
Nevertheless, it encouraged affected customers to upgrade to patched versions as soon as possible: 13.1-64.29 or later for the 13.1 series, and 14.1-73.46 or later for the 14.1 series of ADC and Gateway, and 13.1.37.283 or later for ADC 13.1-FIPS. Or 13.1-NDcPP.
Citrix’s recent run of bad news began on Sept. 27, a Sunday, when it advised users of NetScaler ADC and Gateway to take their systems offline and patch two critical unauthenticated remote code execution vulnerabilities immediately as they were both under active attack, prompting one security researcher to warn, “Monday will be too late.”
More flaws turned up last week including another memory overflow vulnerability (CVE-2026-88779), this one rated 8.7 on the CVSS 4.0 scale. Citrix said it was being actively exploited to cause denial of service. Citrix also released a new version of NetScaler ADC and Gateway, 14.1-60.58, that week, patching a critical memory overread vulnerability previously reported as CVE-2026-3055.
