vendor_advisories": [
        {
          "published_at": "2026-07-28",
          "title": "Bulletin de s\u00e9curit\u00e9 Citrix CTX696836",
          "url": "https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696836\u0026articleURL=XenServer_Security_Update_for_Multiple_Issues"
        }
      ]
    }

    CERTFR-2026-AVI-0885

    Vulnerability from certfr_avis - Published: 2026-07-15 - Updated: 2026-07-15

    De multiples vulnérabilités ont été découvertes dans les produits Citrix. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité des données et un contournement de la politique de sécurité.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    Citrix Citrix Secure Access client Secure Access Client versions antérieures à 26.6.1.20 pour Windows
    Citrix N/A Endpoint Analysis Client versions antérieures à 26.5.1.7 pour Windows
    Citrix XenServer XenCenter versions antérieures à 2026.4.0
    Citrix XenServer XenCenter SDK client versions antérieures à 26.15.0 pour PowerShell et C#
    References
    Bulletin de sécurité Citrix CTX696811 2026-07-14 vendor-advisory
    Bulletin de sécurité Citrix CTX696734 2026-07-14 vendor-advisory

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "Secure Access Client versions ant\u00e9rieures \u00e0 26.6.1.20 pour Windows",
          "product": {
            "name": "Citrix Secure Access client",
            "vendor": {
              "name": "Citrix",
              "scada": false
            }
          }
        },
        {
          "description": "Endpoint Analysis Client versions ant\u00e9rieures \u00e0 26.5.1.7 pour Windows",
          "product": {
            "name": "N/A",
            "vendor": {
              "name": "Citrix",
              "scada": false
            }
          }
        },
        {
          "description": "XenCenter versions ant\u00e9rieures \u00e0 2026.4.0",
          "product": {
            "name": "XenServer",
            "vendor": {
              "name": "Citrix",
              "scada": false
            }
          }
        },
        {
          "description": "XenCenter SDK client versions ant\u00e9rieures \u00e0 26.15.0 pour PowerShell et C#",
          "product": {
            "name": "XenServer",
            "vendor": {
              "name": "Citrix",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2026-53565",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53565"
        },
        {
          "name": "CVE-2026-42491",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42491"
        },
        {
          "name": "CVE-2026-53566",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53566"
        }
      ],
      "initial_release_date": "2026-07-15T00:00:00",
      "last_revision_date": "2026-07-15T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-0885",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-07-15T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        },
        {
          "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
        },
        {
          "description": "\u00c9l\u00e9vation de privil\u00e8ges"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits Citrix. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une \u00e9l\u00e9vation de privil\u00e8ges, une atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es et un contournement de la politique de s\u00e9curit\u00e9.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits Citrix",
      "vendor_advisories": [
        {
          "published_at": "2026-07-14",
          "title": "Bulletin de s\u00e9curit\u00e9 Citrix CTX696811",
          "url": "https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696811\u0026articleURL=XenServer_Security_Update_for_CVE_2026_42491"
        },
        {
          "published_at": "2026-07-14",
          "title": "Bulletin de s\u00e9curit\u00e9 Citrix CTX696734",
          "url": "https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696734\u0026articleURL=Citrix_Secure_Access_Client_for_Windows_and_Citrix_Endpoint_Analysis_Client_for_Windows_Security_Bulletin_for_CVE_2026_53565_and_CVE_2026_53566"
        }
      ]
    }

    CERTFR-2026-ALE-011

    Vulnerability from certfr_alerte - Published: 2026-09-28 - Updated: 2026-09-30

    [Mise à jour du 30 septembre 2026]
    Dans un billet de blogue du 29 septembre 2026 (cf. section Documentation), Mandiant et Google Threat Intelligence Group (GTIG) fournissent des indicateurs de compromission ainsi que des règles de détection au format YARA. Ceux-ci n'ont pas été qualifiés par l'ANSSI.

    Selon Google, la présence de ces motifs est caractéristique d'une exploitation réussie: * 0-PPE-0 : default SSLLOG SSL_HANDSHAKE_FAILURE 0 : SPCBId - ClientIP - ClientPort - VserverServiceIP - VserverServicePort 443 - ClientVersion DTLSv1.0 - CipherSuite "TLS1-AES-256-CBC-SHA" - Session New - Reason "Handshake failure-Internal Error" (dans Syslog) * qat0: Process NSPPE-<##> exit with orphan rings 5:500
    pitboss[<##>]: pitboss NOT restarting NSPPE-<##> (\<PID>)
    (dans /var/log/messages)

    Le CERT-FR a également connaissance d'une preuve de concept publique pour la vulnérabilité CVE-2026-88772.

    [Publication Initiale]
    Le 27 septembre 2026, Citrix a publié un avis de sécurité concernant plusieurs vulnérabilités qui affectent NetScaler ADC et Gateway. Parmi celles-ci, les vulnérabilités CVE-2026-88771 et CVE-2026-88772 permettent une exécution de code arbitraire à distance par un attaquant non authentifié.

    Ces vulnérabilités sont activement exploitées et les exploitations ont commencé avant la disponibilité des correctifs.

    De plus, l'éditeur indique que si les correctifs n'ont pas été installés, tous les équipements sont vulnérables dans leur configuration par défaut.

    Dans son billet de blogue (cf. section Documentation), Citrix indique mettre des indicateurs de compromission à disposition de ses clients par le biais de la console Netscaler.

    [Mise à jour du 28 septembre 2026]
    Le CERT-FR a connaissance d'une preuve de concept publique pour la vulnérabilité CVE-2026-88771.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    Citrix NetScaler ADC Citrix NetScaler ADC versions 14.1-FIPS antérieures à 14.1-73.37 FIPS
    Citrix NetScaler ADC Citrix NetScaler ADC versions 13.1-FIPS antérieures à 13.1-NDcPP 13.1.37.279
    Citrix NetScaler Gateway NetScaler Gateway versions 13.1.x antérieures à 13.1-64.23
    Citrix NetScaler Gateway NetScaler Gateway versions 14.1.x antérieures à 14.1-73.37
    Citrix NetScaler ADC Citrix NetScaler ADC versions 14.1.x antérieures à 14.1-73.37
    Citrix NetScaler ADC Citrix NetScaler ADC versions 13.1.x antérieures à 13.1-64.23

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "Citrix NetScaler ADC versions 14.1-FIPS ant\u00e9rieures \u00e0 14.1-73.37 FIPS",
          "product": {
            "name": "NetScaler ADC",
            "vendor": {
              "name": "Citrix",
              "scada": false
            }
          }
        },
        {
          "description": "Citrix NetScaler ADC versions 13.1-FIPS ant\u00e9rieures \u00e0 13.1-NDcPP 13.1.37.279",
          "product": {
            "name": "NetScaler ADC",
            "vendor": {
              "name": "Citrix",
              "scada": false
            }
          }
        },
        {
          "description": "NetScaler Gateway versions 13.1.x ant\u00e9rieures \u00e0 13.1-64.23",
          "product": {
            "name": "NetScaler Gateway",
            "vendor": {
              "name": "Citrix",
              "scada": false
            }
          }
        },
        {
          "description": "NetScaler Gateway versions 14.1.x ant\u00e9rieures \u00e0 14.1-73.37",
          "product": {
            "name": "NetScaler Gateway",
            "vendor": {
              "name": "Citrix",
              "scada": false
            }
          }
        },
        {
          "description": "Citrix NetScaler ADC versions 14.1.x ant\u00e9rieures \u00e0 14.1-73.37",
          "product": {
            "name": "NetScaler ADC",
            "vendor": {
              "name": "Citrix",
              "scada": false
            }
          }
        },
        {
          "description": "Citrix NetScaler ADC versions 13.1.x ant\u00e9rieures \u00e0 13.1-64.23",
          "product": {
            "name": "NetScaler ADC",
            "vendor": {
              "name": "Citrix",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "closed_at": null,
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2026-88771",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-88771"
        },
        {
          "name": "CVE-2026-88772",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-88772"
        }
      ],
      "initial_release_date": "2026-09-28T00:00:00",
      "last_revision_date": "2026-09-30T00:00:00",
      "links": [
        {
          "title": "Billet de blogue Google du 29 septembre 2026",
          "url": "https://cloud.google.com/blog/topics/threat-intelligence/defending-against-active-exploitation-of-citrix-netscaler-adc-and-gateway-appliances"
        },
        {
          "title": "Billet de blogue Citrix du 27 septembre 2026",
          "url": "https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/#Indicators_of_Compromise__cabcb4"
        },
        {
          "title": "Avis CERT-FR CERTFR-2026-AVI-1235 du 28 septembre 2026",
          "url": "/avis/CERTFR-2026-AVI-1235/"
        }
      ],
      "reference": "CERTFR-2026-ALE-011",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-09-28T00:00:00.000000"
        },
        {
          "description": "Ajout de l\u0027existence d\u0027une preuve de concept pour la vuln\u00e9rabilit\u00e9 CVE-2026-88771.",
          "revision_date": "2026-09-28T00:00:00.000000"
        },
        {
          "description": "Ajout du billet de blogue Google et des indicateurs de compromission.",
          "revision_date": "2026-09-30T00:00:00.000000"
        },
        {
          "description": "Ajout de l\u0027existence d\u0027une preuve de concept pour la vuln\u00e9rabilit\u00e9 CVE-2026-88772.",
          "revision_date": "2026-09-30T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service \u00e0 distance"
        },
        {
          "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
        }
      ],
      "summary": "\u003cspan class=\"important-content\"\u003e[Mise \u00e0 jour du 30 septembre 2026]\u003c/span\u003e\u003cbr\u003e\nDans un billet de blogue du 29 septembre 2026 (cf. section Documentation), Mandiant et Google Threat Intelligence Group (GTIG) fournissent des indicateurs de compromission ainsi que des r\u00e8gles de d\u00e9tection au format YARA. Ceux-ci n\u0027ont pas \u00e9t\u00e9 qualifi\u00e9s par l\u0027ANSSI.\n\nSelon Google, la pr\u00e9sence de ces motifs est caract\u00e9ristique d\u0027une exploitation r\u00e9ussie:\n* \u003ccode\u003e0-PPE-0 : default SSLLOG SSL_HANDSHAKE_FAILURE 0 : SPCBId - ClientIP - ClientPort - VserverServiceIP - VserverServicePort 443 - ClientVersion DTLSv1.0 - CipherSuite \"TLS1-AES-256-CBC-SHA\" - Session New - Reason \"Handshake failure-Internal Error\"\u003c/code\u003e (dans *Syslog*)\n* \u003ccode\u003eqat0: Process \u003cPID\u003e NSPPE-\u003c##\u003e exit with orphan rings 5:500\n\u003cbr\u003epitboss[\u003c##\u003e]: pitboss \u003cDATETIME\u003e NOT restarting NSPPE-\u003c##\u003e (\\\u003cPID\\\u003e)\u003c/code\u003e (dans */var/log/messages*)\n\nLe CERT-FR a \u00e9galement connaissance d\u0027une preuve de concept publique pour la vuln\u00e9rabilit\u00e9 CVE-2026-88772.\n\n**[Publication Initiale]**\u003cbr\u003e\nLe 27 septembre 2026, Citrix a publi\u00e9 un avis de s\u00e9curit\u00e9 concernant plusieurs vuln\u00e9rabilit\u00e9s qui affectent NetScaler ADC et Gateway. \nParmi celles-ci, les vuln\u00e9rabilit\u00e9s CVE-2026-88771 et CVE-2026-88772 permettent une ex\u00e9cution de code arbitraire \u00e0 distance par un attaquant non authentifi\u00e9. \n\nCes vuln\u00e9rabilit\u00e9s sont activement exploit\u00e9es et les exploitations ont commenc\u00e9 avant la disponibilit\u00e9 des correctifs.\n\nDe plus, l\u0027\u00e9diteur indique que si les correctifs n\u0027ont pas \u00e9t\u00e9 install\u00e9s, tous les \u00e9quipements sont vuln\u00e9rables dans leur configuration par d\u00e9faut.\n\nDans son billet de blogue (cf. section Documentation), Citrix indique mettre des indicateurs de compromission \u00e0 disposition de ses clients par le biais de la console Netscaler.\n\n**[Mise \u00e0 jour du 28 septembre 2026]**\u003cbr\u003e\nLe CERT-FR a connaissance d\u0027une preuve de concept publique pour la vuln\u00e9rabilit\u00e9 CVE-2026-88771.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans Citrix NetScaler ADC et Gateway",
      "vendor_advisories": [
        {
          "published_at": "2026-09-27",
          "title": "Bulletin de s\u00e9curit\u00e9 Citrix CTX697096",
          "url": "https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096\u0026articleURL=Citrix_NetScaler_ADC_and_Citrix_NetScaler_Gateway_Security_Bulletin_for_CVE_2026_88771_CVE_2026_88772_CVE_2026_88773_CVE_2026_88774_CVE_2026_88775_CVE_2026_88776_CVE_2026_88777_and_CVE_2026_88778"
        }
      ]
    }

    CVE-2026-88778 (GCVE-0-2026-88778)

    Vulnerability from nvd – Published: 2026-09-27 16:43 – Updated: 2026-09-29 16:35
    VLAI
    Title
    TCP Initial Sequence Number (ISN) prediction
    Summary
    Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 16:34 UTC
    CWE
    • CWE-342 - Predictable exact value from previous values
    Impacted products
    Vendor Product Version
    Citrix NetScaler ADC Affected: 0 , < 14.1-73.37 (Patch)
    Affected: 0 , < 13.1-64.23 (Patch)
    Affected: 0 , < 14.1-73.37 FIPS (Patch)
    Affected: 0 , < 13.1.37.279 FIPS and NDcPP (Patch)
    Create a notification for this product.
    Citrix NetScaler Gateway Affected: 0 , < 14.1-73.37 (Patch)
    Affected: 0 , < 13.1-64.23 (Patch)
    Create a notification for this product.
    Date Public
    2026-09-27 15:30
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88778",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T16:34:20.349812Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T16:35:06.769Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ADC",
              "vendor": "Citrix NetScaler",
              "versions": [
                {
                  "lessThan": "14.1-73.37",
                  "status": "affected",
                  "version": "0",
                  "versionType": "Patch"
                },
                {
                  "lessThan": "13.1-64.23",
                  "status": "affected",
                  "version": "0",
                  "versionType": "Patch"
                },
                {
                  "lessThan": "14.1-73.37 FIPS",
                  "status": "affected",
                  "version": "0",
                  "versionType": "Patch"
                },
                {
                  "lessThan": "13.1.37.279 FIPS and NDcPP",
                  "status": "affected",
                  "version": "0",
                  "versionType": "Patch"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Gateway",
              "vendor": "Citrix NetScaler",
              "versions": [
                {
                  "lessThan": "14.1-73.37",
                  "status": "affected",
                  "version": "0",
                  "versionType": "Patch"
                },
                {
                  "lessThan": "13.1-64.23",
                  "status": "affected",
                  "version": "0",
                  "versionType": "Patch"
                }
              ]
            }
          ],
          "datePublic": "2026-09-27T15:30:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.\u003cp\u003eThis issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23.\u003c/p\u003e"
                }
              ],
              "value": "Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.\n\nThis issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "LOW",
                "subConfidentialityImpact": "LOW",
                "subIntegrityImpact": "LOW",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:L/SI:L/SA:L",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-342",
                  "description": "CWE-342 Predictable exact value from previous values",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-27T16:43:16.503Z",
            "orgId": "50a63c94-1ea7-4568-8c11-eb79e7c5a2b5",
            "shortName": "NetScaler"
          },
          "references": [
            {
              "url": "https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "TCP Initial Sequence Number (ISN) prediction",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "50a63c94-1ea7-4568-8c11-eb79e7c5a2b5",
        "assignerShortName": "NetScaler",
        "cveId": "CVE-2026-88778",
        "datePublished": "2026-09-27T16:43:16.503Z",
        "dateReserved": "2026-09-10T07:14:57.370Z",
        "dateUpdated": "2026-09-29T16:35:06.769Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-88777 (GCVE-0-2026-88777)

    Vulnerability from nvd – Published: 2026-09-27 16:37 – Updated: 2026-09-29 21:01
    VLAI
    Title
    Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service
    Summary
    Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23  leading to unpredictable or erroneous behavior or Denial of Service
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 15:07 UTC
    CWE
    • CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer
    Impacted products
    Vendor Product Version
    Citrix NetScaler ADC Affected: 0 , < 14.1-73.37 (patch)
    Affected: 0 , < 13.1-64.23 (patch)
    Affected: 0 , < 14.1-73.37 FIPS (patch)
    Affected: 0 , < 13.1.37.279 FIPS and NDcPP (patch)
    Create a notification for this product.
    Citrix NetScaler Gateway Affected: 0 , < 14.1-73.37 (patch)
    Affected: 0 , < 13.1-64.23 (patch)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88777",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T15:07:18.195758Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-119",
                    "description": "CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T21:01:24.942Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ADC",
              "vendor": "Citrix NetScaler",
              "versions": [
                {
                  "lessThan": "14.1-73.37",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "13.1-64.23",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "14.1-73.37 FIPS",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "13.1.37.279 FIPS and NDcPP",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Gateway",
              "vendor": "Citrix NetScaler",
              "versions": [
                {
                  "lessThan": "14.1-73.37",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "13.1-64.23",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.\u003cp\u003eThis issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23\u0026nbsp;\u003cspan\u003e\u0026nbsp;leading to unpredictable or erroneous behavior or Denial of Service\u003c/span\u003e\u003c/p\u003e"
                }
              ],
              "value": "Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.\n\nThis issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23\u00a0\u00a0leading to unpredictable or erroneous behavior or Denial of Service"
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-27T16:37:44.345Z",
            "orgId": "50a63c94-1ea7-4568-8c11-eb79e7c5a2b5",
            "shortName": "NetScaler"
          },
          "references": [
            {
              "url": "https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096\u0026articleTitle=Citrix_NetScaler_ADC_and_Citrix_NetScaler_Gateway_Security_Bulletin_for_CVE_2026_88771_CVE_2026_88772_CVE_2026_88773_CVE_2026_88774_CVE_2026_88775_CVE_2026_88776_CVE_2026_88777_and_CVE_2026_88778"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service",
          "x_generator": {
            "engine": "Vulnogram 1.0.4"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "50a63c94-1ea7-4568-8c11-eb79e7c5a2b5",
        "assignerShortName": "NetScaler",
        "cveId": "CVE-2026-88777",
        "datePublished": "2026-09-27T16:37:44.345Z",
        "dateReserved": "2026-09-10T07:14:57.370Z",
        "dateUpdated": "2026-09-29T21:01:24.942Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-88776 (GCVE-0-2026-88776)

    Vulnerability from nvd – Published: 2026-09-27 16:36 – Updated: 2026-09-29 16:06
    VLAI
    Title
    Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service
    Summary
    Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23  leading to unpredictable or erroneous behavior or Denial of Service
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 15:11 UTC
    CWE
    • CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer
    Impacted products
    Vendor Product Version
    Citrix NetScaler ADC Affected: 0 , < 14.1-73.37 (patch)
    Affected: 0 , < 13.1-64.23 (patch)
    Affected: 0 , < 14.1-73.37 FIPS (patch)
    Affected: 0 , < 13.1.37.279 FIPS and NDcPP (patch)
    Create a notification for this product.
    Citrix NetScaler Gateway Affected: 0 , < 14.1-73.37 (patch)
    Affected: 0 , < 13.1-64.23 (patch)
    Create a notification for this product.
    Date Public
    2026-09-27 15:30
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88776",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T15:11:33.607861Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-119",
                    "description": "CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T16:06:45.542Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ADC",
              "vendor": "Citrix NetScaler",
              "versions": [
                {
                  "lessThan": "14.1-73.37",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "13.1-64.23",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "14.1-73.37 FIPS",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "13.1.37.279 FIPS and NDcPP",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Gateway",
              "vendor": "Citrix NetScaler",
              "versions": [
                {
                  "lessThan": "14.1-73.37",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "13.1-64.23",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                }
              ]
            }
          ],
          "datePublic": "2026-09-27T15:30:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.\u003cbr\u003eThis issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23\u0026nbsp;\u0026nbsp;leading to unpredictable or erroneous behavior or Denial of Service"
                }
              ],
              "value": "Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.\nThis issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23\u00a0\u00a0leading to unpredictable or erroneous behavior or Denial of Service"
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-27T16:36:40.034Z",
            "orgId": "50a63c94-1ea7-4568-8c11-eb79e7c5a2b5",
            "shortName": "NetScaler"
          },
          "references": [
            {
              "url": "https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "50a63c94-1ea7-4568-8c11-eb79e7c5a2b5",
        "assignerShortName": "NetScaler",
        "cveId": "CVE-2026-88776",
        "datePublished": "2026-09-27T16:36:40.034Z",
        "dateReserved": "2026-09-10T07:14:57.369Z",
        "dateUpdated": "2026-09-29T16:06:45.542Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-88775 (GCVE-0-2026-88775)

    Vulnerability from nvd – Published: 2026-09-27 16:21 – Updated: 2026-09-29 15:15
    VLAI
    Title
    Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service
    Summary
    Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 15:14 UTC
    CWE
    • CWE-120 - Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
    Impacted products
    Vendor Product Version
    Citrix NetScaler ADC Affected: 0 , < 14.1-73.37 (patch)
    Affected: 0 , < 13.1-64.23 (patch)
    Affected: 0 , < 14.1-73.37 FIPS (patch)
    Affected: 0 , < 13.1.37.279 FIPS and NDcPP (patch)
    Create a notification for this product.
    Citrix NetScaler Gateway Affected: 0 , < 14.1-73.37 (patch)
    Affected: 0 , < 13.1-64.23 (patch)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88775",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T15:14:54.128931Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-120",
                    "description": "CWE-120 Buffer Copy without Checking Size of Input (\u0027Classic Buffer Overflow\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T15:15:39.206Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ADC",
              "vendor": "Citrix NetScaler",
              "versions": [
                {
                  "lessThan": "14.1-73.37",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "13.1-64.23",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "14.1-73.37 FIPS",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "13.1.37.279 FIPS and NDcPP",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Gateway",
              "vendor": "Citrix NetScaler",
              "versions": [
                {
                  "lessThan": "14.1-73.37",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "13.1-64.23",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.\u003cp\u003eThis issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading\u0026nbsp;\u003cspan\u003eMemory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service\u003c/span\u003e\u003c/p\u003e"
                }
              ],
              "value": "Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.\n\nThis issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading\u00a0Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service"
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-27T16:38:24.106Z",
            "orgId": "50a63c94-1ea7-4568-8c11-eb79e7c5a2b5",
            "shortName": "NetScaler"
          },
          "references": [
            {
              "url": "https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096\u0026articleTitle=Citrix_NetScaler_ADC_and_Citrix_NetScaler_Gateway_Security_Bulletin_for_CVE_2026_88771_CVE_2026_88772_CVE_2026_88773_CVE_2026_88774_CVE_2026_88775_CVE_2026_88776_CVE_2026_88777_and_CVE_2026_88778"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service",
          "x_generator": {
            "engine": "Vulnogram 1.0.4"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "50a63c94-1ea7-4568-8c11-eb79e7c5a2b5",
        "assignerShortName": "NetScaler",
        "cveId": "CVE-2026-88775",
        "datePublished": "2026-09-27T16:21:12.160Z",
        "dateReserved": "2026-09-10T07:14:57.369Z",
        "dateUpdated": "2026-09-29T15:15:39.206Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-88774 (GCVE-0-2026-88774)

    Vulnerability from nvd – Published: 2026-09-27 16:14 – Updated: 2026-09-29 15:24
    VLAI
    Title
    Feature policy bypass due to improper HTTP URL based expression usage
    Summary
    Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to a feature policy bypass due to improper HTTP URL based expression usage.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 15:22 UTC
    CWE
    • CWE-20 - Improper Input Validation
    Impacted products
    Vendor Product Version
    Citrix NetScaler ADC Affected: 0 , < 14.1-73.37 (patch)
    Affected: 0 , < 13.1-64.23 (patch)
    Affected: 0 , < 14.1-73.37 FIPS (patch)
    Affected: 0 , < 13.1.37.279 FIPS and NDcPP (patch)
    Create a notification for this product.
    Citrix NetScaler Gateway Affected: 0 , < 14.1-73.37 (patch)
    Affected: 0 , < 13.1-64.23 (patch)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88774",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T15:22:52.478269Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-20",
                    "description": "CWE-20 Improper Input Validation",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T15:24:29.082Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ADC",
              "vendor": "Citrix NetScaler",
              "versions": [
                {
                  "lessThan": "14.1-73.37",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "13.1-64.23",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "14.1-73.37 FIPS",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "13.1.37.279 FIPS and NDcPP",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Gateway",
              "vendor": "Citrix NetScaler",
              "versions": [
                {
                  "lessThan": "14.1-73.37",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "13.1-64.23",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.\u003cp\u003eThis issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to a f\u003cspan\u003eeature policy bypass due to improper HTTP URL based expression usage.\u003c/span\u003e\u003c/p\u003e"
                }
              ],
              "value": "Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.\n\nThis issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to a feature policy bypass due to improper HTTP URL based expression usage."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 7,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-27T16:14:02.993Z",
            "orgId": "50a63c94-1ea7-4568-8c11-eb79e7c5a2b5",
            "shortName": "NetScaler"
          },
          "references": [
            {
              "url": "https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096\u0026articleTitle=Citrix_NetScaler_ADC_and_Citrix_NetScaler_Gateway_Security_Bulletin_for_CVE_2026_88771_CVE_2026_88772_CVE_2026_88773_CVE_2026_88774_CVE_2026_88775_CVE_2026_88776_CVE_2026_88777_and_CVE_2026_88778"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Feature policy bypass due to improper HTTP URL based expression usage",
          "x_generator": {
            "engine": "Vulnogram 1.0.4"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "50a63c94-1ea7-4568-8c11-eb79e7c5a2b5",
        "assignerShortName": "NetScaler",
        "cveId": "CVE-2026-88774",
        "datePublished": "2026-09-27T16:14:02.993Z",
        "dateReserved": "2026-09-10T07:14:57.369Z",
        "dateUpdated": "2026-09-29T15:24:29.082Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-88773 (GCVE-0-2026-88773)

    Vulnerability from nvd – Published: 2026-09-27 16:20 – Updated: 2026-09-29 15:21
    VLAI
    Title
    HTTP Request Smuggling
    Summary
    Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before 13.1-64.23.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 15:17 UTC
    CWE
    • CWE-444 - Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling')
    Impacted products
    Vendor Product Version
    Citrix NetScaler ADC Affected: 0 , < 14.1-73.37 (Patch)
    Affected: 0 , < 13.1-64.23 (Patch)
    Affected: 0 , < 14.1-73.37 FIPS (Patch)
    Affected: 0 , < 13.1-37.279 and NDcPP (Patch)
    Create a notification for this product.
    Citrix NetScaler Gateway Affected: 0 , < 14.1-73.37 FIPS (Patch)
    Affected: 0 , < 13.1-64.23 (Patch)
    Create a notification for this product.
    Date Public
    2026-09-27 15:30
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88773",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T15:17:32.077580Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T15:21:44.819Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ADC",
              "vendor": "Citrix NetScaler",
              "versions": [
                {
                  "lessThan": "14.1-73.37",
                  "status": "affected",
                  "version": "0",
                  "versionType": "Patch"
                },
                {
                  "lessThan": "13.1-64.23",
                  "status": "affected",
                  "version": "0",
                  "versionType": "Patch"
                },
                {
                  "lessThan": "14.1-73.37 FIPS",
                  "status": "affected",
                  "version": "0",
                  "versionType": "Patch"
                },
                {
                  "lessThan": "13.1-37.279 and NDcPP",
                  "status": "affected",
                  "version": "0",
                  "versionType": "Patch"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Gateway",
              "vendor": "Citrix NetScaler",
              "versions": [
                {
                  "lessThan": "14.1-73.37 FIPS",
                  "status": "affected",
                  "version": "0",
                  "versionType": "Patch"
                },
                {
                  "lessThan": "13.1-64.23",
                  "status": "affected",
                  "version": "0",
                  "versionType": "Patch"
                }
              ]
            }
          ],
          "datePublic": "2026-09-27T15:30:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Inconsistent interpretation of HTTP requests (\u0027HTTP Request/Response smuggling\u0027) vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.\u003cp\u003eThis issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before 13.1-64.23.\u003c/p\u003e"
                }
              ],
              "value": "Inconsistent interpretation of HTTP requests (\u0027HTTP Request/Response smuggling\u0027) vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.\n\nThis issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before 13.1-64.23."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 9.3,
                "baseSeverity": "CRITICAL",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-444",
                  "description": "CWE-444 Inconsistent interpretation of HTTP requests (\u0027HTTP Request/Response smuggling\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-27T16:20:08.382Z",
            "orgId": "50a63c94-1ea7-4568-8c11-eb79e7c5a2b5",
            "shortName": "NetScaler"
          },
          "references": [
            {
              "url": "https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "HTTP Request Smuggling",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "50a63c94-1ea7-4568-8c11-eb79e7c5a2b5",
        "assignerShortName": "NetScaler",
        "cveId": "CVE-2026-88773",
        "datePublished": "2026-09-27T16:20:08.382Z",
        "dateReserved": "2026-09-10T07:14:57.369Z",
        "dateUpdated": "2026-09-29T15:21:44.819Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-88772 (GCVE-0-2026-88772)

    Vulnerability from nvd – Published: 2026-09-27 16:09 – Updated: 2026-09-28 03:55
    VLAI CISA CIRCL ENISA Previdian
    Title
    Memory overflow vulnerability leading to Remote Code Execution or Denial of Service
    Summary
    Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service
    SSVC
    Exploitation: active Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-27 00:00 UTC
    CWE
    • CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer
    Impacted products
    Vendor Product Version
    Citrix NetScaler ADC Affected: 0 , < 14.1-73.37 (patch)
    Affected: 0 , < 13.1-64.23 (patch)
    Affected: 0 , < 14.1-73.37 FIPS (patch)
    Affected: 0 , < 13.1.37.279 FIPS and NDcPP (patch)
    Create a notification for this product.
    Citrix NetScaler Gateway Affected: 0 , < 14.1-73.37 (patch)
    Affected: 0 , < 13.1-64.23 (patch)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88772",
                    "options": [
                      {
                        "Exploitation": "active"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-27T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              },
              {
                "other": {
                  "content": {
                    "dateAdded": "2026-09-27",
                    "reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-88772"
                  },
                  "type": "kev"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-119",
                    "description": "CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-28T03:55:42.777Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "government-resource"
                ],
                "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-88772"
              }
            ],
            "timeline": [
              {
                "lang": "en",
                "time": "2026-09-27T00:00:00.000Z",
                "value": "CVE-2026-88772 added to CISA KEV"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ADC",
              "vendor": "Citrix NetScaler",
              "versions": [
                {
                  "lessThan": "14.1-73.37",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "13.1-64.23",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "14.1-73.37 FIPS",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "13.1.37.279 FIPS and NDcPP",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Gateway",
              "vendor": "Citrix NetScaler",
              "versions": [
                {
                  "lessThan": "14.1-73.37",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "13.1-64.23",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.\u003cp\u003eThis issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23\u0026nbsp;\u003cspan\u003eleading to Remote Code Execution or Denial of Service\u003c/span\u003e\u003c/p\u003e"
                }
              ],
              "value": "Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.\n\nThis issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23\u00a0leading to Remote Code Execution or Denial of Service"
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "HIGH",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 9.5,
                "baseSeverity": "CRITICAL",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-27T16:09:56.033Z",
            "orgId": "50a63c94-1ea7-4568-8c11-eb79e7c5a2b5",
            "shortName": "NetScaler"
          },
          "references": [
            {
              "url": "https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096\u0026articleTitle=Citrix_NetScaler_ADC_and_Citrix_NetScaler_Gateway_Security_Bulletin_for_CVE_2026_88771_CVE_2026_88772_CVE_2026_88773_CVE_2026_88774_CVE_2026_88775_CVE_2026_88776_CVE_2026_88777_and_CVE_2026_88778"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Memory overflow vulnerability leading to Remote Code Execution or Denial of Service",
          "x_generator": {
            "engine": "Vulnogram 1.0.4"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "50a63c94-1ea7-4568-8c11-eb79e7c5a2b5",
        "assignerShortName": "NetScaler",
        "cveId": "CVE-2026-88772",
        "datePublished": "2026-09-27T16:09:56.033Z",
        "dateReserved": "2026-09-10T07:14:57.369Z",
        "dateUpdated": "2026-09-28T03:55:42.777Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-88771 (GCVE-0-2026-88771)

    Vulnerability from nvd – Published: 2026-09-27 16:02 – Updated: 2026-09-29 03:55
    VLAI CISA CIRCL ENISA Previdian
    Title
    A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands
    Summary
    Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.
    SSVC
    Exploitation: active Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-27 00:00 UTC
    CWE
    • CWE-20 - Improper input validation
    Impacted products
    Vendor Product Version
    Citrix NetScaler ADC Affected: 0 , < 14.1-73.37 (patch)
    Affected: 0 , < 13.1-64.23 (patch)
    Affected: 0 , < 14.1-73.37 FIPS (patch)
    Affected: 0 , < 13.1.37.279 FIPS and NDcPP (patch)
    Create a notification for this product.
    Citrix NetScaler Gateway Affected: 0 , < 14.1-73.37 (patch)
    Affected: 0 , < 13.1-64.23 (patch)
    Create a notification for this product.
    Date Public
    2026-09-27 15:51
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88771",
                    "options": [
                      {
                        "Exploitation": "active"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-27T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              },
              {
                "other": {
                  "content": {
                    "dateAdded": "2026-09-27",
                    "reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-88771"
                  },
                  "type": "kev"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T03:55:15.090Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "government-resource"
                ],
                "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-88771"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ADC",
              "vendor": "Citrix NetScaler",
              "versions": [
                {
                  "lessThan": "14.1-73.37",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "13.1-64.23",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "14.1-73.37 FIPS",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "13.1.37.279 FIPS and NDcPP",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Gateway",
              "vendor": "Citrix NetScaler",
              "versions": [
                {
                  "lessThan": "14.1-73.37",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "13.1-64.23",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                }
              ]
            }
          ],
          "datePublic": "2026-09-27T15:51:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.\u003cp\u003eThis issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to\u0026nbsp;\u003cspan\u003ean unauthenticated attacker to execute arbitrary commands.\u0026nbsp;\u003c/span\u003e\u003c/p\u003e"
                }
              ],
              "value": "Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.\n\nThis issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to\u00a0an unauthenticated attacker to execute arbitrary commands."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 9.5,
                "baseSeverity": "CRITICAL",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-20",
                  "description": "CWE-20 Improper input validation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-27T16:02:07.001Z",
            "orgId": "50a63c94-1ea7-4568-8c11-eb79e7c5a2b5",
            "shortName": "NetScaler"
          },
          "references": [
            {
              "url": "https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands",
          "x_generator": {
            "engine": "Vulnogram 1.0.4"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "50a63c94-1ea7-4568-8c11-eb79e7c5a2b5",
        "assignerShortName": "NetScaler",
        "cveId": "CVE-2026-88771",
        "datePublished": "2026-09-27T16:02:07.001Z",
        "dateReserved": "2026-09-10T07:14:57.369Z",
        "dateUpdated": "2026-09-29T03:55:15.090Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-78547 (GCVE-0-2026-78547)

    Vulnerability from nvd – Published: 2026-09-11 19:07 – Updated: 2026-09-11 19:34
    VLAI
    Title
    Out-of-Bounds Write
    Summary
    Out-of-bounds write vulnerability in Citrix Citrix Workspace app for Windows. This issue affects Citrix Workspace app for Windows: before 2603.11 Current Release (CR), before 2507.1 LTSR CU3, and before LTSR 2607.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-11 19:34 UTC
    CWE
    Impacted products
    Vendor Product Version
    Citrix Citrix Workspace app for Windows Affected: 0 , < 2603.11 Current Release (CR) (patch)
    Affected: 0 , < 2507.1 LTSR CU3 (patch)
    Affected: 0 , < LTSR 2607 (patch)
    Create a notification for this product.
    Date Public
    2026-09-08 18:58
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-78547",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-11T19:34:11.126522Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-11T19:34:31.103Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Citrix Workspace app for Windows",
              "vendor": "Citrix",
              "versions": [
                {
                  "lessThan": "2603.11 Current Release (CR)",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "2507.1 LTSR CU3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "LTSR 2607",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                }
              ]
            }
          ],
          "datePublic": "2026-09-08T18:58:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Out-of-bounds write vulnerability in Citrix Citrix Workspace app for Windows.\u003cp\u003eThis issue affects Citrix Workspace app for Windows: before 2603.11 Current Release (CR), before 2507.1 LTSR CU3, and before LTSR 2607.\u003c/p\u003e"
                }
              ],
              "value": "Out-of-bounds write vulnerability in Citrix Citrix Workspace app for Windows.\n\nThis issue affects Citrix Workspace app for Windows: before 2603.11 Current Release (CR), before 2507.1 LTSR CU3, and before LTSR 2607."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "HIGH",
                "attackRequirements": "NONE",
                "attackVector": "PHYSICAL",
                "baseScore": 4.4,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:P/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-787",
                  "description": "CWE-787 Out-of-bounds write",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-11T19:11:16.233Z",
            "orgId": "e437aed5-38e0-4fa3-a98b-cb73e7acaec6",
            "shortName": "Citrix"
          },
          "references": [
            {
              "url": "https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697034\u0026articleTitle=Citrix_Workspace_app_for_Windows_Security_Bulletin_CVE_2026_78546_and_CVE_2026_78547"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Out-of-Bounds Write",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "e437aed5-38e0-4fa3-a98b-cb73e7acaec6",
        "assignerShortName": "Citrix",
        "cveId": "CVE-2026-78547",
        "datePublished": "2026-09-11T19:07:38.810Z",
        "dateReserved": "2026-08-24T18:48:00.120Z",
        "dateUpdated": "2026-09-11T19:34:31.103Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-19490 (GCVE-0-2026-19490)

    Vulnerability from nvd – Published: 2026-08-19 12:54 – Updated: 2026-09-10 03:55
    VLAI CISA Previdian
    Title
    NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490
    Summary
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
    SSVC
    Exploitation: active Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-19 00:00 UTC
    CWE
    • CWE-288 - Authentication Bypass Using an Alternate Path or Channel
    Impacted products
    Vendor Product Version
    NetScaler ADC Affected: 14.1 , ≤ 73.32 (patch)
    Affected: 13.1 , ≤ 63.21 (patch)
    Create a notification for this product.
    NetScaler Gateway Affected: 14.1 , ≤ 73.32 (patch)
    Affected: 13.1 , ≤ 63.21 (patch)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-19490",
                    "options": [
                      {
                        "Exploitation": "active"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-19T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-288",
                    "description": "CWE-288 Authentication Bypass Using an Alternate Path or Channel",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-10T03:55:17.040Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "government-resource"
                ],
                "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-19490"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ADC",
              "vendor": "NetScaler",
              "versions": [
                {
                  "lessThanOrEqual": "73.32",
                  "status": "affected",
                  "version": "14.1",
                  "versionType": "patch"
                },
                {
                  "lessThanOrEqual": "63.21",
                  "status": "affected",
                  "version": "13.1",
                  "versionType": "patch"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Gateway",
              "vendor": "NetScaler",
              "versions": [
                {
                  "lessThanOrEqual": "73.32",
                  "status": "affected",
                  "version": "14.1",
                  "versionType": "patch"
                },
                {
                  "lessThanOrEqual": "63.21",
                  "status": "affected",
                  "version": "13.1",
                  "versionType": "patch"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Vulnerability in NetScaler ADC and NetScaler Gateway.\u003cp\u003eThis issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.\u003c/p\u003e"
                }
              ],
              "value": "Vulnerability in NetScaler ADC and NetScaler Gateway.\n\nThis issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 9.3,
                "baseSeverity": "CRITICAL",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "LOW",
                "subConfidentialityImpact": "LOW",
                "subIntegrityImpact": "LOW",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-19T12:54:39.730Z",
            "orgId": "50a63c94-1ea7-4568-8c11-eb79e7c5a2b5",
            "shortName": "NetScaler"
          },
          "references": [
            {
              "url": "https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490",
          "x_generator": {
            "engine": "Vulnogram 1.0.4"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "50a63c94-1ea7-4568-8c11-eb79e7c5a2b5",
        "assignerShortName": "NetScaler",
        "cveId": "CVE-2026-19490",
        "datePublished": "2026-08-19T12:54:39.730Z",
        "dateReserved": "2026-08-10T17:39:56.668Z",
        "dateUpdated": "2026-09-10T03:55:17.040Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-18751 (GCVE-0-2026-18751)

    Vulnerability from nvd – Published: 2026-08-18 12:26 – Updated: 2026-08-19 03:55
    VLAI
    Title
    Citrix Workspace App for Mac Security Bulletin for CVE-2026-18751
    Summary
    External control of file name or path vulnerability in Citrix WorkSpace App on MacOS. This issue affects WorkSpace App: 2607.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-18 00:00 UTC
    CWE
    • CWE-73 - External control of file name or path
    Impacted products
    Vendor Product Version
    Citrix WorkSpace App Affected: 2607 (patch)
    Create a notification for this product.
    Date Public
    2026-08-18 12:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-18751",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-18T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-19T03:55:52.767Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "MacOS"
              ],
              "product": "WorkSpace App",
              "vendor": "Citrix",
              "versions": [
                {
                  "status": "affected",
                  "version": "2607",
                  "versionType": "patch"
                }
              ]
            }
          ],
          "datePublic": "2026-08-18T12:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "External control of file name or path vulnerability in Citrix WorkSpace App on MacOS.\u003cp\u003eThis issue affects WorkSpace App: 2607.\u003c/p\u003e"
                }
              ],
              "value": "External control of file name or path vulnerability in Citrix WorkSpace App on MacOS.\n\nThis issue affects WorkSpace App: 2607."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "LOCAL",
                "baseScore": 5.2,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "ACTIVE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-73",
                  "description": "CWE-73 External control of file name or path",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-18T12:26:35.987Z",
            "orgId": "e437aed5-38e0-4fa3-a98b-cb73e7acaec6",
            "shortName": "Citrix"
          },
          "references": [
            {
              "url": "https://support.citrix.com/external/article/CTX696911"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Citrix Workspace App for Mac Security Bulletin for CVE-2026-18751",
          "x_generator": {
            "engine": "Vulnogram 1.0.4"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "e437aed5-38e0-4fa3-a98b-cb73e7acaec6",
        "assignerShortName": "Citrix",
        "cveId": "CVE-2026-18751",
        "datePublished": "2026-08-18T12:26:35.987Z",
        "dateReserved": "2026-08-03T23:06:10.019Z",
        "dateUpdated": "2026-08-19T03:55:52.767Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-53566 (GCVE-0-2026-53566)

    Vulnerability from nvd – Published: 2026-07-14 13:12 – Updated: 2026-07-14 13:56
    VLAI
    Title
    Out-of-bounds memory read
    Summary
    Out-of-bounds read vulnerability in Citrix Citrix Secure Access Client for Windows. This issue affects Citrix Secure Access Client for Windows: before 26.6.1.20.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-07-14 13:56 UTC
    CWE
    Impacted products
    Vendor Product Version
    Citrix Citrix Secure Access Client for Windows Affected: 0 , < 26.6.1.20 (patch)
    Create a notification for this product.
    Date Public
    2026-07-14 12:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-53566",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-07-14T13:56:00.733974Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-07-14T13:56:09.574Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Citrix Secure Access Client for Windows",
              "vendor": "Citrix",
              "versions": [
                {
                  "lessThan": "26.6.1.20",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                }
              ]
            }
          ],
          "datePublic": "2026-07-14T12:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Out-of-bounds read vulnerability in Citrix Citrix Secure Access Client for Windows.\u003cp\u003eThis issue affects Citrix Secure Access Client for Windows: before 26.6.1.20.\u003c/p\u003e"
                }
              ],
              "value": "Out-of-bounds read vulnerability in Citrix Citrix Secure Access Client for Windows.\n\nThis issue affects Citrix Secure Access Client for Windows: before 26.6.1.20."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "LOCAL",
                "baseScore": 6.8,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-125",
                  "description": "CWE-125 Out-of-bounds read",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-07-14T13:12:57.829Z",
            "orgId": "e437aed5-38e0-4fa3-a98b-cb73e7acaec6",
            "shortName": "Citrix"
          },
          "references": [
            {
              "url": "https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696734"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Out-of-bounds memory read",
          "x_generator": {
            "engine": "Vulnogram 1.0.2"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "e437aed5-38e0-4fa3-a98b-cb73e7acaec6",
        "assignerShortName": "Citrix",
        "cveId": "CVE-2026-53566",
        "datePublished": "2026-07-14T13:12:57.829Z",
        "dateReserved": "2026-06-09T18:32:47.375Z",
        "dateUpdated": "2026-07-14T13:56:09.574Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-53565 (GCVE-0-2026-53565)

    Vulnerability from nvd – Published: 2026-07-14 12:49 – Updated: 2026-07-15 04:00
    VLAI
    Title
    Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges
    Summary
    Improper Privilege Management vulnerability in Citrix Secure Access Client for Windows, Citrix Citrix Endpoint Analysis Client for Windows. This issue affects Secure Access Client for Windows: before 26.6.1.20; Citrix Endpoint Analysis Client for Windows: before 26. 5.1.7.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-07-14 00:00 UTC
    CWE
    • CWE-269 - Improper Privilege Management
    Impacted products
    Date Public
    2026-07-14 12:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-53565",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-07-14T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-07-15T04:00:59.472Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Secure Access Client for Windows",
              "vendor": "Citrix",
              "versions": [
                {
                  "lessThan": "26.6.1.20",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Citrix Endpoint Analysis Client for Windows",
              "vendor": "Citrix",
              "versions": [
                {
                  "lessThan": "26. 5.1.7",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                }
              ]
            }
          ],
          "datePublic": "2026-07-14T12:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Improper Privilege Management vulnerability in Citrix Secure Access Client for Windows, Citrix Citrix Endpoint Analysis Client for Windows.\u003cp\u003eThis issue affects Secure Access Client for Windows: before 26.6.1.20; Citrix Endpoint Analysis Client for Windows: before 26. 5.1.7.\u003c/p\u003e"
                }
              ],
              "value": "Improper Privilege Management vulnerability in Citrix Secure Access Client for Windows, Citrix Citrix Endpoint Analysis Client for Windows.\n\nThis issue affects Secure Access Client for Windows: before 26.6.1.20; Citrix Endpoint Analysis Client for Windows: before 26. 5.1.7."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "LOCAL",
                "baseScore": 8.5,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-269",
                  "description": "CWE-269 Improper Privilege Management",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-07-14T12:49:17.998Z",
            "orgId": "e437aed5-38e0-4fa3-a98b-cb73e7acaec6",
            "shortName": "Citrix"
          },
          "references": [
            {
              "url": "https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696734"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges",
          "x_generator": {
            "engine": "Vulnogram 1.0.2"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "e437aed5-38e0-4fa3-a98b-cb73e7acaec6",
        "assignerShortName": "Citrix",
        "cveId": "CVE-2026-53565",
        "datePublished": "2026-07-14T12:49:17.998Z",
        "dateReserved": "2026-06-09T18:32:47.375Z",
        "dateUpdated": "2026-07-15T04:00:59.472Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-88778 (GCVE-0-2026-88778)

    Vulnerability from cvelistv5 – Published: 2026-09-27 16:43 – Updated: 2026-09-29 16:35
    VLAI
    Title
    TCP Initial Sequence Number (ISN) prediction
    Summary
    Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 16:34 UTC
    CWE
    • CWE-342 - Predictable exact value from previous values
    Impacted products
    Vendor Product Version
    Citrix NetScaler ADC Affected: 0 , < 14.1-73.37 (Patch)
    Affected: 0 , < 13.1-64.23 (Patch)
    Affected: 0 , < 14.1-73.37 FIPS (Patch)
    Affected: 0 , < 13.1.37.279 FIPS and NDcPP (Patch)
    Create a notification for this product.
    Citrix NetScaler Gateway Affected: 0 , < 14.1-73.37 (Patch)
    Affected: 0 , < 13.1-64.23 (Patch)
    Create a notification for this product.
    Date Public
    2026-09-27 15:30
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88778",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T16:34:20.349812Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T16:35:06.769Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ADC",
              "vendor": "Citrix NetScaler",
              "versions": [
                {
                  "lessThan": "14.1-73.37",
                  "status": "affected",
                  "version": "0",
                  "versionType": "Patch"
                },
                {
                  "lessThan": "13.1-64.23",
                  "status": "affected",
                  "version": "0",
                  "versionType": "Patch"
                },
                {
                  "lessThan": "14.1-73.37 FIPS",
                  "status": "affected",
                  "version": "0",
                  "versionType": "Patch"
                },
                {
                  "lessThan": "13.1.37.279 FIPS and NDcPP",
                  "status": "affected",
                  "version": "0",
                  "versionType": "Patch"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Gateway",
              "vendor": "Citrix NetScaler",
              "versions": [
                {
                  "lessThan": "14.1-73.37",
                  "status": "affected",
                  "version": "0",
                  "versionType": "Patch"
                },
                {
                  "lessThan": "13.1-64.23",
                  "status": "affected",
                  "version": "0",
                  "versionType": "Patch"
                }
              ]
            }
          ],
          "datePublic": "2026-09-27T15:30:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.\u003cp\u003eThis issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23.\u003c/p\u003e"
                }
              ],
              "value": "Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.\n\nThis issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "LOW",
                "subConfidentialityImpact": "LOW",
                "subIntegrityImpact": "LOW",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:L/SI:L/SA:L",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-342",
                  "description": "CWE-342 Predictable exact value from previous values",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-27T16:43:16.503Z",
            "orgId": "50a63c94-1ea7-4568-8c11-eb79e7c5a2b5",
            "shortName": "NetScaler"
          },
          "references": [
            {
              "url": "https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "TCP Initial Sequence Number (ISN) prediction",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "50a63c94-1ea7-4568-8c11-eb79e7c5a2b5",
        "assignerShortName": "NetScaler",
        "cveId": "CVE-2026-88778",
        "datePublished": "2026-09-27T16:43:16.503Z",
        "dateReserved": "2026-09-10T07:14:57.370Z",
        "dateUpdated": "2026-09-29T16:35:06.769Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-88777 (GCVE-0-2026-88777)

    Vulnerability from cvelistv5 – Published: 2026-09-27 16:37 – Updated: 2026-09-29 21:01
    VLAI
    Title
    Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service
    Summary
    Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23  leading to unpredictable or erroneous behavior or Denial of Service
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 15:07 UTC
    CWE
    • CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer
    Impacted products
    Vendor Product Version
    Citrix NetScaler ADC Affected: 0 , < 14.1-73.37 (patch)
    Affected: 0 , < 13.1-64.23 (patch)
    Affected: 0 , < 14.1-73.37 FIPS (patch)
    Affected: 0 , < 13.1.37.279 FIPS and NDcPP (patch)
    Create a notification for this product.
    Citrix NetScaler Gateway Affected: 0 , < 14.1-73.37 (patch)
    Affected: 0 , < 13.1-64.23 (patch)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88777",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T15:07:18.195758Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-119",
                    "description": "CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T21:01:24.942Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ADC",
              "vendor": "Citrix NetScaler",
              "versions": [
                {
                  "lessThan": "14.1-73.37",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "13.1-64.23",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "14.1-73.37 FIPS",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "13.1.37.279 FIPS and NDcPP",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Gateway",
              "vendor": "Citrix NetScaler",
              "versions": [
                {
                  "lessThan": "14.1-73.37",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "13.1-64.23",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.\u003cp\u003eThis issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23\u0026nbsp;\u003cspan\u003e\u0026nbsp;leading to unpredictable or erroneous behavior or Denial of Service\u003c/span\u003e\u003c/p\u003e"
                }
              ],
              "value": "Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.\n\nThis issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23\u00a0\u00a0leading to unpredictable or erroneous behavior or Denial of Service"
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-27T16:37:44.345Z",
            "orgId": "50a63c94-1ea7-4568-8c11-eb79e7c5a2b5",
            "shortName": "NetScaler"
          },
          "references": [
            {
              "url": "https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096\u0026articleTitle=Citrix_NetScaler_ADC_and_Citrix_NetScaler_Gateway_Security_Bulletin_for_CVE_2026_88771_CVE_2026_88772_CVE_2026_88773_CVE_2026_88774_CVE_2026_88775_CVE_2026_88776_CVE_2026_88777_and_CVE_2026_88778"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service",
          "x_generator": {
            "engine": "Vulnogram 1.0.4"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "50a63c94-1ea7-4568-8c11-eb79e7c5a2b5",
        "assignerShortName": "NetScaler",
        "cveId": "CVE-2026-88777",
        "datePublished": "2026-09-27T16:37:44.345Z",
        "dateReserved": "2026-09-10T07:14:57.370Z",
        "dateUpdated": "2026-09-29T21:01:24.942Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-88776 (GCVE-0-2026-88776)

    Vulnerability from cvelistv5 – Published: 2026-09-27 16:36 – Updated: 2026-09-29 16:06
    VLAI
    Title
    Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service
    Summary
    Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23  leading to unpredictable or erroneous behavior or Denial of Service
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 15:11 UTC
    CWE
    • CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer
    Impacted products
    Vendor Product Version
    Citrix NetScaler ADC Affected: 0 , < 14.1-73.37 (patch)
    Affected: 0 , < 13.1-64.23 (patch)
    Affected: 0 , < 14.1-73.37 FIPS (patch)
    Affected: 0 , < 13.1.37.279 FIPS and NDcPP (patch)
    Create a notification for this product.
    Citrix NetScaler Gateway Affected: 0 , < 14.1-73.37 (patch)
    Affected: 0 , < 13.1-64.23 (patch)
    Create a notification for this product.
    Date Public
    2026-09-27 15:30
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88776",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T15:11:33.607861Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-119",
                    "description": "CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T16:06:45.542Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ADC",
              "vendor": "Citrix NetScaler",
              "versions": [
                {
                  "lessThan": "14.1-73.37",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "13.1-64.23",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "14.1-73.37 FIPS",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "13.1.37.279 FIPS and NDcPP",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Gateway",
              "vendor": "Citrix NetScaler",
              "versions": [
                {
                  "lessThan": "14.1-73.37",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "13.1-64.23",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                }
              ]
            }
          ],
          "datePublic": "2026-09-27T15:30:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.\u003cbr\u003eThis issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23\u0026nbsp;\u0026nbsp;leading to unpredictable or erroneous behavior or Denial of Service"
                }
              ],
              "value": "Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.\nThis issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23\u00a0\u00a0leading to unpredictable or erroneous behavior or Denial of Service"
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-27T16:36:40.034Z",
            "orgId": "50a63c94-1ea7-4568-8c11-eb79e7c5a2b5",
            "shortName": "NetScaler"
          },
          "references": [
            {
              "url": "https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "50a63c94-1ea7-4568-8c11-eb79e7c5a2b5",
        "assignerShortName": "NetScaler",
        "cveId": "CVE-2026-88776",
        "datePublished": "2026-09-27T16:36:40.034Z",
        "dateReserved": "2026-09-10T07:14:57.369Z",
        "dateUpdated": "2026-09-29T16:06:45.542Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-88775 (GCVE-0-2026-88775)

    Vulnerability from cvelistv5 – Published: 2026-09-27 16:21 – Updated: 2026-09-29 15:15
    VLAI
    Title
    Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service
    Summary
    Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 15:14 UTC
    CWE
    • CWE-120 - Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
    Impacted products
    Vendor Product Version
    Citrix NetScaler ADC Affected: 0 , < 14.1-73.37 (patch)
    Affected: 0 , < 13.1-64.23 (patch)
    Affected: 0 , < 14.1-73.37 FIPS (patch)
    Affected: 0 , < 13.1.37.279 FIPS and NDcPP (patch)
    Create a notification for this product.
    Citrix NetScaler Gateway Affected: 0 , < 14.1-73.37 (patch)
    Affected: 0 , < 13.1-64.23 (patch)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88775",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T15:14:54.128931Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-120",
                    "description": "CWE-120 Buffer Copy without Checking Size of Input (\u0027Classic Buffer Overflow\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T15:15:39.206Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ADC",
              "vendor": "Citrix NetScaler",
              "versions": [
                {
                  "lessThan": "14.1-73.37",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "13.1-64.23",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "14.1-73.37 FIPS",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "13.1.37.279 FIPS and NDcPP",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Gateway",
              "vendor": "Citrix NetScaler",
              "versions": [
                {
                  "lessThan": "14.1-73.37",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "13.1-64.23",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.\u003cp\u003eThis issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading\u0026nbsp;\u003cspan\u003eMemory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service\u003c/span\u003e\u003c/p\u003e"
                }
              ],
              "value": "Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.\n\nThis issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading\u00a0Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service"
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-27T16:38:24.106Z",
            "orgId": "50a63c94-1ea7-4568-8c11-eb79e7c5a2b5",
            "shortName": "NetScaler"
          },
          "references": [
            {
              "url": "https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096\u0026articleTitle=Citrix_NetScaler_ADC_and_Citrix_NetScaler_Gateway_Security_Bulletin_for_CVE_2026_88771_CVE_2026_88772_CVE_2026_88773_CVE_2026_88774_CVE_2026_88775_CVE_2026_88776_CVE_2026_88777_and_CVE_2026_88778"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service",
          "x_generator": {
            "engine": "Vulnogram 1.0.4"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "50a63c94-1ea7-4568-8c11-eb79e7c5a2b5",
        "assignerShortName": "NetScaler",
        "cveId": "CVE-2026-88775",
        "datePublished": "2026-09-27T16:21:12.160Z",
        "dateReserved": "2026-09-10T07:14:57.369Z",
        "dateUpdated": "2026-09-29T15:15:39.206Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-88773 (GCVE-0-2026-88773)

    Vulnerability from cvelistv5 – Published: 2026-09-27 16:20 – Updated: 2026-09-29 15:21
    VLAI
    Title
    HTTP Request Smuggling
    Summary
    Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before 13.1-64.23.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 15:17 UTC
    CWE
    • CWE-444 - Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling')
    Impacted products
    Vendor Product Version
    Citrix NetScaler ADC Affected: 0 , < 14.1-73.37 (Patch)
    Affected: 0 , < 13.1-64.23 (Patch)
    Affected: 0 , < 14.1-73.37 FIPS (Patch)
    Affected: 0 , < 13.1-37.279 and NDcPP (Patch)
    Create a notification for this product.
    Citrix NetScaler Gateway Affected: 0 , < 14.1-73.37 FIPS (Patch)
    Affected: 0 , < 13.1-64.23 (Patch)
    Create a notification for this product.
    Date Public
    2026-09-27 15:30
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88773",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T15:17:32.077580Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T15:21:44.819Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ADC",
              "vendor": "Citrix NetScaler",
              "versions": [
                {
                  "lessThan": "14.1-73.37",
                  "status": "affected",
                  "version": "0",
                  "versionType": "Patch"
                },
                {
                  "lessThan": "13.1-64.23",
                  "status": "affected",
                  "version": "0",
                  "versionType": "Patch"
                },
                {
                  "lessThan": "14.1-73.37 FIPS",
                  "status": "affected",
                  "version": "0",
                  "versionType": "Patch"
                },
                {
                  "lessThan": "13.1-37.279 and NDcPP",
                  "status": "affected",
                  "version": "0",
                  "versionType": "Patch"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Gateway",
              "vendor": "Citrix NetScaler",
              "versions": [
                {
                  "lessThan": "14.1-73.37 FIPS",
                  "status": "affected",
                  "version": "0",
                  "versionType": "Patch"
                },
                {
                  "lessThan": "13.1-64.23",
                  "status": "affected",
                  "version": "0",
                  "versionType": "Patch"
                }
              ]
            }
          ],
          "datePublic": "2026-09-27T15:30:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Inconsistent interpretation of HTTP requests (\u0027HTTP Request/Response smuggling\u0027) vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.\u003cp\u003eThis issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before 13.1-64.23.\u003c/p\u003e"
                }
              ],
              "value": "Inconsistent interpretation of HTTP requests (\u0027HTTP Request/Response smuggling\u0027) vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.\n\nThis issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before 13.1-64.23."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 9.3,
                "baseSeverity": "CRITICAL",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-444",
                  "description": "CWE-444 Inconsistent interpretation of HTTP requests (\u0027HTTP Request/Response smuggling\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-27T16:20:08.382Z",
            "orgId": "50a63c94-1ea7-4568-8c11-eb79e7c5a2b5",
            "shortName": "NetScaler"
          },
          "references": [
            {
              "url": "https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "HTTP Request Smuggling",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "50a63c94-1ea7-4568-8c11-eb79e7c5a2b5",
        "assignerShortName": "NetScaler",
        "cveId": "CVE-2026-88773",
        "datePublished": "2026-09-27T16:20:08.382Z",
        "dateReserved": "2026-09-10T07:14:57.369Z",
        "dateUpdated": "2026-09-29T15:21:44.819Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-88774 (GCVE-0-2026-88774)

    Vulnerability from cvelistv5 – Published: 2026-09-27 16:14 – Updated: 2026-09-29 15:24
    VLAI
    Title
    Feature policy bypass due to improper HTTP URL based expression usage
    Summary
    Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to a feature policy bypass due to improper HTTP URL based expression usage.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 15:22 UTC
    CWE
    • CWE-20 - Improper Input Validation
    Impacted products
    Vendor Product Version
    Citrix NetScaler ADC Affected: 0 , < 14.1-73.37 (patch)
    Affected: 0 , < 13.1-64.23 (patch)
    Affected: 0 , < 14.1-73.37 FIPS (patch)
    Affected: 0 , < 13.1.37.279 FIPS and NDcPP (patch)
    Create a notification for this product.
    Citrix NetScaler Gateway Affected: 0 , < 14.1-73.37 (patch)
    Affected: 0 , < 13.1-64.23 (patch)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88774",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T15:22:52.478269Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-20",
                    "description": "CWE-20 Improper Input Validation",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T15:24:29.082Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ADC",
              "vendor": "Citrix NetScaler",
              "versions": [
                {
                  "lessThan": "14.1-73.37",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "13.1-64.23",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "14.1-73.37 FIPS",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "13.1.37.279 FIPS and NDcPP",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Gateway",
              "vendor": "Citrix NetScaler",
              "versions": [
                {
                  "lessThan": "14.1-73.37",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "13.1-64.23",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.\u003cp\u003eThis issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to a f\u003cspan\u003eeature policy bypass due to improper HTTP URL based expression usage.\u003c/span\u003e\u003c/p\u003e"
                }
              ],
              "value": "Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.\n\nThis issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to a feature policy bypass due to improper HTTP URL based expression usage."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 7,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-27T16:14:02.993Z",
            "orgId": "50a63c94-1ea7-4568-8c11-eb79e7c5a2b5",
            "shortName": "NetScaler"
          },
          "references": [
            {
              "url": "https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096\u0026articleTitle=Citrix_NetScaler_ADC_and_Citrix_NetScaler_Gateway_Security_Bulletin_for_CVE_2026_88771_CVE_2026_88772_CVE_2026_88773_CVE_2026_88774_CVE_2026_88775_CVE_2026_88776_CVE_2026_88777_and_CVE_2026_88778"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Feature policy bypass due to improper HTTP URL based expression usage",
          "x_generator": {
            "engine": "Vulnogram 1.0.4"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "50a63c94-1ea7-4568-8c11-eb79e7c5a2b5",
        "assignerShortName": "NetScaler",
        "cveId": "CVE-2026-88774",
        "datePublished": "2026-09-27T16:14:02.993Z",
        "dateReserved": "2026-09-10T07:14:57.369Z",
        "dateUpdated": "2026-09-29T15:24:29.082Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-88772 (GCVE-0-2026-88772)

    Vulnerability from cvelistv5 – Published: 2026-09-27 16:09 – Updated: 2026-09-28 03:55
    VLAI CISA CIRCL ENISA Previdian
    Title
    Memory overflow vulnerability leading to Remote Code Execution or Denial of Service
    Summary
    Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service
    SSVC
    Exploitation: active Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-27 00:00 UTC
    CWE
    • CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer
    Impacted products
    Vendor Product Version
    Citrix NetScaler ADC Affected: 0 , < 14.1-73.37 (patch)
    Affected: 0 , < 13.1-64.23 (patch)
    Affected: 0 , < 14.1-73.37 FIPS (patch)
    Affected: 0 , < 13.1.37.279 FIPS and NDcPP (patch)
    Create a notification for this product.
    Citrix NetScaler Gateway Affected: 0 , < 14.1-73.37 (patch)
    Affected: 0 , < 13.1-64.23 (patch)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88772",
                    "options": [
                      {
                        "Exploitation": "active"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-27T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              },
              {
                "other": {
                  "content": {
                    "dateAdded": "2026-09-27",
                    "reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-88772"
                  },
                  "type": "kev"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-119",
                    "description": "CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-28T03:55:42.777Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "government-resource"
                ],
                "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-88772"
              }
            ],
            "timeline": [
              {
                "lang": "en",
                "time": "2026-09-27T00:00:00.000Z",
                "value": "CVE-2026-88772 added to CISA KEV"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ADC",
              "vendor": "Citrix NetScaler",
              "versions": [
                {
                  "lessThan": "14.1-73.37",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "13.1-64.23",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "14.1-73.37 FIPS",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "13.1.37.279 FIPS and NDcPP",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Gateway",
              "vendor": "Citrix NetScaler",
              "versions": [
                {
                  "lessThan": "14.1-73.37",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "13.1-64.23",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.\u003cp\u003eThis issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23\u0026nbsp;\u003cspan\u003eleading to Remote Code Execution or Denial of Service\u003c/span\u003e\u003c/p\u003e"
                }
              ],
              "value": "Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.\n\nThis issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23\u00a0leading to Remote Code Execution or Denial of Service"
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "HIGH",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 9.5,
                "baseSeverity": "CRITICAL",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-27T16:09:56.033Z",
            "orgId": "50a63c94-1ea7-4568-8c11-eb79e7c5a2b5",
            "shortName": "NetScaler"
          },
          "references": [
            {
              "url": "https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096\u0026articleTitle=Citrix_NetScaler_ADC_and_Citrix_NetScaler_Gateway_Security_Bulletin_for_CVE_2026_88771_CVE_2026_88772_CVE_2026_88773_CVE_2026_88774_CVE_2026_88775_CVE_2026_88776_CVE_2026_88777_and_CVE_2026_88778"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Memory overflow vulnerability leading to Remote Code Execution or Denial of Service",
          "x_generator": {
            "engine": "Vulnogram 1.0.4"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "50a63c94-1ea7-4568-8c11-eb79e7c5a2b5",
        "assignerShortName": "NetScaler",
        "cveId": "CVE-2026-88772",
        "datePublished": "2026-09-27T16:09:56.033Z",
        "dateReserved": "2026-09-10T07:14:57.369Z",
        "dateUpdated": "2026-09-28T03:55:42.777Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-88771 (GCVE-0-2026-88771)

    Vulnerability from cvelistv5 – Published: 2026-09-27 16:02 – Updated: 2026-09-29 03:55
    VLAI CISA CIRCL ENISA Previdian
    Title
    A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands
    Summary
    Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.
    SSVC
    Exploitation: active Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-27 00:00 UTC
    CWE
    • CWE-20 - Improper input validation
    Impacted products
    Vendor Product Version
    Citrix NetScaler ADC Affected: 0 , < 14.1-73.37 (patch)
    Affected: 0 , < 13.1-64.23 (patch)
    Affected: 0 , < 14.1-73.37 FIPS (patch)
    Affected: 0 , < 13.1.37.279 FIPS and NDcPP (patch)
    Create a notification for this product.
    Citrix NetScaler Gateway Affected: 0 , < 14.1-73.37 (patch)
    Affected: 0 , < 13.1-64.23 (patch)
    Create a notification for this product.
    Date Public
    2026-09-27 15:51
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88771",
                    "options": [
                      {
                        "Exploitation": "active"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-27T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              },
              {
                "other": {
                  "content": {
                    "dateAdded": "2026-09-27",
                    "reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-88771"
                  },
                  "type": "kev"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T03:55:15.090Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "government-resource"
                ],
                "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-88771"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ADC",
              "vendor": "Citrix NetScaler",
              "versions": [
                {
                  "lessThan": "14.1-73.37",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "13.1-64.23",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "14.1-73.37 FIPS",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "13.1.37.279 FIPS and NDcPP",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Gateway",
              "vendor": "Citrix NetScaler",
              "versions": [
                {
                  "lessThan": "14.1-73.37",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "13.1-64.23",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                }
              ]
            }
          ],
          "datePublic": "2026-09-27T15:51:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.\u003cp\u003eThis issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to\u0026nbsp;\u003cspan\u003ean unauthenticated attacker to execute arbitrary commands.\u0026nbsp;\u003c/span\u003e\u003c/p\u003e"
                }
              ],
              "value": "Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.\n\nThis issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to\u00a0an unauthenticated attacker to execute arbitrary commands."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 9.5,
                "baseSeverity": "CRITICAL",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-20",
                  "description": "CWE-20 Improper input validation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-27T16:02:07.001Z",
            "orgId": "50a63c94-1ea7-4568-8c11-eb79e7c5a2b5",
            "shortName": "NetScaler"
          },
          "references": [
            {
              "url": "https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands",
          "x_generator": {
            "engine": "Vulnogram 1.0.4"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "50a63c94-1ea7-4568-8c11-eb79e7c5a2b5",
        "assignerShortName": "NetScaler",
        "cveId": "CVE-2026-88771",
        "datePublished": "2026-09-27T16:02:07.001Z",
        "dateReserved": "2026-09-10T07:14:57.369Z",
        "dateUpdated": "2026-09-29T03:55:15.090Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-78547 (GCVE-0-2026-78547)

    Vulnerability from cvelistv5 – Published: 2026-09-11 19:07 – Updated: 2026-09-11 19:34
    VLAI
    Title
    Out-of-Bounds Write
    Summary
    Out-of-bounds write vulnerability in Citrix Citrix Workspace app for Windows. This issue affects Citrix Workspace app for Windows: before 2603.11 Current Release (CR), before 2507.1 LTSR CU3, and before LTSR 2607.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-11 19:34 UTC
    CWE
    Impacted products
    Vendor Product Version
    Citrix Citrix Workspace app for Windows Affected: 0 , < 2603.11 Current Release (CR) (patch)
    Affected: 0 , < 2507.1 LTSR CU3 (patch)
    Affected: 0 , < LTSR 2607 (patch)
    Create a notification for this product.
    Date Public
    2026-09-08 18:58
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-78547",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-11T19:34:11.126522Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-11T19:34:31.103Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Citrix Workspace app for Windows",
              "vendor": "Citrix",
              "versions": [
                {
                  "lessThan": "2603.11 Current Release (CR)",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "2507.1 LTSR CU3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                },
                {
                  "lessThan": "LTSR 2607",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch"
                }
              ]
            }
          ],
          "datePublic": "2026-09-08T18:58:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Out-of-bounds write vulnerability in Citrix Citrix Workspace app for Windows.\u003cp\u003eThis issue affects Citrix Workspace app for Windows: before 2603.11 Current Release (CR), before 2507.1 LTSR CU3, and before LTSR 2607.\u003c/p\u003e"
                }
              ],
              "value": "Out-of-bounds write vulnerability in Citrix Citrix Workspace app for Windows.\n\nThis issue affects Citrix Workspace app for Windows: before 2603.11 Current Release (CR), before 2507.1 LTSR CU3, and before LTSR 2607."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "HIGH",
                "attackRequirements": "NONE",
                "attackVector": "PHYSICAL",
                "baseScore": 4.4,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:P/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-787",
                  "description": "CWE-787 Out-of-bounds write",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-11T19:11:16.233Z",
            "orgId": "e437aed5-38e0-4fa3-a98b-cb73e7acaec6",
            "shortName": "Citrix"
          },
          "references": [
            {
              "url": "https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697034\u0026articleTitle=Citrix_Workspace_app_for_Windows_Security_Bulletin_CVE_2026_78546_and_CVE_2026_78547"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Out-of-Bounds Write",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "e437aed5-38e0-4fa3-a98b-cb73e7acaec6",
        "assignerShortName": "Citrix",
        "cveId": "CVE-2026-78547",
        "datePublished": "2026-09-11T19:07:38.810Z",
        "dateReserved": "2026-08-24T18:48:00.120Z",
        "dateUpdated": "2026-09-11T19:34:31.103Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-19490 (GCVE-0-2026-19490)

    Vulnerability from cvelistv5 – Published: 2026-08-19 12:54 – Updated: 2026-09-10 03:55
    VLAI CISA Previdian
    Title
    NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490
    Summary
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
    SSVC
    Exploitation: active Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-19 00:00 UTC
    CWE
    • CWE-288 - Authentication Bypass Using an Alternate Path or Channel
    Impacted products
    Vendor Product Version
    NetScaler ADC Affected: 14.1 , ≤ 73.32 (patch)
    Affected: 13.1 , ≤ 63.21 (patch)
    Create a notification for this product.
    NetScaler Gateway Affected: 14.1 , ≤ 73.32 (patch)
    Affected: 13.1 , ≤ 63.21 (patch)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-19490",
                    "options": [
                      {
                        "Exploitation": "active"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-19T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-288",
                    "description": "CWE-288 Authentication Bypass Using an Alternate Path or Channel",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-10T03:55:17.040Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "government-resource"
                ],
                "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-19490"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ADC",
              "vendor": "NetScaler",
              "versions": [
                {
                  "lessThanOrEqual": "73.32",
                  "status": "affected",
                  "version": "14.1",
                  "versionType": "patch"
                },
                {
                  "lessThanOrEqual": "63.21",
                  "status": "affected",
                  "version": "13.1",
                  "versionType": "patch"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Gateway",
              "vendor": "NetScaler",
              "versions": [
                {
                  "lessThanOrEqual": "73.32",
                  "status": "affected",
                  "version": "14.1",
                  "versionType": "patch"
                },
                {
                  "lessThanOrEqual": "63.21",
                  "status": "affected",
                  "version": "13.1",
                  "versionType": "patch"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Vulnerability in NetScaler ADC and NetScaler Gateway.\u003cp\u003eThis issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.\u003c/p\u003e"
                }
              ],
              "value": "Vulnerability in NetScaler ADC and NetScaler Gateway.\n\nThis issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 9.3,
                "baseSeverity": "CRITICAL",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "LOW",
                "subConfidentialityImpact": "LOW",
                "subIntegrityImpact": "LOW",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-19T12:54:39.730Z",
            "orgId": "50a63c94-1ea7-4568-8c11-eb79e7c5a2b5",
            "shortName": "NetScaler"
          },
          "references": [
            {
              "url": "https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490",
          "x_generator": {
            "engine": "Vulnogram 1.0.4"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "50a63c94-1ea7-4568-8c11-eb79e7c5a2b5",
        "assignerShortName": "NetScaler",
        "cveId": "CVE-2026-19490",
        "datePublished": "2026-08-19T12:54:39.730Z",
        "dateReserved": "2026-08-10T17:39:56.668Z",
        "dateUpdated": "2026-09-10T03:55:17.040Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-18751 (GCVE-0-2026-18751)

    Vulnerability from cvelistv5 – Published: 2026-08-18 12:26 – Updated: 2026-08-19 03:55
    VLAI
    Title
    Citrix Workspace App for Mac Security Bulletin for CVE-2026-18751
    Summary
    External control of file name or path vulnerability in Citrix WorkSpace App on MacOS. This issue affects WorkSpace App: 2607.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-18 00:00 UTC
    CWE
    • CWE-73 - External control of file name or path
    Impacted products
    Vendor Product Version
    Citrix WorkSpace App Affected: 2607 (patch)
    Create a notification for this product.
    Date Public
    2026-08-18 12:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-18751",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-18T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-19T03:55:52.767Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "MacOS"
              ],
              "product": "WorkSpace App",
              "vendor": "Citrix",
              "versions": [
                {
                  "status": "affected",
                  "version": "2607",
                  "versionType": "patch"
                }
              ]
            }
          ],
          "datePublic": "2026-08-18T12:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "External control of file name or path vulnerability in Citrix WorkSpace App on MacOS.\u003cp\u003eThis issue affects WorkSpace App: 2607.\u003c/p\u003e"
                }
              ],
              "value": "External control of file name or path vulnerability in Citrix WorkSpace App on MacOS.\n\nThis issue affects WorkSpace App: 2607."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "LOCAL",
                "baseScore": 5.2,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "ACTIVE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-73",
                  "description": "CWE-73 External control of file name or path",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-18T12:26:35.987Z",
            "orgId": "e437aed5-38e0-4fa3-a98b-cb73e7acaec6",
            "shortName": "Citrix"
          },
          "references": [
            {
              "url": "https://support.citrix.com/external/article/CTX696911"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Citrix Workspace App for Mac Security Bulletin for CVE-2026-18751",
          "x_generator": {
            "engine": "Vulnogram 1.0.4"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "e437aed5-38e0-4fa3-a98b-cb73e7acaec6",
        "assignerShortName": "Citrix",
        "cveId": "CVE-2026-18751",
        "datePublished": "2026-08-18T12:26:35.987Z",
        "dateReserved": "2026-08-03T23:06:10.019Z",
        "dateUpdated": "2026-08-19T03:55:52.767Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }