Cyber & AI intelligence
Wasteland.
Briefs indexed2904
Issues29
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-88772 2026-09-27

Citrix NetScaler CVE-2026-88772: Actively Exploited Memory Buffer Flaw Enables RCE or DoS

"CISA has added CVE-2026-88772 to its Known Exploited Vulnerabilities catalog. It is a critical memory buffer flaw in Citrix NetScaler ADC and NetScaler Gateway that can lead to remote code execution or denial of…"

CISA has added CVE-2026-88772 to its Known Exploited Vulnerabilities catalog. It is a critical memory buffer flaw in Citrix NetScaler ADC and NetScaler Gateway that can lead to remote code execution or denial of service, and federal agencies must remediate it by September 30, 2026.

What Is It

CVE-2026-88772 is an improper restriction of operations within the bounds of a memory buffer (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway. According to CISA and NVD, successful exploitation could result in remote code execution or denial of service.

The vendor-supplied CVSS v4.0 score is 9.5 (Critical). The vector shows a network attack vector, high attack complexity, no privileges required and no user interaction. It rates high impact to confidentiality, integrity and availability on both the vulnerable system and subsequent systems.

Why It Matters

CISA added this CVE to the KEV catalog on September 27, 2026, which confirms active exploitation. CISA's SSVC assessment also lists exploitation as "active" and technical impact as "total." Whether ransomware campaigns have used it is currently listed as unknown.

CISA has also flagged this entry for forensic triage. Under BOD 26-04, federal agencies are required to investigate for signs of compromise in addition to patching. Other organizations are not bound by the directive but should consider the same step, given confirmed active exploitation. CISA notes that running the IOCs Citrix provides in the NetScaler console may help identify indicators of exploitation.

What's Vulnerable

According to NVD, the following versions are affected:

NetScaler ADC - Before 14.1-73.37 - Before 13.1-64.23 - Before 14.1-73.37 FIPS - Before 13.1-37.279 FIPS and NDcPP

NetScaler Gateway - Before 14.1-73.37 - Before 13.1-64.23

The Citrix security bulletin for this issue also covers CVE-2026-88771 through CVE-2026-88778.

Patch Status

Citrix has published a security bulletin (CTX697096) with fixed versions and mitigation guidance. CISA's required action is to apply mitigations according to the vendor's instructions, in line with BOD 26-04 (Prioritizing Security Updates Based on Risk) and CISA's Forensics Triage Requirements. If mitigations are unavailable, organizations should follow the BOD 26-04 guidance for cloud services or stop using the product. Stakeholders are responsible for evaluating each asset's internet exposure.

The due date is September 30, 2026. Citrix also publishes separate guidance on what to do if a NetScaler ADC is suspected of compromise (CTX694799).

Sources