DIRAS TAKE
Act urgently: the vulnerability enables remote code execution and has public exploit code, and a CISA listing indicates active concern. Prioritise patching exposed appliances or applying vendor mitigations immediately.
What is CVE-2026-88772?
Multiple releases of NetScaler ADC and NetScaler Gateway contain a memory-buffer bounds issue that can be triggered remotely. Successful exploitation can result in remote code execution or cause a denial of service. The flaw requires a network attacker to send specially crafted input to affected ADC and Gateway builds; no authentication is required per the available facts. A high-severity CVSS 3.1 score indicates significant impact to confidentiality, integrity, and availability.
Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Citrix NetScaler are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| ADC 14.x | before 14.1-73.37 | 14.1-73.37 |
| ADC 13.x | before 13.1-64.23 | 13.1-64.23 |
| ADC 14.x | before 14.1-73.37 FIPS | 14.1-73.37 FIPS |
| ADC 13.x | before 13.1.37.279 FIPS and NDcPP | 13.1.37.279 FIPS and NDcPP |
| Gateway 14.x | before 14.1-73.37 | 14.1-73.37 |
| Gateway 13.x | before 13.1-64.23 | 13.1-64.23 |
Is CVE-2026-88772 being exploited?
CISA lists this issue as exploited in the wild (date added 2026-09-27). Public exploit code is available. As of 2026-09-29 there are public reports of exploit code and official US government listing of exploitation.
How to fix CVE-2026-88772
- Apply the vendor fixes: upgrade ADC to 14.1-73.37 or 13.1-64.23 (and the listed FIPS/NDcPP fixed builds)
- If you cannot patch immediately, follow the vendor mitigations and restrict internet exposure of affected appliances
- Monitor appliance logs and network traffic for suspicious activity and indicators of exploitation
- Follow CISA guidance referenced in their advisory and verify compliance with any applicable emergency update policies
Frequently asked questions
Is CVE-2026-88772 being actively exploited?
Yes. CISA lists this CVE as exploited in the wild (added 2026-09-27), and public exploit code exists as of 2026-09-29.
Which versions contain the fix?
Fixed builds include ADC 14.1-73.37, ADC 13.1-64.23, the listed FIPS/NDcPP fixed builds (14.1-73.37 FIPS; 13.1.37.279 FIPS and NDcPP), and Gateway 14.1-73.37 and 13.1-64.23.
What immediate steps should I take if I run affected appliances?
Upgrade to the fixed builds as soon as possible, remove or block internet exposure for vulnerable appliances until patched, and increase monitoring for signs of compromise.
References
- nvd.nist.gov/vuln/detail/CVE-2026-88772
- cve.org/CVERecord?id=CVE-2026-88772
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-88772
- support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096&articleTitle=Citrix_NetScaler_ADC_and_Citrix_NetScaler_Gateway_Security_Bulletin_for_CVE_2026_88771_CVE_2026_88772_CVE_2026_88773_CVE_2026_88774_CVE_2026_88775_CVE_2026_88776_CVE_2026_88777_and_CVE_2026_88778
- All Citrix CVEs on CVE Radar
- CVEs published in September 2026