Predictable Value Exposure in Citrix NetScaler ADC and Gateway
CVE-2026-88778

8.8HIGH

Key Information:

Vendor
CVE Published:
27 September 2026

What is CVE-2026-88778?

A vulnerability in Citrix NetScaler ADC and Gateway allows for the exposure of predictable exact values derived from previous values. This issue potentially compromises the security of sensitive information by making it easier for unauthorized users to predict and access data related to system configurations or user sessions. Affected versions include multiple releases prior to the specified updates, underscoring the need for timely patching and network security reviews to mitigate risks associated with this exposure.

Affected Version(s)

ADC 0 < 14.1-73.37

ADC 0 < 13.1-64.23

ADC 0 < 14.1-73.37 FIPS

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.