• CISA KEV
  • EXPLOITED
  • PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-88772: remote code execution and denial of service in Citrix NetScaler

Multiple releases of NetScaler ADC and NetScaler Gateway contain a memory-buffer bounds issue that can be triggered remotely. Successful exploitation can result in remote code execution or cause a denial of service. The flaw requires a network attacker to send specially crafted input to affected ADC and Gateway builds; no authentication is required per the available facts. A high-severity CVSS 3.1 score indicates significant impact to confidentiality, integrity, and availability.

Published Updated Source: CVE Program, NVD, CISA KEV

CVSS 3.1
8.1HIGH
EPSS
0.01301
CWE
CWE-119
KEV DUE DATE
PATCH
Available

DIRAS TAKE

Act urgently: the vulnerability enables remote code execution and has public exploit code, and a CISA listing indicates active concern. Prioritise patching exposed appliances or applying vendor mitigations immediately.

What is CVE-2026-88772?

Multiple releases of NetScaler ADC and NetScaler Gateway contain a memory-buffer bounds issue that can be triggered remotely. Successful exploitation can result in remote code execution or cause a denial of service. The flaw requires a network attacker to send specially crafted input to affected ADC and Gateway builds; no authentication is required per the available facts. A high-severity CVSS 3.1 score indicates significant impact to confidentiality, integrity, and availability.

Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Citrix NetScaler are affected?

BRANCHAFFECTEDFIXED
ADC 14.xbefore 14.1-73.3714.1-73.37
ADC 13.xbefore 13.1-64.2313.1-64.23
ADC 14.xbefore 14.1-73.37 FIPS14.1-73.37 FIPS
ADC 13.xbefore 13.1.37.279 FIPS and NDcPP13.1.37.279 FIPS and NDcPP
Gateway 14.xbefore 14.1-73.3714.1-73.37
Gateway 13.xbefore 13.1-64.2313.1-64.23

Is CVE-2026-88772 being exploited?

CISA lists this issue as exploited in the wild (date added 2026-09-27). Public exploit code is available. As of 2026-09-29 there are public reports of exploit code and official US government listing of exploitation.

How to fix CVE-2026-88772

  1. Apply the vendor fixes: upgrade ADC to 14.1-73.37 or 13.1-64.23 (and the listed FIPS/NDcPP fixed builds)
  2. If you cannot patch immediately, follow the vendor mitigations and restrict internet exposure of affected appliances
  3. Monitor appliance logs and network traffic for suspicious activity and indicators of exploitation
  4. Follow CISA guidance referenced in their advisory and verify compliance with any applicable emergency update policies

Frequently asked questions

Is CVE-2026-88772 being actively exploited?

Yes. CISA lists this CVE as exploited in the wild (added 2026-09-27), and public exploit code exists as of 2026-09-29.

Which versions contain the fix?

Fixed builds include ADC 14.1-73.37, ADC 13.1-64.23, the listed FIPS/NDcPP fixed builds (14.1-73.37 FIPS; 13.1.37.279 FIPS and NDcPP), and Gateway 14.1-73.37 and 13.1-64.23.

What immediate steps should I take if I run affected appliances?

Upgrade to the fixed builds as soon as possible, remove or block internet exposure for vulnerable appliances until patched, and increase monitoring for signs of compromise.

References