NetScaler ADC and NetScaler Gateway DoS (CTX697174)

high Nessus Plugin ID 363353

Synopsis

The remote device is affected by multiple vulnerabilities.

Description

The remote NetScaler ADC (formerly Citrix ADC) or NetScaler Gateway (formerly Citrix Gateway) device is 13.1 prior to 13.1-64.28, or 14.1 prior to 14.1-73.41, or 13.1-FIPS/NDcPP prior to 13.1-37.282, or 14.1-FIPS prior to 14.1-73.41. It is, therefore, affected by multiple vulnerabilities:

- Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for a denial of service. (CVE-2026-88779)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to NetScaler ADC or NetScaler Gateway version 13.1-64.28, 14.1-73.41, 13.1-37.282-FIPS, 13.1-37.282-NDcPP, or 14.1-73.41-FIPS or later.

See Also

http://www.nessus.org/u?5827482a

Plugin Details

Severity: High

ID: 363353

File Name: netscaler_adc_gateway_CTX697174.nasl

Version: 1.1

Type: Combined

Family: CGI abuses

Published: 10/6/2026

Updated: 10/6/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.6

Percentile: 98.25

CVSS v2

Risk Factor: High

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2026-88779

CVSS v3

Risk Factor: High

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVSS v4

Risk Factor: High

Base Score: 8.7

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Vulnerability Information

CPE: cpe:/h:citrix:netscaler_application_delivery_controller, cpe:/h:citrix:netscaler_gateway

Required KB Items: Host/NetScaler/Detected

Patch Publication Date: 10/4/2026

Vulnerability Publication Date: 10/4/2026

Reference Information

CVE: CVE-2026-88779

IAVA: 2026-A-1086