CISA has added CVE-2026-88772 to its Known Exploited Vulnerabilities catalog. It is a critical memory buffer flaw in Citrix NetScaler ADC and NetScaler Gateway that can lead to remote code execution or denial of service, and federal agencies must remediate it by September 30, 2026.
What Is It
CVE-2026-88772 is an improper restriction of operations within the bounds of a memory buffer (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway. According to CISA and NVD, successful exploitation could result in remote code execution or denial of service.
The vendor-supplied CVSS v4.0 score is 9.5 (Critical). The vector shows a network attack vector, high attack complexity, no privileges required and no user interaction. It rates high impact to confidentiality, integrity and availability on both the vulnerable system and subsequent systems.
Why It Matters
CISA added this CVE to the KEV catalog on September 27, 2026, which confirms active exploitation. CISA's SSVC assessment also lists exploitation as "active" and technical impact as "total." Whether ransomware campaigns have used it is currently listed as unknown.
CISA has also flagged this entry for forensic triage. Under BOD 26-04, federal agencies are required to investigate for signs of compromise in addition to patching. Other organizations are not bound by the directive but should consider the same step, given confirmed active exploitation. CISA notes that running the IOCs Citrix provides in the NetScaler console may help identify indicators of exploitation.
What's Vulnerable
According to NVD, the following versions are affected:
NetScaler ADC - Before 14.1-73.37 - Before 13.1-64.23 - Before 14.1-73.37 FIPS - Before 13.1-37.279 FIPS and NDcPP
NetScaler Gateway - Before 14.1-73.37 - Before 13.1-64.23
The Citrix security bulletin for this issue also covers CVE-2026-88771 through CVE-2026-88778.
Patch Status
Citrix has published a security bulletin (CTX697096) with fixed versions and mitigation guidance. CISA's required action is to apply mitigations according to the vendor's instructions, in line with BOD 26-04 (Prioritizing Security Updates Based on Risk) and CISA's Forensics Triage Requirements. If mitigations are unavailable, organizations should follow the BOD 26-04 guidance for cloud services or stop using the product. Stakeholders are responsible for evaluating each asset's internet exposure.
The due date is September 30, 2026. Citrix also publishes separate guidance on what to do if a NetScaler ADC is suspected of compromise (CTX694799).
Sources
- CISA KEV Catalog; CVE-2026-88772
- NVD, CVE-2026-88772
- Citrix Security Bulletin CTX697096
- Citrix TechZone; NetScaler ADC and Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778
- Citrix CTX694799; Steps to Take if NetScaler ADC Is Suspected of Compromise
- CISA BOD 26-04; Prioritizing Security Updates Based on Risk
- CISA BOD 26-04 Implementation Guidance; Forensics Triage Requirements